Citrix SD-WAN

Gateway mode

Gateway mode places the SD-WAN appliance physically in the path (two-arm deployment) and requires changes in the existing network infrastructure to make the SD-WAN appliance the default gateway for the entire LAN network for that site. Gateway mode used for new networks and router replacement. Gateway mode allows SD-WAN appliances:

  • To view all traffic to and from the WAN
  • To perform local routing

Gateway deployment mode is supported on Citrix SD-WAN Orchestrator service. For more information, see Interfaces.

Gateway mode

Note

An SD-WAN deployed in Gateway mode acts as a Layer 3 device and cannot perform fail-to-wire. All interfaces involved will be configured for Fail-to-block. In the event of appliance failure, the default gateway for the site will also fail, causing an outage until the appliance and default gateway are restored.

In the Inline mode, the SD-WAN appliance appears to be an Ethernet bridge. Most of the SD-WAN appliance models include a fail-to-wire (Ethernet bypass) feature for inline mode. If power fails, a relay closes and the input and output ports become electrically connected, allowing the Ethernet signal to pass through from one port to another. In the fail-to-wire mode, the SD-WAN appliance looks like a cross-over cable connecting the two ports. Inline mode used to integrate into already well-defined networks.

Inline mode workflow

This article provides step-by-step procedure to configure an SD-WAN appliance in Gateway mode in a sample network setup. Inline deployment is also described for the branch side to complete the configuration. A network can continue to function if an Inline device is removed, but loses all access if the Gateway device is removed.

Topology

The following illustrations describe the topologies supported in an SD-WAN network.

Data Center in gateway deployment

Data center gateway mode

Branch in inline deployment

Branch inline deployment

Data center site gateway mode configuration

Following are the high-level configuration steps to configure data center site Gateway deployment:

  1. Create a DC site.

  2. Populate Interface Groups based on connected Ethernet interfaces.

  3. Create Virtual IP address for each virtual interface.

  4. Populate WAN links based on physical rate and not burst speeds using Internet and MPLS Links.

  5. Populate Routes if there are more subnets in the LAN infrastructure.

To create Virtual IP (VIP) address for each virtual interface

  1. Create a VIP on the appropriate subnet for each WAN Link. VIPs are used for communication between two SD-WAN appliances in the Virtual WAN environment.

  2. Create a Virtual IP Address to be used as the Gateway address for the LAN network.

    VIP gateway mode

To populate WAN links based on physical rate and not on burst speeds using Internet link:

  1. Navigate to WAN Links, click the + Add Link button to add a WAN Link for the Internet link.

  2. Populate Internet link details, including the supplied Public IP address as shown below. AutoDetect Public IP cannot be selected for SD-WAN appliance configured as MCN.

  3. Navigate to Access Interfaces, from the section drop-down menu, and click the + Add button to add interface details specific for the Internet link.

  4. Populate Access Interface for IP and gateway addresses as shown below.

    WAN link gateway mode

    Access interface gateway mode

  1. Navigate to WAN Links, click the + button to add a WAN Link for the MPLS link.

  2. Populate MPLS link details as shown below.

  3. Navigate to Access Interfaces, click the + button to add interface detail specific for the MPLS link.

  4. Populate Access Interface for IP and gateway addresses as shown below.

    MPLS gateway mode WAN links

    MPLS access interface gateway mode

To populate Routes

Routes are auto-created based on the above configuration. The DC LAN sample topology shown above has an extra LAN subnet which is 192.168.31.0/24. A route needs to be created for this subnet. Gateway IP address must be in the same subnet as the DC LAN VIP as shown below.

MPLS routes gateway mode

Branch site inline deployment configuration

Following are the high-level configuration steps to configure Branch site for Inline deployment:

  1. Create a Branch site.

  2. Populate Interface Groups based on connected Ethernet interfaces.

  3. Create Virtual IP address for each virtual interface.

  4. Populate WAN links based on physical rate and not burst speeds using Internet and MPLS Links.

  5. Populate Routes if there are more subnets in the LAN infrastructure.

To create Virtual IP (VIP) address for each virtual interface

  1. Create a Virtual IP address on the appropriate subnet for each WAN Link. VIPs are used for communication between two SD-WAN appliances in the Virtual WAN environment.

    Virtual IP address gateway mode branch

To populate WAN links based on physical rate and not on burst speeds using Internet link:

  1. Navigate to WAN Links, click the + button to add a WAN Link for the Internet link.

  2. Populate Internet link details, including the Auto Detect Public IP address as shown below.

  3. Navigate to Access Interfaces, click the + button to add interface details specific for the Internet link.

  4. Populate Access Interface for IP address and gateway as shown below.

    WAN link gateway mode

    Access interface gateway mode branch

  1. Navigate to WAN Links, click the + button to add a WAN Link for the MPLS link.

  2. Populate MPLS link details as shown below.

  3. Navigate to Access Interfaces, click the + button to add interface details specific for the MPLS link.

  4. Populate Access Interface for IP address and gateway as shown below.

    MPLS gateway mode WAN links branch

    MPLS access interface branch

To populate routes

Routes are auto-created based on above configuration. In case there are more subnets specific to this remote branch office, then specific routes need to be added identifying which gateway to direct traffic to reach those back-end subnets.

MPLS routes gateway mode branch

Resolve audit errors

After completing configuration for DC and Branch sites, you will be alerted to resolve audit error on both DC and BR sites.

By default, the system generates paths for WAN Links defined as access type Public Internet. You would be required to use the auto-path group function or enable paths manually for WAN Links with an access type of Private Internet. Paths for MPLS links can be enabled by clicking Add operator (in the green rectangle).

Default WAN links

After completing all the above steps, proceed to Preparing the SD-WAN Appliance Packages.–>