Configure Palo Alto Networks PANOS SDWAN

แชร์
ฝัง
  • เผยแพร่เมื่อ 7 ม.ค. 2025

ความคิดเห็น •

  • @chris71mach1
    @chris71mach1 ปีที่แล้ว +1

    This was a great and concise explanation of Strata SD-WAN and its initial setup and requirements. Thanks for the vid, I think you've earned another subscriber!

  • @Neur0bit
    @Neur0bit 6 หลายเดือนก่อน +1

    Fantastic explanation and demo. Bravo!

  • @aswin05
    @aswin05 ปีที่แล้ว +1

    Can we have Branch to Hub and also branch to branch ? also can we route an application through specific link ?

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว

      Yes, you can. Branch to branch is through hub or may be direct if you choose mesh instead of hub and spokes in vpn cluster config

  • @mostafasafari8583
    @mostafasafari8583 ปีที่แล้ว +1

    Thank you for your video.
    I have a bunch of branches and one hub. These branches are currently connected to the hub by IPSec tunnels, one for each branch. The tunnels are also part of the internal zone; therefore, we have L3-Trust (the internal network and tunnels) and L3-Untrust. If I want to use SD-WAN, should I define a third zone for tunnels? How should I map the zones?

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว

      create zone-to-hub and zone-to-branch and map L3-Trust with internal and L3-Untrust with internet

  • @richardrugambwa883
    @richardrugambwa883 4 หลายเดือนก่อน +1

    Nice video and good explaination.
    Why do we have the sdwan.1 manual VIF since the Auto-VPN is creating sdwan.902? Can't it cause a conflict.

    • @Cyberbulb
      @Cyberbulb  4 หลายเดือนก่อน

      There's no one way to do it. You can use autovpn or manual SD-WAN. Also routing can be static or dynamic using bgp. But I prefer not to mix. If your wan topology is simple you can go for manual / static.

  • @gouthamm.n2644
    @gouthamm.n2644 ปีที่แล้ว +1

    Could you also show the virtual router configurations?

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว +1

      BGP configured using sdwan plugin auto configures virtual router. connected routes for branches are advertised using bgp. subnets added under hub "prefixes to redistribute" are reachable from branches through bgp routes as well. if you wish to use static routes, it will be another story to tell may be on my next video!

    • @gouthamm.n2644
      @gouthamm.n2644 ปีที่แล้ว

      @@Cyberbulb got it I had issues with the loopback interface after fixing that the BGP was established I still have 1 more problem.
      Internet from zone-private to zone-internet does not work I do not see any hit counts on the nat policy which i have configured.

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว

      if you have mapped the zones use the original zones in the policy like from trust to untrust as an example also check static default route that sdwan automatically create on the firewall with metric 5 @@gouthamm.n2644

  • @spm3365
    @spm3365 ปีที่แล้ว

    Much appreciated, May I know the difference between the above configuration and the CloudGenix ION device configurations from Prisma-SDWAN portal.

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว

      This is the sdwan integrated feature in paloalto ngfw. Cloudgenix is a dedicated sdwan solution.

    • @spm3365
      @spm3365 ปีที่แล้ว

      @@Cyberbulb that is absolutely right. Lemme put my query in different way, what is the difference between the PANW's dedicated SDWAN (CloudGenix) methodology vs the PA-NGFW PANOS integrated SDWAN.

  • @kauffmann1983
    @kauffmann1983 ปีที่แล้ว +1

    Hello, Panorama is not necessary in order to implement SD-WAN, right?

    • @Cyberbulb
      @Cyberbulb  ปีที่แล้ว

      it should work without panorama as its role is the automation of VPN tunnels configurations and better monitoring

    • @chris71mach1
      @chris71mach1 ปีที่แล้ว

      Most everything you do with multiple PAN firewalls will use Panorama as the central point. Whether you HAVE to or not (which I honestly think you do), it's going to be a lot less of a migraine if you have at least a PA-VM on your network.

  • @TranVanLamBDCVT-
    @TranVanLamBDCVT- 7 หลายเดือนก่อน +1

    Can you show me the Zones on the Panorama ?

    • @Cyberbulb
      @Cyberbulb  7 หลายเดือนก่อน

      If it is a green field it is better to create the following zones on panorama and use them zone-internet, zone-internal, zone-to-hub, and zone-to-branch

    • @Cyberbulb
      @Cyberbulb  7 หลายเดือนก่อน

      Creat the following zones on panorama: zone-internal zone-internet zone-to-hub zone-to-branch

  • @Black_Swan68761
    @Black_Swan68761 ปีที่แล้ว +1

    Thanks for sharing the video.

  • @MB_72282
    @MB_72282 8 หลายเดือนก่อน +1

    Awesome! thanks

  • @mahmoudabomosalm1893
    @mahmoudabomosalm1893 ปีที่แล้ว +1

    Good job 👍

  • @henryhajj1248
    @henryhajj1248 2 ปีที่แล้ว +1

    Amazing!

  • @vijayyadav-pm5vv
    @vijayyadav-pm5vv ปีที่แล้ว +1

    good

  • @zmsaw
    @zmsaw ปีที่แล้ว

    Please help with pcnse certification