Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Configuring NextHop List
Microbranch APs leverage IP-SLA probes to monitor the health of SSE tunnels orchestrated by Cloud Connect. These probes actively measure tunnel liveness by sending requests (HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands., HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection., or ICMP Internet Control Message Protocol. ICMP is an error reporting protocol. It is used by network devices such as routers, to send error messages and operational information to the source IP address when network problems prevent delivery of IP packets.) to endpoints defined by Cloud Connect. The results, such as latency, packet loss, and reachability, are used to determine which next-hop path should be selected for traffic forwarding. This mechanism ensures that traffic is not sent through a degraded or unreachable SSE tunnel, preventing blackholing and improving application performance.
You can configure Microbranch to forward packets to NextHop devices using Policy-Based Routing (PBR Policy-based Routing. PBR provides a flexible mechanism for forwarding data packets based on polices configured by a network administrator.). With a NextHop list, administrators can ensure that when a NextHop device becomes unreachable, packets matching the policy can still reach their destination via an alternate path. IP-SLA probes complement this by providing real-time health checks that inform PBR decisions, enabling dynamic failover and maintaining service continuity.
In addition to SSE tunnels, IP-SLA can also help prevent full-tunneled traffic from being sent through a VPNC or data center experiencing issues. In such scenarios, the branch gateway establishes SD-WAN Software-Defined Wide Area Network. SD-WAN is an application for applying SDN technology to WAN connections that connect enterprise networks across disparate geographical locations. tunnels to a VPNC. To ensure traffic is not dropped beyond the VPNC, the gateway must be able to probe a resource located behind it. This same principle applies to SSE tunnels: by validating the health of the path beyond the tunnel endpoint, Microbranch APs can make intelligent routing decisions that maintain optimal connectivity.
To define a NextHop list, complete the following steps:
-
In the WebUI, set the filter to a Microbranch group that contains at least one AP.
The dashboard context for a group is displayed.
-
Click the Config icon.
The Microbranch group configuration page is displayed.
-
Click Tunnels & Routing > NextHop List.
The NextHop Configuration page is displayed with Name and Preemptive Failover.
-
Click + below the NextHop Configuration table to create a new NextHop destination and configure the following parameters:
Table 1: Routing Rule Parameters
Parameters
Description
Enter the name of the new NextHop list. Ensure the name does not exceed 127 characters. You cannot edit the name of the NextHop list after creating a NextHop list.
Select the checkbox to enable preemptive-failover.
If Preemptive-failover is disabled and the highest-priority device on the NextHop list is disabled, the new primary NextHop device functions as the primary device, even when the initial device comes back online.
Preemptive-failover is enabled by default.
Enable the Preemptive failover for Zscaler tunnels.
Configure the following parameters:
-
IP Address—IP address of the NextHop device.
-
Priority—Priority of the NextHop device. The default value is 128.
If the VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. gets an IP address using DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. and the default gateway is determined by the VLAN interface, the gateway IP is used as the NextHop IP address.
Configure the following parameters:
VLAN ID—VLAN id of the VLAN used by NextHop device.
Priority—Priority of the NextHop device. The default value is 128.
Priorities of NextHops define which NextHop should get a higher priority to carry the session traffic. A higher number indicates a higher priority (1 – 255). If two NextHops have the same priority, they will be load-balanced.
To configure the NextHop as IPSec Map to VPNC, configure the following parameters:
-
Cluster—Select a gateway cluster from the drop-down list.
-
VPNC—Select a VPNC from the drop-down list.
-
Uplink Tag—Select a Uplink from the drop-down list.
-
Priority—Priority of the NextHop device. The default value is 128.
For more information on configuring Cluster and VPNCs, refer Configure Data Center VPNCs. For more information on configuring Uplink tag, refer Configuring the WAN Uplink.
To configure the NextHop to IPSec Map, configure the following parameters:
-
IPSec Map—Select the applicable IPSec map in the IPSec map name drop-down list. For more information on Zscaler IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. map, refer to Microbranch Integration with Zscaler through Cloud Connect Service.
-
Priority—Priority of the NextHop device. The default value is 128.
-
-
Click Save.
A maximum of 24 NextHop list per group and 16 route per NextHop list can be added.
Optionally, to enable or disable Preemptive -failover, do one of the following:
-
Select the NextHop list that you want to edit and click the edit icon.
-
Select the NextHop list route row that you want to edit and click the edit icon.
Click Save.
-
