Install the ION 7000
connected to a copper 1G ethernet port. This port should have access to the outbound internet
access to the Prisma SD-WAN controller service on port 443 (HTTPS).
Aer this port is connected and the ION 7000 powered on, the ION 7000 automacally connects
and registers with the controller. Aer registraon, the ION 7000 is available to claim and
configure in the Prisma SD-WAN console.
ION 7000 Peering Ports
The Prisma SD-WAN ION 7000 uses the peering ports to communicate with WAN edge or core
or WAN distribuon routers using BGP. The routers may be connected using one physical port per
router, or mulple routers can share a single port by using a shared Layer 2 VLAN.
The below figure shows the peering port topologies of an ION 7000.
Depending on the number, type and choice of routers and Layer 2 or Layer 3 configuraons, the
number of peering ports you require may vary. However, any non-controller port may be used for
a peering port. These ports are setup and idenfied at configuraon me.
To pre-cable the peering ports before configuraon:
STEP 1 |
Plan the number and the type of ION 7000 ports needed for peering configuraon.
STEP 2 |
Physically plug in the ports from the ION 7000 devices to the appropriate routers or
switches.
STEP 3 |
Record the ION port numbers and connecng router or switch port informaon for future
reference.
ION 7000 Internet Ports
The Prisma SD-WAN ION 7000 uses the internet ports to receive inbound VPN connecons from
the internet. Typically, ION 7000 devices use one internet port per data center, and this port must
be able to receive traffic from the internet.
This internet port must allow inbound UDP 4500 to the ION 7000 from remote ION devices. If a
firewall or NAT is used outside the ION 7000 on this port, UDP 4500 needs to be port-forwarded
or passed-through from the firewall or NAT device.
To pre-cable the internet ports before configuraon:
STEP 1 |
Plan the number and the type of ION 7000 ports you need for VPN configuraon.
ION 7000 Hardware Reference
26
©
2021 Palo Alto Networks, Inc.