SD-WAN

 View Only
last person joined: yesterday 

Forum to discuss HPE Aruba EdgeConnect SD-WAN and SD-Branch solutions. This includes SD-WAN Orchestration WAN edge network functions - routing, security, zone-based firewall, segmentation and WAN optimization, micro-branch solutions, best practics, and third-party integrations. All things SD-WAN!
Expand all | Collapse all

NGFW feature licencing and dual stack.

This thread has been viewed 39 times
  • 1.  NGFW feature licencing and dual stack.

    Posted Mar 06, 2023 03:37 AM

    Hi Team,

    • Kindly confirm if we need addtional licences on SDWAN Edge connect in order to use NGFW feature?.
    • If Yes, whether it is for complete SDWAN solution for all Edge connect or we need to have indual licenes for each edge connect device?
    • Where i can see/verify more about NGFW licenes on SDWAN Orchestrator and Edge connect device.

    Addtion to this i just have one addtional question:

    • Can SDWAN edge connect support dual stack.
    • Are there any chalenges with IPv6 / dual stack solution?.

    Thank you so much to in advance.



  • 2.  RE: NGFW feature licencing and dual stack.

    EMPLOYEE
    Posted Mar 06, 2023 06:47 AM

    Hi, I can answer the first question on licensing. We have all the NGFW in the standard SD-WAN bandwidth license. The only features not included is IDS/IPS. You require a separate security license for that. If you check out the link below, it has a breakdown of features and which is license is required.

    To review your current licensing you should be able to see this on the main Orchestrator dashboard or under configuration then licences. 

    https://www.arubanetworks.com/resource/secure-sd-wan-fabric-with-aruba-edgeconnect-enterprise/

    Regarding the dual stack question. Do you mean high availability or clustering?




  • 3.  RE: NGFW feature licencing and dual stack.

    Posted Mar 08, 2023 06:54 AM

    Thank for the information.

    My current WAN infra is setup for dual stack (IP v4 and v6). wanted to know whether SDWAN edge connect will support dual stack solution.

    Thank you




  • 4.  RE: NGFW feature licencing and dual stack.

    EMPLOYEE
    Posted Mar 09, 2023 10:37 AM

    Yes, EdgeConnect can support IPv4 and IPv6



    ------------------------------
    DuaneHenigin
    ------------------------------



  • 5.  RE: NGFW feature licencing and dual stack.

    Posted Mar 17, 2023 03:16 AM

    Hello Duane,

    Thank you so much for your confirmation. 
    Can you please guide me how i can configure v4 and v6 interface on one interface. i tried doing it but it is not allowing.

    Thank you so much in adavance for all your support.




  • 6.  RE: NGFW feature licencing and dual stack.

    Posted Mar 17, 2023 04:20 AM

    Easy...

    In the deployment page, click on the +ip link next to your interface. A new IP-address box will appear. Hit the ipv4 link below it to toggle it to IPv6 and you are set.



    ------------------------------
    Jan-Willem
    ------------------------------



  • 7.  RE: NGFW feature licencing and dual stack.

    Posted Jun 27, 2023 08:11 AM

    Hi Team,

    In bit of bind with this one, hope someone can advice further.
    Our organization has Aruba SDWAN as a service from service provider that include transport (undelay) links.
    In current legacy infra we already have IPv4 and IPv6 and Our organization is planning  to implement IPv6 along with IPv4 on SDWAN also.
    However, the response that we receive are Aruba will not support segmentation with IPv6 and IPv4 together.

    Wanted to check if this is true? If yes, whether Aruba has plan to come up with some solution.

    Can we have any specific document for the same.


    Thank you so much in advance.




  • 8.  RE: NGFW feature licencing and dual stack.

    EMPLOYEE
    Posted Mar 31, 2023 12:09 PM

    Adding more to this thread,

    NGFW was added in Orchestrator and ECOS v9.2.0 so you'll need to upgrade first. You can use Templates to add NGFW to groups of appliances with different settings in each Template.  Here's a snippet from the release notes.

    Feature
    Firewall Protection Profiles
    Users can now add firewall protection profiles in the Configuration menu. Protection profiles allow users to define firewall thresholds around specific threats and security objectives of an environment where the firewall will be used, map the profile to a segment or zone of the firewall, and quickly add/edit the profile as a template.