Outlines key restrictions and limitations when configuring SD-WAN RA functionality for remote access headend devices.
Before configuring SD-WAN RA functionality for a remote access headend device, first use Cisco SD-WAN Manager feature templates to configure any prerequite configurations, such as service VPN VRF definition and static public IP for the TLOC interface.
-
The tools for monitoring and troubleshooting are limited to show commands and viewing syslogs on the SD-WAN RA headend device.
-
Traffic that reaches a Cisco Catalyst SD-WAN edge device operating as a remote access headend goes through two IPsec tunnels—one from the remote device to the remote access headend, and another from the remote access headend to other endpoints within the enterprise network or outside of the network. Because packets use two separate tunnels, the remote access headend device may reach its licensed throughput limit sooner than expected. To check whether any packets are being dropped due to a throughput limit use the show platform hardware qfp active feature ipsec data drop command on the edge device to view the counters for packets dropped due to exceeding the throughput limit.
-
Cisco SD-WAN RA in SSL-VPN mode only supports TLS and not DTLS.