Overview
Lists the best practices for implementing DIA at branch sites to optimize traffic routing, enhance performance, and maintain secure WAN connectivity.
ECMP Best Practices
-
ECMP zones must be configured for active/active load balancing of application traffic.
-
ECMP is supported only in the routed firewall mode and a device can have a maximum of 256 ECMP zones.
-
Only routed interfaces must be used. Each interface must belong to only a single ECMP zone.
-
Make sure that interfaces belong to the virtual router where ECMP is being configured.
-
Interfaces used in the ECMP zone configuration must have logical names defined within the interface configuration.
-
Validate that no more than eight interfaces per ECMP zone are configured for PBR on Firewall Threat Defense.
Policy-Based Routing Best Practices
-
Firewall Threat Defense must not be deployed in a cluster because PBR is not supported in this mode.
-
PBR must be configured for the global virtual router as it is not supported on user-defined virtual routers.
-
Ensure that interfaces used in ingress and egress interface within PBR are either routed interfaces or non management-only interfaces and they belong to the global virtual router.
DNS Best Practices
-
Trusted DNS servers must be configured to ensure DNS snooping is performed through trusted DNS servers to support application traffic flow.
-
DNS requests passing through Threat Defense must be in a clear-text format and not encrypted to allow DNS snooping to facilitate PBR flows.