Network Design
VeloCloud Hybrid WAN Architecture
New
in 2.1
WAN Headend
Gold Site
Dual L3
switches To core switch
(Campus/DC)
New
in 2.0
Silver Site
Single L2/L3
switch
New
in 2.0
Legacy Site
MPLS with
Existing
VPN backup
VPN hub
Bronze Site
Single/dual
Internet
4/14/16 VeloCloud - Confidential 3
Branch Insertion Options (Release 1.8.x)
Subnet A Subnet A Subnet A
…
…
…
L2 SW L3 SW
Subnet N Subnet N Subnet N
VCE with L2 switch VCE with L3 switch VCE with Branch Firewall
§ Use L2 switch to increase the § Connect to L3 switch over § VCE on public side of firewall.
number of switch ports access or trunk port § VCE provides high
§ VCE LAN connects to switch § Support static routes to the performance, secure, and
using access or trunk (802.1Q LAN subnets resilient WAN while firewall
– up to 32 VLANs) § L3 switch is the default gateway enforces security policy
§ VCE is the default gateway
4/14/16 VeloCloud - Confidential 4
Branch Insertion Options (Hybrid) New in
2.0
Router redirects
traffic to VCE L3 SW
VCE is in path and is default VCE is off path. MPLS router is VCE is off path and is default
gateway for L2/L3 switch default gateway for L2 switch gateway for L3 switch
Pro: Simple. Recommend & common Pro: No change to the host IP and Pro: Automatic fallback to MPLS when
when branch has only L2 switch default gateway VCE fails. HA not required for
survivability
§ Easy if branch uses DHCP so § CE router needs to redirect all traffic
readdressing is simple to the VCE (OSPF, IP SLA with static § L3 switch redirects traffic to SD-WAN
§ Traffic will stop if the VCE fails route) overlay (OSPF, IP SLA with static
§ Propose HA if availability is a § Redirection stops if VCE fails and route)
concern traffic follows original path (MPLS) § Redirection stops if VCE fails and
traffic follows original path (MPLS)
4/14/16 VeloCloud - Confidential 5
Flexible DC Insertion Options New in
2.0
Two-arm deployment mode One-arm deployment mode
§ One overlay (WAN) link per physical interface § Single physical interface, multiple overlay (WAN)
§ Require new VLAN between VCE and L3 switch links
§ Firewall point all traffic to internal subnet through § Firewall should point all traffic to internal subnet
VCE for congestion control through VCE for congestion control
§ VCE should not NAT traffic to the Internet § VCE should not NAT traffic to the Internet
4/14/16 VeloCloud - Confidential 6
Design Options for Securing Internet Traffic
No split tunnel for untrusted Split tunnel traffic from branch Internet traffic is sent to the
Internet traffic CWS, e.g. ZScaler
§ Use VCE built-in firewall § Use dedicated branch firewall (need § Use VCE built-in firewall in
§ Trusted SaaS traffic is sent through to allow inbound UDP/2426, UDP/ conjunction with cloud-based Web
the VCG 500, and UDP/4500 into the firewall security (CWS) such as Zscaler
§ Backhaul Internet traffic to HQ from VCE IP) § Trusted SaaS traffic is sent through
§ Trusted SaaS traffic is sent through VCG
the VCG § Internet traffic is chained through
§ Send the Internet traffic direct ZScaler via the VCG
4/14/16 VeloCloud - Confidential 7