Product Documentation

Auto Secure Peering and Manual Secure Peering

Aug 09, 2017

Enterprise Edition appliance can be installed at the data center and has the capability to initiate auto or manual secure peering, create SSL profile and associate service class, and join the appliance to a Windows Domain Controller for allowing users/administrator to make use of the extended rich feature of standalone WANOP appliance.

Following are the deployment modes supported for Auto Secure Peering and Manual Secure Peering:

Auto Secure Peering Deployments

  1. To perform auto secure peering to an EE appliance from a standalone WANOP / SDWAN SE/WANOP on the DC site.

               Steps to initiate this deployment:

o    WANOP DC appliance is in LISTEN ON mode (2312/Any non-standard port) and Branch EE is in CONNECT-TO mode.

o    WANOP DC initiates automatic secure peering to an EE appliance which installs the Private CA Certs and CERT KEY Pairs and configure CONNECT-TO on the EE appliance with WANOPs LISTEN-ON IP.

         2. To perform Auto-secure peering initiated from EE appliance at DC site and Branch site EE appliance.

Steps to initiate this deployment:

o    EE DC appliance is in LISTEN ON mode (on port 443). Branch EE is in CONNECT-TO mode.

o    EE DC appliance initiates automatic secure peering to an EE Branch appliance which installs the Private CA Certs and CERT KEY Pairs and configures CONNECT-TO on the EE Branch appliance with DC EE’s LISTEN-ON IP.

o    LISTEN-ON IP for EE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.

          3. Auto Secure Peering initiated from EE Appliance at DC site and Branch with WANOP/ SDWAN SE appliance.

Steps to initiate this deployment:

o    EE DC appliance is in LISTEN ON mode (on port 443). Branch WANOP / SDWAN SE is in CONNECT-TO mode.

o    EE DC appliance initiates automatic secure peering to Branch WANOP / SDWAN SE appliance which installs the Private CA Certs and CERT KEY Pairs and configures CONNECT-TO on the EE appliance with DC EE’s  LISTEN-ON IP.

Manual Secure Peering Deployments

          4.  Manual Secure Peering initiated from EE appliance at DC site to Branch EE Appliance.

                Steps to initiate this deployment:

o   EE DC appliance is in LISTEN ON mode (on port 443). Branch EE is in CONNECT-TO mode.

o   LISTEN-ON IP for EE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.

o  Manually upload CA and Cert Key pair certificates obtained from authentic source of certificate authority.

          5.  Manual Secure Peering initiated from EE appliance at DC site to Branch WANOP/SDWAN-SE Appliance.

             Steps to initiate this deployment:

o   EE DC appliance is in LISTEN ON mode (on port 443). Branch WANOP / SDWAN SE is in CONNECT-TO mode.

o   LISTEN-ON IP for EE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled

o   Manually upload CA and Cert Key pair certificates obtained from authentic source of certificate authority.