Explains the prerequisites and procedures for configuring network tunnels with Cisco Catalyst SD-WAN.
Secure Access enables fast, reliable, and secure private network connections to your applications through IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels. Tunnels and tunnel groups are core concepts in managing connections between your data centers and Cisco Secure Access. A network tunnel group provides the framework for establishing tunnel redundancy and high availability. Connect tunnels to the hubs within a network tunnel group to securely control user access to the Internet and private resources.
Follow these steps to connect a Cisco IOS XE Catalyst SD-WAN device through an IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnel to Cisco Secure Access.
For more information about Cisco Catalyst SD-WAN devices and related topics, see Cisco's SD-WAN product documentation.
Before you begin
The following prerequisites must be met for the tunnel to work successfully.
-
You must enable NAT in the interface feature template that faces the internet.
-
You can access the Cisco Catalyst SD-WAN (Manager) console with a web browser. By default, the HTTPS port is 8443, but this may vary based on how your Cisco Catalyst SD-WAN (Manager) is configured.
If you get a "Not Secure" warning when accessing the link, you can ignore it. When the Cisco Catalyst SD-WAN (Manager) login screen appears, enter your credentials. -
An HSEC license is required to get high-throughput internet bandwidth for SLVPN tunnel setup. For more information, see Managing HSEC Licenses in Cisco Catalyst SD-WAN.