Configure automatic tunnel between Secure Access and Firewall Threat Defense devices using SASE wizard
The SASE wizard simplifies tunnel creation from Firewall Threat Defense devices to Secure Access by automating multiple steps.
Before you begin
Ensure that you review Prerequisites for an automatic tunnel between Secure Access and Firewall Threat Defense devices .
Procedure
Step 1 | Choose , and click Add . |
Step 2 | In the Topology Name field, enter a name for the SASE topology. |
Step 3 | Click the SASE Topology radio button and click Create . |
Step 4 | Configure a Secure Access region by choosing a region from the Region drop-down list: A Secure Access region is a cluster of data centers in a specific geographic area. |
Step 5 | Configure Firewall Threat Defense nodes: |
Step 6 | Configure Tunnel ID and passphrase . |
Step 7 | Configure NAT or routing : |
Step 8 | Check the Deploy to Threat Defense devices check box to trigger deployment of all the configurations besides the Secure Access auto tunnel configurations that are yet to be deployed on the device. |
Step 9 | Click Finish to save and validate the configurations, and create the SASE topology. The wizard performs these actions:
You can view the SASE topology in the Site-to-Site VPN & SD-WAN page ( ). |
What to do next
-
Create an extended Access Control List (ACL).
This ACL defines the specific DNS and web traffic intended for routing through the tunnel to Secure Access . For more information, refer to Configure Extended ACL Objects .
-
Configure the static route to the next hop of the VTI interface.
-
Create a policy-based routing (PBR) policy.
Use the newly created extended ACL within a policy-based routing policy to direct the defined DNS and web traffic through the tunnel to Secure Access for security inspection. For more information, refer to Configure policy-based routing policy .
-
When you create multiple SASE topologies for a multi-ISP setup, configure ECMP zones with the VPN interfaces to balance the load of application traffic.
-
Perform validation. For more information, refer to Validate Secure Access integration with Firewall Threat Defense devices .
