Auto Secure Peering initiated from PE appliance at DC site and branch site PE appliance 编辑
Configuration
To configure auto secure peering on a new Premium (Enterprise) Edition appliance at DC:
- PE DC appliance is in LISTEN ON mode (on port 443). Branch PE appliance is in CONNECT-TO mode.
- PE DC appliance initiates automatic secure peering to a PE Branch appliance which installs the Private CA Certs and CERT KEY Pairs and configures CONNECT-TO on the PE Branch appliance with DC EE’s LISTEN-ON IP.
- LISTEN-ON IP for PE appliance is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.
In the SD-WAN web GUI, navigate to Configuration > WAN Optimization > Secure Acceleration > Secure Peering.
Configure keystore by providing the keystore password or by disabling keystore.
Enable Secure Peering by selecting Private CA to perform AUTOMATIC SECURE PEERING.
Click the ‘+’ icon and to add IP with username and password. After successful authentication with the remote IP and credentials provided, a request is sent to the remote machine that will install CA Certificate and the Private cert and key for itself locally on the remote machine.
Note
IP Address – IP Address of remote EE Appliance MANAGEMENT IP
Username – Username of remote EE Appliance
Password – Password of remote EE Appliance
Monitoring
To validate if the Private CA and Private Certificate Key pair is generated successfully, review the information displayed below.
View Secure Partner Information on the Premium (Enterprise) Edition appliance under Monitoring > WAN Optimization > Partners page.
On partner appliance, view Secure Partner Information on the Premium (Enterprise) Edition Appliance under Monitoring > Partners & Plug-ins > Secure Partners page.
Troubleshooting
View Secure Partner Success / Failure Information on the Premium (Enterprise) Edition Appliance under Monitoring > WAN Optimization > Partners > Secure Partners page.
On partner appliance, view Secure Partner Information on the Premium (Enterprise) Edition Appliance under Monitoring > Partners & Plug-ins > Secure Partners page.
On partner Appliance, view Secure Partner Information on the Premium (Enterprise) Edition Appliance under Monitoring > Appliance Performance > Logging page.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论