SD-WAN

nevermind wind, no matter rain

BGP over IPSec between VMware SD-WAN Edge and Cisco IOS

Configurations

Configuration of the SD-WAN Edge ABCD-Edge1

Under Configure –> Network Services, define the two Non SD-WAN Destinations via Edge. Please note in this POST, it is Generic IKEv2 (not IKEv1).

Figure 2 – IPSec Configuration to R-IPSec1
Figure 3 – IPSec Configuration to R-IPSec2
Figure 4 – Enable Branch to Non SD-WAN Destination via Edge under Cloud VPN

Figure 4 shows in order to enable the IPSec from the ABCD-VCE1, under “Cloud VPN –> Branch to Non SD-WAN Destination via Edge”, create the two corresponding tunnels by selecting “IPSec1” and “IPSec2” created previously. If you wonder where to put the pre-shared key, it is at the window by clicking either “Add” or “Edit” under the action column.

Figure 5 – The “Edit” or “Add” button allows configure the Pre-Shared Key

At this point, the IPSec configurations are completed. The next configuration we have to perform is the BGP over IPSec, check Figure 6 below:

Figure 6 – BGP configuration of ABCD-Edge1

The area I would like to highlight are, firstly, for BGP over IPSec, the neighbors are created under “NSD Neighbors” instead of the normal “Neighbors”. Secondly, the tunnel IP address 169.254.80.2 and 169.254.80.6 are configured under the option called “Local IP” of “Additional Options”. The other fields of the GUI I believe they are self-explanatory.

BGP over IPSec between VMware SD-WAN Edge and Cisco IOS

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top