Lists the prerequisites required to configure SD-WAN Remote Access using vManage.
This reference provides the prerequisites and requirements for configuring Cisco Catalyst SD-WAN Remote Access using Cisco SD-WAN Manager.
-
Global private IP pool for SD-WAN RA: In the network hierarchy, define a global private IPv4 pool and IPv6 pool for remote access. Ensure that this pool address range is unique in the Cisco Catalyst SD-WAN overlay.
This global private IP pool for remote access is used to allocate a unique IP pool to each device enabled for remote access. The devices use the allocated pool to assign a unique IP address to each remote access client. The remote access clients use the assigned IP address as the source IP address of the traffic from the client that is sent over an encrypted tunnel to the device.
-
Certificate authority: Define the certificate authority for SD-WAN RA. The devices enabled for remote access receive a certificate from this certificate authority. The devices use the certificate to authenticate to remote access clients.
From the Cisco SD-WAN Manager menu, choose and select Enterprise CA and Simple Certificate Enrollment Protocol (SCEP).
The other CA options such as Enterprise CA without SCEP, SD-WAN as CA and SD-WAN as intermediate CA are not supported for the SD-WAN RA feature.
-
RADIUS server: Define a RADIUS server in a configuration group using the AAA feature profile in the System Profile. The devices enabled for remote access use the RADIUS server to authenticate and to fetch an authorization policy for remote access clients.
Configure the authentication and authorization policies and the attributes on the RADIUS server.
-
Default service VPN for SD-WAN RA: Select one of the service VPNs as the default service VPN for remote access. The connection from each remote access client is placed in this service VPN unless the authorization policy from the RADIUS server specifies a different service VPN.