Cisco Secure Access Help

PDF

Cisco Secure Access Help

Configure Tunnels with VeloCloud SD-WAN

Want to summarize with AI?

Log in

Understand how to connect VeloCloud SD-WAN to Cisco Secure Access with singular or failover network tunnel groups.


VeloCloud is a cloud network service solution that you can integrate into Secure Access by adding it as a device type within a network tunnel group. You can create singular or failover network tunnel groups to address connectivity issues for larger deployments. You can use VeloCloud as a third party SD-WAN device to enhance general security and connectivity. When used in network tunnel groups, this allows secure IPsec tunnels to redirect branch traffic to Secure Access.

Previously, failover to a secondary tunnel was not supported and environments experienced warnings, delays in migration, or excessive amounts of network tunnel groups to address the lack of support. We strongly recommend creating secondary tunnels for large deployments and organizations to create a seamless, scalable, and supported tunnel redundancy for VeloCloud SD-WAN devices. This option reduces operational risk, validates secondary tunnel configuration, and supports Zscaler and other SSE solutions.

If you intend to initiate failover or configure a primary and secondary SD-WAN hub, both hubs must share the same authentication ID; this is configurable in the VeloCloud dashboard. Configuring a different authentication ID does not allow the hubs to sync. Share the authID within a network tunnel group and this ensures that when if the primary hub experiences an issue, the secondary hub immediately switches to the primary role without requiring authentication from an admin.

Use this procedure to create and configure a network tunnel group using a VeloCloud SD-WAN device:

Before you begin

The following prerequisites must be met for the tunnel to work successfully.

  • You ust be an admin.

  • You must already have your Velocloud SD-WAN environment configured. For more information see Secure Access SD-WAN Integration with Arista VeloCloud.

  • Your data center hubs must already be created and configured. If you have a secondary hub for a failover environment, both hubs must share the same authentication ID; this is configurable in the VeloCloud dashboard.

Procedure

  1. Follow the steps in Add a Network Tunnel Group. Select VeloCloud as the device type.

  2. Make note of the Tunnel ID and Passphrase you enter when configuring the network tunnel group. These values are needed to configure the SD-WAN tunnel.

  3. Configure the network tunnel group with a secondary tunnel to support failover. Note that the secondary tunnel uses the same passphrase as the primary tunnel. Failover prevents dropped traffic during select downtime such as maintenance periods.

  4. Continue with the remaining steps in Add a Network Tunnel Group. Upon completion, review and confirm the VeloCloud configuration; if you have configured a secondary network tunnel group, the details page displays details for both the primary and secondary hub as well as the corresponding network tunnel groups.