Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Best Practices

Updated: February 5, 2026

Overview

Lists the best practices for implementing DIA at branch sites to optimize traffic routing, enhance performance, and maintain secure WAN connectivity.

ECMP Best Practices

  • ECMP zones must be configured for active/active load balancing of application traffic.

  • ECMP is supported only in the routed firewall mode and a device can have a maximum of 256 ECMP zones.

  • Only routed interfaces must be used. Each interface must belong to only a single ECMP zone.

  • Make sure that interfaces belong to the virtual router where ECMP is being configured.

  • Interfaces used in the ECMP zone configuration must have logical names defined within the interface configuration.

  • Validate that no more than eight interfaces per ECMP zone are configured for PBR on Firewall Threat Defense.

Policy-Based Routing Best Practices

  • Firewall Threat Defense must not be deployed in a cluster because PBR is not supported in this mode.

  • PBR must be configured for the global virtual router as it is not supported on user-defined virtual routers.

  • Ensure that interfaces used in ingress and egress interface within PBR are either routed interfaces or non management-only interfaces and they belong to the global virtual router.

DNS Best Practices

  • Trusted DNS servers must be configured to ensure DNS snooping is performed through trusted DNS servers to support application traffic flow.

  • DNS requests passing through Threat Defense must be in a clear-text format and not encrypted to allow DNS snooping to facilitate PBR flows.