background image

ION 9000 HARDWARE REFERENCE   |   Install the ION 9000   

31

©

 2021 Palo Alto Networks, Inc.

Connect the controller 1 port to a copper 1G ethernet port, similar to how client PC or Laptops are

connected to a corporate network. Ensure that you allow outbound internet access on port 443 to enable

communication between the controller port and the Prisma SD-WAN controller service.
After this port is connected and the ION 9000 powered on, the ION 9000 automatically connects and

registers with the Prisma SD-WAN controller. After the registration, the ION 9000 is available for claiming

and configuration in the Prisma SD-WAN console.

Configure Peering Ports

The Prisma SD-WAN ION 9000 uses the peering ports to communicate with WAN edge or core or WAN

distribution routers via BGP. The routers may be connected using one physical port per router or multiple

routers can share a single port by using a shared Layer 2 VLAN.
The below figure shows the peering port topologies of an ION 9000.

Depending on the number, type and choice of routers and Layer 2 or Layer 3 configurations, the number of

peering ports required may vary. However, any non-controller port may be used for a peering port. These

ports are set-up and identified at configuration time.
To pre-cable the peering ports before configuration:
1. Plan the type and the number of ION 9000 ports needed for peering configuration.
2. Physically plug in the ports from the ION 9000 devices to the appropriate routers or switches.
3. Record the ION port numbers and connecting router or switch port information for future reference.

Configure Internet Ports

The Prisma SD-WAN ION 9000 uses the internet ports to receive inbound VPN connections from the

internet. Typically, ION 9000 devices use one internet port per data center and this port must be able to

receive traffic from the internet.
The internet port must specifically allow inbound UDP 4500 to the ION 9000 from remote ION devices.

If a firewall or NAT is used outside the ION 9000 on this port, UDP 4500 needs to be port forwarded or

passed-through from the firewall or NAT device.
To pre-cable the internet ports before configuration:
1. Plan the type and the number of ION 9000 ports needed for VPN configuration.
2. Physically plug in the ports from the ION 9000 devices to the appropriate devices.
3. Record the ION port numbers and connecting device port information for future reference.

Содержание Prisma SD-WAN ION 9000

Страница 1: ...ION 9000 Hardware Reference paloaltonetworks com documentation...

Страница 2: ...ecific topic go to our search page www paloaltonetworks com documentation document search html Have feedback or questions for us Leave a comment on any page in the portal or write to us at documentati...

Страница 3: ...LEDs 19 ION 9000 Specifications 20 ION Device Compliance Statement 22 ION 9000 Installation Kit Components 23 Power on the ION 9000 24 Shut down the ION 9000 24 Reboot the ION 9000 24 Install the ION...

Страница 4: ...iv TABLE OF CONTENTS...

Страница 5: ...u install or service a Palo Alto Networks next generation firewall or appliance The following topics apply to all Palo Alto Networks firewalls and appliances except where noted Tamper Proof Statement...

Страница 6: ...6 ION 9000 HARDWARE REFERENCE Before You Begin 2021 Palo Alto Networks Inc...

Страница 7: ...g shipping verify the following upon receipt of each product The tracking number provided to you electronically when ordering the product matches the tracking number that is physically labeled on the...

Страница 8: ...ARDWARE REFERENCE Before You Begin 2021 Palo Alto Networks Inc Third Party Component Support Before you consider installing third party hardware read the Palo Alto Networks Third Party Component Suppo...

Страница 9: ...e EMC regulations French Translation Des c bles Ethernet blind s reli s la terre doivent tre utilis s pour garantir la conformit de l organisme aux missions lectromagn tiques CEM ION 7000 and ION 9000...

Страница 10: ...ue consulter la rubrique des caract ristiques lectriques dans la documentation de votre mat riel de pare feu ou votre dispositif Do not replace a battery with an incorrect battery type doing so can ca...

Страница 11: ...ION 9000 HARDWARE REFERENCE Before You Begin 11 2021 Palo Alto Networks Inc...

Страница 12: ...12 ION 9000 HARDWARE REFERENCE Before You Begin 2021 Palo Alto Networks Inc Applicable to ION 9000...

Страница 13: ...ION 9000 HARDWARE REFERENCE Before You Begin 13 2021 Palo Alto Networks Inc...

Страница 14: ...14 ION 9000 HARDWARE REFERENCE Before You Begin...

Страница 15: ...isma SD WAN Instant On Network ION 9000 and plan your deployment ION 9000 ION 9000 Ports ION 9000 Front Panel with LEDs ION 9000 Specifications ION Device Compliance Statement ION 9000 Installation Ki...

Страница 16: ...16 ION 9000 HARDWARE REFERENCE ION 9000 Overview 2021 Palo Alto Networks Inc...

Страница 17: ...ing traditional standards based routing protocols Deploy the ION 9000 in an off path model enabling elastic non disruptive scale out and high availability HA The ION 9000 Establishes connectivity to t...

Страница 18: ...installed system USB Port This port is reserved for future use Controller Ports This port is used by the ION device to communicate with the Prisma SD WAN controller By default controller ports are DHC...

Страница 19: ...on Displays power status Green light Powered on Black light Powered off Displays Controller connectivity status Blue light Connected No light Not Connected Displays disk status Orange light blinking D...

Страница 20: ...000 RJ45 Port pairs 1 2 3 4 5 6 and 7 8 have programmable inline fail to wire capability for use in branch device mode Throughput Throughput Up to 10 Gbps Power and Mechanical Type Watts 1 1 Hot swapp...

Страница 21: ...ore gigabit or ten gigabit ports for other features BGP peers Layer 2 connectivity to two separate network devices that are currently participating in any dynamic routing protocol BGP OSPF EIGRP with...

Страница 22: ...or peripheral This equipment has been tested and found to comply with the limits for a Class A digital device pursuant to Part 15 of the FCC Rules These limits are designed to provide reasonable prote...

Страница 23: ...inch 1RU rack mount sliding rails built in with quick attach square hole adapters 2x Mounting brackets with accompanying screws 2x 19 inch slide lock ears with accompanying screws 2x Red Cat 5E crosso...

Страница 24: ...the ION 9000 Shut down the ION 9000 in the following ways Shut down using the Device Toolkit commands Run the device toolkit command debug shutdown to shut down the device Ensure the device is physica...

Страница 25: ...25 Install the ION 9000 Deploy the Prisma SD WAN ION 9000 in the following modes Rack Mount the ION 9000 Install the ION 9000 in Virtual In Path Configuration Install ION 9000 in High Availability...

Страница 26: ...26 ION 9000 HARDWARE REFERENCE Install the ION 9000 2021 Palo Alto Networks Inc...

Страница 27: ...the chassis mounting brackets from the rails by extending the bracket out and sliding the bracket release button towards the front to fully withdraw it from the rails The ION 9000 uses the chassis mou...

Страница 28: ...o not detach the screws from the rails before inserting in the racks If the rack has threaded round holes 1 Use fitting pins in the rack mounting kit and screw them through the rack holes 2 Screw the...

Страница 29: ...e rack Ensure that the spring retention clip is fully engaged so that the rail is securely attached to the rack STEP 3 Slide the ION 9000 into the rails 1 Align the mounting brackets on the ION 9000 w...

Страница 30: ...y Horizontally scale based on load and site number and geographic distribution Seamlessly transition traffic to another ION 9000 or the legacy routing network when there is a failure The following fig...

Страница 31: ...required may vary However any non controller port may be used for a peering port These ports are set up and identified at configuration time To pre cable the peering ports before configuration 1 Plan...

Страница 32: ...st ION device The IP addresses for the core and WAN edge peering ports are unique for each ION device and their peering addresses are allocated a 29 or larger subnet block The IP addresses for the int...

Страница 33: ...ERENCE Install the ION 9000 33 2021 Palo Alto Networks Inc The following image illustrates the logical connectivity and IP addressing for the ION 9000 HA The following image illustrates the setting up...

Страница 34: ...34 ION 9000 HARDWARE REFERENCE Install the ION 9000...

Отзывы: