0% found this document useful (0 votes)
7 views6 pages

VeloCloud Hybrid WAN Design Options

The document outlines the VeloCloud Hybrid WAN Architecture, detailing various site configurations including Gold, Silver, and Bronze sites, as well as branch insertion options for different network designs. It introduces new features in releases 2.0 and 2.1, such as flexible deployment modes and design options for securing internet traffic. The document emphasizes the use of VCE (VeloCloud Edge) for enhancing WAN performance and security across different network setups.

Uploaded by

Nguyet Bui
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views6 pages

VeloCloud Hybrid WAN Design Options

The document outlines the VeloCloud Hybrid WAN Architecture, detailing various site configurations including Gold, Silver, and Bronze sites, as well as branch insertion options for different network designs. It introduces new features in releases 2.0 and 2.1, such as flexible deployment modes and design options for securing internet traffic. The document emphasizes the use of VCE (VeloCloud Edge) for enhancing WAN performance and security across different network setups.

Uploaded by

Nguyet Bui
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Network Design

VeloCloud Hybrid WAN Architecture


New
in 2.1
WAN Headend
Gold Site
Dual L3
switches To core switch
(Campus/DC)
New
in 2.0
Silver Site
Single L2/L3
switch
New
in 2.0

Legacy Site
MPLS with
Existing
VPN backup
VPN hub
Bronze Site
Single/dual
Internet
4/14/16 VeloCloud - Confidential 3
Branch Insertion Options (Release 1.8.x)

Subnet A Subnet A Subnet A



L2 SW L3 SW
Subnet N Subnet N Subnet N

VCE with L2 switch VCE with L3 switch VCE with Branch Firewall

§ Use L2 switch to increase the § Connect to L3 switch over § VCE on public side of firewall.
number of switch ports access or trunk port § VCE provides high
§ VCE LAN connects to switch § Support static routes to the performance, secure, and
using access or trunk (802.1Q LAN subnets resilient WAN while firewall
– up to 32 VLANs) § L3 switch is the default gateway enforces security policy
§ VCE is the default gateway

4/14/16 VeloCloud - Confidential 4


Branch Insertion Options (Hybrid) New in
2.0

Router redirects
traffic to VCE L3 SW

VCE is in path and is default VCE is off path. MPLS router is VCE is off path and is default
gateway for L2/L3 switch default gateway for L2 switch gateway for L3 switch

Pro: Simple. Recommend & common Pro: No change to the host IP and Pro: Automatic fallback to MPLS when
when branch has only L2 switch default gateway VCE fails. HA not required for
survivability
§ Easy if branch uses DHCP so § CE router needs to redirect all traffic
readdressing is simple to the VCE (OSPF, IP SLA with static § L3 switch redirects traffic to SD-WAN
§ Traffic will stop if the VCE fails route) overlay (OSPF, IP SLA with static
§ Propose HA if availability is a § Redirection stops if VCE fails and route)
concern traffic follows original path (MPLS) § Redirection stops if VCE fails and
traffic follows original path (MPLS)
4/14/16 VeloCloud - Confidential 5
Flexible DC Insertion Options New in
2.0

Two-arm deployment mode One-arm deployment mode


§ One overlay (WAN) link per physical interface § Single physical interface, multiple overlay (WAN)
§ Require new VLAN between VCE and L3 switch links
§ Firewall point all traffic to internal subnet through § Firewall should point all traffic to internal subnet
VCE for congestion control through VCE for congestion control
§ VCE should not NAT traffic to the Internet § VCE should not NAT traffic to the Internet

4/14/16 VeloCloud - Confidential 6


Design Options for Securing Internet Traffic

No split tunnel for untrusted Split tunnel traffic from branch Internet traffic is sent to the
Internet traffic CWS, e.g. ZScaler
§ Use VCE built-in firewall § Use dedicated branch firewall (need § Use VCE built-in firewall in
§ Trusted SaaS traffic is sent through to allow inbound UDP/2426, UDP/ conjunction with cloud-based Web
the VCG 500, and UDP/4500 into the firewall security (CWS) such as Zscaler
§ Backhaul Internet traffic to HQ from VCE IP) § Trusted SaaS traffic is sent through
§ Trusted SaaS traffic is sent through VCG
the VCG § Internet traffic is chained through
§ Send the Internet traffic direct ZScaler via the VCG

4/14/16 VeloCloud - Confidential 7

You might also like