Guides configuration of dynamic on-demand tunnels, including setup using control policies, centralized control policy methods, and configuration via transport gateways, covering both group and template-based approaches.
Configure on-demand tunnels using control policy
To configure on-demand tunnels using the control policy method, do the following:
Procedure
-
Configure a control policy, as described in Configure a centralized control policy for on-demand tunnels.
-
Enable on-demand tunnels n spoke devices, as described in Enable on-demand tunnels on a spoke device using a template and Enable on-demand tunnels using a CLI template.
Configure a centralized control policy for on-demand tunnels
Before you begin
This procedure configures a centralized control policy on a Cisco Catalyst SD-WAN Controller to enable on-demand tunnels.
-
The Cisco Catalyst SD-WAN Controller centralized control policy must include the
tloc-action backupaction.This ensures that the backup path through the hub for communication between all of the spoke devices.
-
The Cisco Catalyst SD-WAN Controllerr centralized control policy must accept all spoke prefix routes.
-
The Cisco Catalyst SD-WAN Controller centralized control policy must accept TLOCs of all spokes.
For information about configuring a Cisco Catalyst SD-WAN Controller centralized control policy, see the policies configuration guides on the Cisco Catalyst SD-WAN Configuration Guides page.
-
When configuring on-demand tunnels using a transport gateway, do not use the control policy procedure described here. For information, see Configure On-Demand Tunnels Using a Transport Gateway.
Procedure
-
From the Cisco SD-WAN Manager menu, choose .
- Select Centralized Policy.
- Click Add Policy.
- In the left pane, click Site.
- Click Next.
- Click Add Topology and select Custom Control (Route & TLOC).
- Enter a name and description for the topology.
- Click Sequence Type.
- In the Add Control Policy pop-up window, choose Route.
- Click Sequence Rule to create a sequence.
-
Click Match.
- Among the match conditions, click Site.
- In the Match Conditions area, click the Site List menu and choose a site list.
- Click Actions, and then Accept.
-
Among the actions, click TLOC Action.
- In the Actions area, click the TLOC Action menu and choose Backup.
- Among the actions, click TLOC.
- In the Actions area, click the TLOC List menu and choose or create a TLOC list.
- Click Save Match and Actions.
-
Click Default Action.
- In the Default Action area, click the pencil icon to edit.
- Near the Actions label, click Accept.
- Click Save Control Policy.
- Click Next twice.
- In the Topology tab, click New Site/WAN Region List.
- Click Outbound Site List and choose a site list that defines the sites at which you are enabling on-demand tunnels.
- Adjacent to the site list, click Add.
- Enter a name and description for the policy.
- Click Save Policy.
Configure centralized control policy for on-demand tunnels using a CLI policy
Before you begin
The Cisco Catalyst SD-WAN Controller must be managed by Cisco SD-WAN Manager.
Procedure
Configure on-demand tunnels using a transport gateway
Before you begin
-
On Cisco SD-WAN Controllers, configure the send path limit, as described in Prerequisites: OMP settings.
-
On spoke devices, configure the ECMP limit, as described in Prerequisites: Spoke Device ECMP Limit.
-
When using a transport gateway as a hub to support on-demand tunnels, there is no need to create or modify a control policy.
Do not use the procedure described in Configure a Centralized Control Policy for On-Demand Tunnels.
Procedure
-
Enable transport gateway functionality on a router serving as the hub, providing a backup route between spokes, as described in the Transport Gateway section of the Cisco Catalyst SD-WAN Routing Configuration Guide.
-
Enable on-demand tunnels and configure the idle timeout on spoke devices as described in Enable on-demand tunnels on a spoke device using a template.
Enable on-demand tunnels on a spoke device using a configuration group
Before you begin
On the page, choose the SD-WAN solution type.
Procedure
-
From the Cisco SD-WAN Manager menu, choose .
-
Do one of these:
-
Edit a profile directly:
In the System Profile tab, create (Add New) or edit a System profile.
-
Edit a profile in a configuration group:
Open a configuration group and edit the System profile.
-
-
In the System profile, create (Add New) or edit a Basic feature.
-
In the Advanced section, use the On Demand Tunnel control to enable on-demand tunnels.
Enable on-demand tunnels on a spoke device using a template
Before you begin
-
See the Prerequisites for On-Demand Tunnels.
-
Do not enable on-demand on the hub device.
-
On the spoke devices, enable on-demand at the system level. In the case of multi-homed sites, enable on-demand on all systems at the site.
Procedure
Enable on-demand tunnels using a CLI template
For more information about using CLI templates, see CLI Add-On Feature Templates and CLI Templates.
By default, CLI templates execute commands in global configuration mode.
Before you begin
-
See Prerequisites for On-Demand Tunnels.
-
Do not enable on-demand on the hub device
Procedure
The default idle timeout value is 10 minutes. Range: 1 to 65535 minutes
Example:
system
on-demand enable
on-demand idle-timeout 10