Secure peering 编辑

Premium (Enterprise) Edition appliance can be installed at the data center and can initiate auto or manual secure peering, create SSL profile and associate service class, and join the appliance to a Windows Domain Controller for allowing users/administrator to use extended rich feature of standalone WANOP appliance.

Following are the deployment modes supported for Auto Secure Peering and Manual Secure Peering:

Auto Secure Peering deployments:

To perform auto secure peering to a PE appliance from a standalone WANOP / SDWAN SE/WANOP on the DC site.

Steps to initiate this deployment:

  • WANOP DC appliance is in LISTEN ON mode (2312/Any non-standard port) and Branch PE is in CONNECT-TO mode.
  • WANOP DC initiates automatic secure peering to a PE appliance which installs the Private CA Certs and CERT KEY Pairs and configure CONNECT-TO on the PE appliance with WANOPs LISTEN-ON IP.

To perform Auto-secure peering initiated from PE appliance at DC site and Branch site PE appliance.

Steps to initiate this deployment:

  • PE DC appliance is in LISTEN ON mode (on port 443). Branch PE is in CONNECT-TO mode.
  • PE DC appliance initiates automatic secure peering to a PE Branch appliance which installs the Private CA Certs and CERT KEY Pairs and configures CONNECT-TO on the PE Branch appliance with DC PE’s LISTEN-ON IP.
  • LISTEN-ON IP for PE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.

Auto Secure Peering initiated from PE Appliance at DC site and Branch with WANOP/ SDWAN SE appliance.

Steps to initiate this deployment:

  • PE DC appliance is in LISTEN ON mode (on port 443). Branch WANOP / SD-WAN SE is in CONNECT-TO mode.
  • PE DC appliance initiates automatic secure peering to Branch WANOP / SD-WAN SE appliance which installs the Private CA Certs and CERT KEY Pairs and configures CONNECT-TO on the PE appliance with DC PE’s LISTEN-ON IP.

Manual Secure Peering deployments:

Manual Secure Peering initiated from PE appliance at DC site to Branch PE Appliance.

Steps to initiate this deployment:

  • PE DC appliance is in LISTEN ON mode (on port 443). Branch PE is in CONNECT-TO mode.
  • LISTEN-ON IP for PE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled.
  • Manually upload CA and Cert Key pair certificates obtained from authentic source of certificate authority.

Manual Secure Peering initiated from PE appliance at DC site to Branch WANOP/SDWAN-SE Appliance.

Steps to initiate this deployment:

  • PE DC appliance is in LISTEN ON mode (on port 443). Branch WANOP / SD-WAN SE is in CONNECT-TO mode.
  • LISTEN-ON IP for PE is in the interface IP associated to the routing domain for which “Redirect to WANOP” is enabled
  • Manually upload CA and Cert Key pair certificates obtained from authentic source of certificate authority.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。
列表为空,暂无数据

词条统计

浏览:0 次

字数:3866

最后编辑:7年前

编辑次数:0 次

    我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
    原文