Citrix SD-WAN

Basic Configuration Mode

The Basic configuration mode allows you to configure sites easily and quickly. Using WAN Link templates, you can configure certain settings and, save it as templates, and then apply these templates to other sites. These reduce repetitive tasks and allow configuring new sites with minimal clicks.

The simplified basic configuration mode has two views Global and Sites.

Using the Global tab, you can:

  • Install centralized licenses.
  • Install certificates.
  • Configure Routing Domains.
  • Configure Applications.
  • Set the global virtual WAN network encryption settings.
  • Set global security settings and firewall settings.
  • Create Regions and define Region Control Nodes.
  • Set up Rules.

Using the Sites tab, you can:

  • Add Sites.
  • Configure Basic Settings for the site.
  • Enable site as intermediate node.
  • Configure centralized licensing
  • Configure Interface Groups, Virtual IP addresses
  • Configure routing domains and WAN Links.
  • Create multiple WAN Link Templates and map it to Service Providers.
  • Create WAN Link Template for MPLS links.
  • Configure the WAN Link speeds in Mbps or Kbps.
  • Set up MPLS Queues using % or kbps.
  • Enable dynamic virtual path.
  • Clone Sites.

localized image

localized image

Global virtual WAN network encryption

To set global virtual WAN network encryption settings:

  1. In the SD-WAN web management interface, navigate to Configuration Editor > New > Basic. Click Global to change from the (default) Sites view to the Network view.

  2. Under Global, click Virtual WAN Network Settings.

  3. In the right pane, click the Network Settings edit icon.

  4. Select the required network encryption options:

    • Network Encryption Mode – This is the encryption algorithm used for encrypted paths. Select one of the following from the drop-down menu: AES 128 Bits or AES 256 Bits.
    • Enable Encryption Key Rotation – When enabled, encryption keys are rotated at intervals of 10–15 minutes.
    • Enable Extended Packet Encryption Header – When enabled, a 16 bytes encrypted counter is prepended to encrypted traffic to serve as an initialization vector, and randomize packet encryption.
    • Enable Extended Packet Authentication Trailer – When enabled, an authentication code is appended to the contents of the encrypted traffic to verify that the message is delivered unaltered.
    • Extended Packet Authentication Trailer Type – This is the type of trailer used to validate packet contents. Select one of the following from the drop-down menu: 32-Bit Checksum or SHA-256.
  5. Click Apply.

    localized image

To create WAN link templates and associate it to service provider:

  1. In the SD-WAN web management interface, navigate to Configuration Editor > New > Basic. Click Global to change from the (default) Sites view to the Network view.

    localized image

  2. Click + Service Provider. Select and click the default name to rename the service provider.

    localized image

  3. Click + on the right pane to create a WAN link template. In the WAN Link Templates window, enter a name for the WAN link template.

    localized image

  4. Select the newly created Service Provider. Click the + Add sign to edit WAN Link templates.

    localized image

  5. In the Link Type field, select the link type. Either Internet or MPLS.

    localized image

  6. In the Rate unit field, select a unit for the WAN link speed. Either Kbps or Mbps. Specify the physical rate for LAN to WAN and WAN to LAN.

    Tip

    Select Auto Learn, to automatically detect the permitted rate.

  7. For MPLS links, create an MPLS Queue. Click + and enter values for the following parameters and click Add.

    • DSCP tag - Service Provider’s DSCP tag setting for the queue.
    • LAN to WAN Permitted Rate - The amount of bandwidth that SD-WAN devices are permitted to use for upload, which cannot exceed the defined physical upload rate of the WAN Link.
    • WAN to LAN Permitted Rate - The amount of bandwidth that SD-WAN devices are permitted to use for download, which cannot exceed the defined physical download rate of the WAN Link.

      localized image

    Tip

    You can set the unit for permitted rates of the MPLS queue to % or Kbps.

  8. Click Apply. Continue to add more WAN link templates for the service provider, if necessary.

    You can view a summary of the template details in the left pane. The Link type is displayed as broadband in the summary, if you selected internet link type.

    localized image

    localized image

Site cloning

The Basic > Sites view simplifies the configuration process by enabling you to create a configuration file that generates a virtual path between the defined sites. The required configuration properties for a virtual path between sites include:

  • Appliance
  • Interface
  • WAN Links
  • Static Routes

For information on adding and configuring an MCN site, see Setting up the Master Control Node (MCN) Site.

For information on adding and configuring a Branch site, see Adding and Configuring the Branch Sites.

You can now easily duplicate by using the clone option. This simplifies the process of creating multiple similar sites.

Note

A site configured as a primary or secondary MCN cannot be cloned.

To clone a site:

  1. In the SD-WAN web management interface, navigate to Configuration Editor > Basic. Click Sites.

  2. Select a site other than primary or secondary MCN and click the clone icon.

    localized image

  3. In the Clone Site window, review the fields and change the values for the fields for which the input values must be different from the site being cloned.

    localized image

  4. Click Clone. The cloned site appears in the list of sites.

Basic Configuration Mode