Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Best Practices

Want to summarize with AI?

Log in

Overview

Lists the best practices for implementing DIA at branch sites to optimize traffic routing, enhance performance, and maintain secure WAN connectivity.

ECMP Best Practices

  • ECMP zones must be configured for active/active load balancing of application traffic.

  • ECMP is supported only in the routed firewall mode and a device can have a maximum of 256 ECMP zones.

  • Only routed interfaces must be used. Each interface must belong to only a single ECMP zone.

  • Make sure that interfaces belong to the virtual router where ECMP is being configured.

  • Interfaces used in the ECMP zone configuration must have logical names defined within the interface configuration.

  • Validate that no more than eight interfaces per ECMP zone are configured for PBR on Firewall Threat Defense.

Policy-Based Routing Best Practices

  • Firewall Threat Defense must not be deployed in a cluster because PBR is not supported in this mode.

  • PBR must be configured for the global virtual router as it is not supported on user-defined virtual routers.

  • Ensure that interfaces used in ingress and egress interface within PBR are either routed interfaces or non management-only interfaces and they belong to the global virtual router.

DNS Best Practices

  • Trusted DNS servers must be configured to ensure DNS snooping is performed through trusted DNS servers to support application traffic flow.

  • DNS requests passing through Threat Defense must be in a clear-text format and not encrypted to allow DNS snooping to facilitate PBR flows.