SD-WAN

 View Only
last person joined: 2 days ago 

Forum to discuss HPE Aruba EdgeConnect SD-WAN and SD-Branch solutions. This includes SD-WAN Orchestration WAN edge network functions - routing, security, zone-based firewall, segmentation and WAN optimization, micro-branch solutions, best practics, and third-party integrations. All things SD-WAN!
Expand all | Collapse all

Private connection between Silverpeak sites that currently use public Internet exclusively.

This thread has been viewed 31 times
  • 1.  Private connection between Silverpeak sites that currently use public Internet exclusively.

    Posted Aug 08, 2023 01:05 PM

    [[ Thank you all for your responses, I have the answers that I need now.
    An update in the BIO will allow me to do what I need to do. ]]

    All of our sites currently establish tunnels over public internet connections and are working properly. 
    Many are dual-homed to multiple ISPs without issue. Tunnels are established and fail over as designed.
    For the purpose of this discussion, let's assume that these are all 1Gb ISP lines and a full mesh of SDWAN tunnels.

    Two specific sites require more bandwidth than we can provide over ISP connections for site-to-site bulk file transfers.
    I have the ability to provide a 10Gb dark fiber connection between the two.
    If I present this network to each Silverpeak's WAN interface as another .1q subinterface, will the two impacted appliances automatically recognize this as a shorter path for this specific tunnel?
    Or is additional configuration needed in the underlay?



  • 2.  RE: Private connection between Silverpeak sites that currently use public Internet exclusively.

    EMPLOYEE
    Posted Aug 09, 2023 02:45 AM

    Not sure I understand your statement --- you have 2 EC that build tunnel over 1GInternet are working fine already, and now you want to bulld the new tunnel over 10G private link, and your concern is whether it will affect the exsting routing?

    It is all about BIO setting:

    you need to look at the BIO setting, and make sure that the WAN label name that you will use for the new 10G link if not in the primary path of any BIO. I will suggest you to create the new WAN label and assign the 10G link with that new label, after that you go into BIO, you will see the new label, you can either drag them into the primary path, or secondary path, all up to you.




  • 3.  RE: Private connection between Silverpeak sites that currently use public Internet exclusively.

    Posted Aug 09, 2023 03:00 AM

    The two site will recognize each other and build a tunnel between them per the configuration of BIO's and WAN interface labels. @10Gbps plus your regular ISP connections the hardware capacity you have will be exceeded, so you will be in unsupported land.

    There are a number of options to prevent tunnels from forming between the two locations:

    • Give them the same site name. That has consequences for how the remotes connect to this logical site and traffic destined for the 2nd half landing on the 1st half needs to be routed across on the LAN side
    • Configure tunnel exceptions
    • Don't label the new 10Gbps path or give it an unused label (avoids warnings)

    With no tunnels present you can simply use it as a router interface.

    Again, given the speeds you'll likely be in unsupported land. Discuss with your supplier or local Aruba SE on the best option, config details and caveats.

    not 100% about the network layout, but putting a L3-Switch between the WAN interfaces and bypassing the Silver Peak for the new VLAN could be an alternative.




  • 4.  RE: Private connection between Silverpeak sites that currently use public Internet exclusively.

    EMPLOYEE
    Posted Aug 09, 2023 01:09 PM

    To answer your question regarding "will the two impacted appliances automatically recognize this as a shorter path for this specific tunnel? for the bulk transfer.

    my 2 cents, I would use either route policy to match the file transfer to steer it via the 10gig or use the BIO waterfall path loading and manually select the fixed link order, this will assure the 10GIG will be selected for the bulk BIO.




  • 5.  RE: Private connection between Silverpeak sites that currently use public Internet exclusively.

    EMPLOYEE
    Posted Aug 10, 2023 02:36 AM

    The short answer is: If the Overlay is in High Quality mode then yes, the EdgeConnect will send packets to the link with the highest quality based on an internal metric that combines Latency and Loss. The algorithm used by the internal/in-house metric is: latency(ms)/100+20*floor(loss(%))

    Also, for High Quality mode the EC will waterfall once > 5ms Wait Time is observed in the associated shaper traffic class. So if you want to use 1Gbps of the 10Gbps dark fiber you would set the Deployment page values to "1,000,000". Once the 1Gbps link is filled High Quality mode will begin waterfalling packets to the next best link by internal/in-house metric.