Product Documentation

Manual Secure Peering initiated from EE appliance at DC site and Branch EE appliance

This deployment configures DC site EE appliance in LISTEN ON mode and Branch site EE appliance in CONNECT TO mode.

  • EE DC appliance is in LISTEN ON mode (on port 443).
  • Branch EE appliance is in CONNECT-TO mode.
  • LISTEN-ON IP for EE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.
  • Manually upload CA and Cert Key pair certificates obtained from authentic source of certificate authority.

Configuration

To configure auto secure peering initiated from an EE appliance at DC site and PE appliance at branch site:

  1. Upload CA Certificate and CA Key Certificate obtained from authentic certificate and provide to SD-WAN as shown below. localized image localized image

  2. On a new EE appliance at the DC site, in the SD-WAN web GUI, go to Configuration > Secure Acceleration > Secure Peering. localized image

  3. Configure keystore by providing the keystore password or by disabling the keystore. localized image localized image

  4. Enable secure peering by selecting CA Certificate radio button and providing uploaded CA and CA Key pair certificates appropriately as shown below. localized image

  5. Provide Remote machine’s Virtual IP along with Port 443 as shown below. localized image

Monitoring

  1. To validate if the Private CA and Private Certificate Key pair is generated successfully, review the information below. localized image

  2. On partner appliance, View Secure Partner Information on the (Enterprise) Edition appliance under Monitoring > Partners > Secure Partners page. localized image

Troubleshooting

View Secure Partner Success / Failure Information on the Enterprise Edition Appliance under Monitoring > WAN Optimization > Partners > Secure Partners page. localized image

Manual Secure Peering initiated from EE appliance at DC site and Branch EE appliance