Use Cases for SD-WAN Capabilities in Cisco Secure Firewall

PDF

Best Practices

Updated: February 5, 2026

Overview

Lists the best practices for using DVTI with Cisco Secure Firewall in a scalable SD‑WAN deployment.

  • Ensure that Secure Firewall Threat Defense is runing on version 6.7 and later.

  • VTI is supported in routed mode only.

  • Configure the borrow IP for the dynamic interface from a loopback interface.

  • Ensure to apply access rules on a VTI interface to control traffic through VTI.

  • Configure ECMP zones for SVTIs to load balance VTI traffic.