Cisco Secure Access Help

PDF

Cisco Secure Access Help

Configure Tunnels with Cisco Catalyst SD-WAN

Want to summarize with AI?

Log in

Explains the prerequisites and procedures for configuring network tunnels with Cisco Catalyst SD-WAN.


Secure Access enables fast, reliable, and secure private network connections to your applications through IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels. Tunnels and tunnel groups are core concepts in managing connections between your data centers and Cisco Secure Access. A network tunnel group provides the framework for establishing tunnel redundancy and high availability. Connect tunnels to the hubs within a network tunnel group to securely control user access to the Internet and private resources.

Follow these steps to connect a Cisco IOS XE Catalyst SD-WAN device through an IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnel to Cisco Secure Access.

For more information about Cisco Catalyst SD-WAN devices and related topics, see Cisco's SD-WAN product documentation.

Before you begin

The following prerequisites must be met for the tunnel to work successfully.

  • You must enable NAT in the interface feature template that faces the internet.

  • You can access the Cisco Catalyst SD-WAN (Manager) console with a web browser. By default, the HTTPS port is 8443, but this may vary based on how your Cisco Catalyst SD-WAN (Manager) is configured.

    Note
    If you get a "Not Secure" warning when accessing the link, you can ignore it. When the Cisco Catalyst SD-WAN (Manager) login screen appears, enter your credentials.
  • An HSEC license is required to get high-throughput internet bandwidth for SLVPN tunnel setup. For more information, see Managing HSEC Licenses in Cisco Catalyst SD-WAN.

Procedure

  1. Follow the steps in Add a Network Tunnel Group. Select Static routing under routing options. Only static routing is supported.

  2. Make note of the Tunnel ID and Passphrase you enter when configuring the network tunnel group. These values are needed when you configure your Catalyst SD-WAN tunnel.

    The new network tunnel group appears in the Secure Access dashboard as Disconnected, and with the Primary Hub and Secondary Hub status showing as Hub Down. The network tunnel group status is updated once it is fully configured and connected with Catalyst SD-WAN.


    Network Tunnel Groups page displaying the status of the network tunnel group, including primary and secondary hubs
  3. Configure a Catalyst SD-WAN tunnel to connect a Catalyst SD-WAN device to Cisco Secure Access.

    In Cisco Catalyst SD-WAN Manager, all the features are configured through templates. Once the Cisco Catalyst SD-WAN devices are registered with Cisco Catalyst SD-WAN Manager, you cannot configure anything through the CLI.

    You can use the Cisco Catalyst SD-WAN Manager Device and Feature templates to establish a tunnel from the device. First define the device template and then the feature template.

    In SD-WAN Manager version 20.9, the SIG template is divided into several sections:

    1. Device Type, Template Name, Description, and SIG Provider (Umbrella, Zscaler, or Generic).

      Note
      In version 20.4/17.4, the only two tunnel types that are offered are Umbrella and Third Party. You can configure Secure Access manual tunnels (IPSec or GRE) using the Third Party option. Starting in 20.5/17.5, the three tunnel types that are offered are Umbrella, Zscaler, and Generic. To configure IPSec or GRE Secure Access tunnels, choose the Generic option. You can configure Secure Access manual and automatic tunnels (IPSec or GRE) using the Generic option. Secure Access recommends you use automatic tunnels if available.
    2. Tracker: Allows you to configure custom L7 health check tracker information.

    3. Configuration: Allows you to specify different tunnel type (IPSec or GRE) and other tunnel characteristics, such as tunnel name, tracker name, tunnel source, whether the tunnel is attached to a primary or secondary data center (which is specified or discovered later) and advanced options, like IP MTU and other tunnel settings.

    4. High Availability: Allows you to choose up to 4 active tunnels or 4 active/standby tunnel pairs by choosing the tunnels defined in the Configuration section under the Active or Backup column. You can also modify traffic ratios for the tunnels.

  4. Log into the Cisco Catalyst SD-WAN Manager console and navigate to Configuration > Templates.

  5. Confirm that the Feature Templates tab is selected, then click Add Template.

    Templates page with an option to add a new feature template
  6. Choose the device for which you are creating the template.

  7. Under VPN, click Cisco Secure Internet Gateway (SIG).

  8. Under SIG Provider select Device Types, click the Genric radio button.

    Cisco secure Internet Gateway (SIG) page with an option to configure the SIG provider for a device

    Trackers and Tunnel Health Monitoring

    Trackers are a critical part of monitoring and maintaining overlay and SSE/SIG tunnel health on Cisco Catalyst SD-WAN. A tracker sends periodic probe packets (such as HTTP, ICMP, or DNS) towards a specified endpoint to determine reachability. When a tracker detects that its endpoint is unreachable, the SD-WAN control plan can withdraw routes or triggers failover actions to maintain service continuity. Trackers are used for interface reachability, static route tracking, service/SSE health, and SLA-based tunnel decisions.

    Configuring Custom L7 Tracker URLs

    Customers who require more granular SLA tracking (for example, monitoring a specific endpoint or cloud service) can define custom endpoint trackers specifying an L7 HTTP/HTTPS URL:

    1. In Catalyst SD-WAN Manager, navigate to Configuration > Feature Template > Secure Internet Gateway (SIG).

    2. Click New Tracker.

    3. Enter a Tracker Name.

    4. Adjust the Threshold, Interval, and Multiplier values as needed. Default values are selected by default.

    5. In the API url endpoint, enter the API URL for the SIG endpoint of the tunnel.

      Configuration page for setting the API URL for the SIG tunnel endpoint
    6. Choose Tracker from the drop-down list and enter the tracker configuration details.

      Update Tunnel page with an option to configure the tracker
    7. Click Save Changes.

    For more information on how Catalyst SD-WAN tracker work and their use cases, see Understand Catalyst SD-WAN Tracker Usability and Use Cases.

  9. Under Configuration, click Add Tunnel .

    Configuration section with an option to add a tunnel
    1. Choose the Tunnel Type radio button for the tunnel.
    2. Enter the Interface Name from 1 to 255. For example: ipsec1.
    3. Optionally, choose a Tunnel Description for the Tunnel interface.
    4. Optionally, select the Tracker for the tunnel interface.
    5. Set the Tunnel Source Interface. This must be the WAN interface in VPN 0, which has the internet connectivity.
    6. Set the SIG Tunnels Destination to the closest data center.
    7. Enter the Preshared Key from SSE.
    Configuration section displaying fields for configuring a tunnel
  10. Under General configuration, the Shutdown option is set to the NO radio button by default.

    Configuration section with an option to set the default configuration for Shutdown field
  11. Choose the Global Attribute to change IKE defaults:

    1. IKE Rekey Interval: Set to 28800.
    2. Cipher Suite: Leave default option unchanged, AES-256-CBC-SHA1.
    3. IKE DH Group: Set to 14 2048-bit Modulus.
    4. IKE ID for Remote End point: IP address of Secure Access Data Center that is 52.228.XX.XXX, 44.35.XXX.XX
    5. IKE ID for local End point: Tuneel Group ID on SSE page.
    Status display for primary and secondary hubs
  12. Choose the Global Attribute to change IPsec defaults:

    1. IPsec Rekey Interval & Replay Window: Leave defaults unchanged.
    2. Cipher Suite: Leave default option unchanged, AES 256 GCM.
    3. Perfect Forward Secrecy: Set to NONE.
    Tip
    Cipher Suite Encryption

    If performance is an issue with the default cipher, both AES 256 CBC SHA1 and Null SHA1 are also supported. You can test these to determine whether one offers better performance for a particular platform. Note that Null SHA1 isn't necessarily faster than the default AES 256 GCM because of the cost of the SHA1 hashing. In addition, Null SHA1 is not recommended due to security concerns of unencrypted transport.

    IPSec section displaying default values for IPsec parameters
  13. Under High Availability, select Active and Backup tunnel interface from the drop-down list.

    High Availability section with options to select active and backup tunnel interfaces
  14. Click Save to configure the template.

  15. Add the Cisco SIG template: Navigate to Configuration > Templates > Device, then choose the device template for the CDFW tunnel.

  16. Select Edit from the rightmost dropdown menu.

    Templates page with an option to edit a device template
  17. Add the Cisco SIG template in the VPN 0 Transport & Management VPN section. Choose the VPN Interface IPSec that you added as part of the feature template.

  18. Click Update.

    A success message appears.

    Device Group section displaying a success message after updating template details
  19. Add static routes from the service VPN to redirect the traffic through the IPSec tunnel to CDFW headend: Navigate to Configuration > Templates > Feature Templates.

  20. Right-click the right most column of the Service VPN template, and Edit the template to add SIG service route.

    Feature Templates tab with an option to edit the template and add SIG service route details
  21. Click New Service Route.

    Feature Template tab with an option to add a new service route

    In this example, the default route is set to the SIG tunnel interface.

    Service Route section displaying the SIG tunnel interface as the default route
  22. Verify the Tunnel Status in the Cisco Catalyst SD-WAN Manager Console.

    1. Log in to the Cisco Catalyst SD-WAN Manager console.
    2. Navigate to Monitor > Tunnels.
    3. Click the SIG/SSE Tunnels tab.

      You can view the tunnel status.