Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

Multitenant WAN edge devices

Want to summarize with AI?

Log in

Describes WAN edge devices operating in a multitenancy environment, including benefits, device resource tiers, supported devices, and restrictions.


A multitenant WAN edge device is an edge device in a Cisco Catalyst SD-WAN network that

  • operates in a multitenancy environment, and

  • can serve multiple tenants.

As a service provider managing a multitenant Cisco Catalyst SD-WAN deployment, you can deploy a multitenant WAN edge device in the overlay network to serve as a shared gateway for traffic belonging to multiple tenants. For example, you can deploy such a shared gateway in each regional point of presence (PoP). You can carry inter-region traffic belonging to multiple tenants through these shared gateways and the transport backbone linking the PoPs.

Figure 1. Multitenant WAN edge devices as shared gateways

Multitenant WAN edge devices isolate traffic belonging to different tenants by mapping a tenant service VPN (referred to as tenant VPN) to a device VPN (also referred to as the device VRF). Cisco SD-WAN Manager performs the mapping between the tenant and device VPNs when you onboard a tenant on a multitenant WAN edge device.

Multitenant WAN edge devices establish control connections with the Cisco SD-WAN Validator nodes specified in the bootstrap configuration, and then connect to nodes in the Cisco SD-WAN Manager cluster. When you onboard a tenant to a multitenant WAN edge device, the device establishes control connections to the Cisco SD-WAN Controller assigned to the tenant.

The service provider must deploy, configure, and manage multitenant WAN edge devices. The devices and their states are displayed only in the Cisco SD-WAN Manager provider view. The provider, acting on behalf of the tenant, must deploy, configure, and manage single-tenant WAN edge devices owned by a tenant. The devices and their states are displayed in the tenant view or the provider-as-tenant view. When a tenant is onboarded to a multitenant WAN edge device, the multitenant WAN edge device can interoperate with single-tenant WAN edge devices owned by the tenant and other multitenant WAN edge devices to which the tenant is onboarded.


Benefits of multitenant WAN edge devices

These are the benefits of a multitenant WAN edge device.

As a managed service provider, by deploying multitenant WAN edge devices, you can

  • reuse the edge devices and the interconnecting transport backbone to serve multiple tenants

  • lower capital and operational expenditure

  • provide faster access to tenants to shared resources, SaaS, and IaaS through the shared transport backbone, and

  • manage tenant association with the devices, tenant-specific policies, and QoS requirements with Cisco SD-WAN Manager as the unified management interface.


Device resource tiers

A device resource tier is a structure for managing multitenant WAN edge devices that defines how much of each device resources a tenant assigned to the teir can consume.

When you onboard many tenants on a multitenant WAN edge device, you may need to distribute the limited device resources among the tenants to ensure fair usage of resources or to implement different service-level agreements (SLAs). A tier lets you define and limit how much of each device resource a tenant assigned to the tier can consume. After creating a tier, when you onboard a tenant, you assign a tenant to a particular tier to apply the resource-usage limits to the tenant.

Usage notes

  • After you create a tier, you cannot modify the device-resource-usage limits specified in the tier. To apply a different set of limits to tenants, you must create a new tier and assign the relevant tenants to the new tier.

  • You can delete a tier only when no tenants are assigned to it.


Device resource tiers

This section describes the resources governed by tier.
Table 1. Resources governed by tier

Resource usage limit

Description

Available from

Number of VPNs

Maximum number of tenant VPNs that can be created for a tenant belonging to the tier.

Cisco SD-WAN Manager enforces the limit when you create a new tenant VPN for a tenant.

  • If you have already created the maximum number of tenant VPNs specified in the tier, Cisco SD-WAN Manager reports the error and doesn't apply the configuration.

Cisco IOS XE Release 17.8.1 and Cisco vManage Release 20.8.1

Route-limit

The number of IPv4 unicast and IPv6 unicast routes that can be created for a tenant belonging to the tier.

Route limit on a tenant is the sum of routes from all VRFs.

Cisco IOS XE Catalyst SD-WAN Release 17.10.1a

Cisco vManage Release 20.10.1

TLOC

TLOC allows you to map transport interfaces to tenants. At least one TLOC needs to be selected per tier and you can include up to 16 TLOCs in a tier.

Cisco IOS XE Catalyst SD-WAN Release 17.10.1a

Cisco vManage Release 20.10.1

NAT limit

The maximum limit on the number of NAT translations per tenant.

Once the maximum limit has reached for a tenant, the packets are dropped and further translations are not allowed.

Cisco IOS XE Catalyst SD-WAN Release 17.12.1a

Cisco Catalyst SD-WAN Manager Release 20.12.1


Supported devices for multitenant WAN edge devices

This table describes the devices that can operate as multitenant WAN edge devices.
Table 2. Supported devices

Device family

Model

Cisco ASR 1000 Series Aggregation Services Routers

ASR 1001-HX

ASR 1001-X

ASR 1002-HX

ASR 1002-X

Note

Cisco IOS XE Catalyst SD-WAN Release 17.9.1a is the last supported release for ASR 1001-X and ASR 1002-X.

Cisco Catalyst 8000V Edge Software

Catalyst 8000V

Cisco Catalyst 8300 Series Edge Platforms

C8300-1N1S-4T2X

C8300-1N1S-6T

C8300-2N2S-4T2X

C8300-2N2S-6T

Cisco Catalyst 8500 Series Edge Platforms

C8500-12X

C8500-12X4QC

C8500L-8S4X

Cisco ISR 4000 Series Integrated Services Routers

ISR 4461


Restrictions for multitenant WAN edge devices

Unsupported services and technologies

Multitenant WAN edge devices do not support these services and technologies:

  • Cloud Express and Multicloud workflows

  • Zone-Based Firewall (ZBFW) and advanced security features

  • Per-tenant DPI statistics

  • Dynamic on-demand tunnels

  • SNMP

  • Per-tenant management of NAT resources

  • OMP IPv6 route filtering

  • OMP notifications

Provider ownership of devices

The provider must own, deploy, and manage all multitenant WAN edge devices in the deployment. The provider must also deploy and manage any single-tenant device owned by a specific tenant.

Unique system IP addresses

Configure a unique system IP address for each WAN edge device in the multitenant Cisco Catalyst SD-WAN deployment, irrespective of whether the device is a multitenant device owned and managed by the provider or a single-tenant device owned by a tenant and managed by the provider on behalf of the tenant.

Maximum SLA classes

You can configure a maximum of 16 SLA classes. You can either assign specific SLA classes to tenants or share SLA classes among tenants.

Migration of device from the tenant level to be multitenant device

You cannot migrate a single-tenant WAN edge device from the tenant level to serve as a multitenant WAN edge device at the provider level. You must decommission the single-tenant device and delete it from Cisco SD-WAN Manager, perform a factory reset on the device to erase the existing configuration, and onboard the device at the provider level.

Precedence in VRF limits

Tenant limits takes precedence when VRF limits are also configured.