Configuring Uplink Interfaces on Branch Gateways

To configure uplink interfaces on Branch Gateways, complete the following steps:

  1. To configure a Branch Gateway group or a Branch Gateway, complete one of the following steps:

    • To select a gateway group:

      1. In the Classic Central app, set the filter to a group that contains at least one Branch Gateway.

        The dashboard context for a group is displayed.

      2. Under Manage, click Devices > Gateways.

        A list of gateways is displayed in the List view.

      3. Click Config.

        The configuration page is displayed for the selected group.

    • To select a gateway:

      1. In the Classic Central app, set the filter to Global or a group that contains at least one Branch Gateway.

      2. Under Manage, click Devices > Gateways.

        A list of gateways is displayed in the List view.

      3. Click a gateway under Device Name.

        The dashboard context for the gateway is displayed.

      4. Under Manage, click Device.

        The gateway device configuration page is displayed.

  2. If you are in the Basic Mode, click Advanced Mode to access the advanced configuration options.

  3. Go to WAN > Uplink. The Uplink configuration page opens.

  4. To enable data compression, select the Compression check box.

  5. Select any one of the following load balancing modes:

    • Round Robin—To equally distribute traffic among all active uplinks on a round robin basis. By default, Branch Gateway uses the round robin mode for balancing load across uplinks.

    • Session Count—To balance traffic among the uplinks based on the number of sessions managed by each link, so that the load for each active uplink stays within 5% of the other active uplinks. For example, if there are two active uplinks with the Weight parameter defined as 10 and 20, the active uplink with a weight of 20 will have more sessions assigned.

    • Uplink utilization—To distribute traffic between active WAN Wide Area Network. WAN is a telecommunications network or computer network that extends over a large geographical distance. uplinks based on the utilization % of each active WAN uplink. Uplink utilization considers the link speed to calculate the utilization and allows a maximum percentage of bandwidth threshold to be defined. When the bandwidth threshold exceeds, the WAN uplink is no-longer considered for session allocation.

  6. To add an uplink, click + in the Uplink VLANs table and enter the following values to define an uplink VLAN Virtual Local Area Network. In computer networking, a single Layer 2 network may be partitioned to create multiple distinct broadcast domains, which are mutually isolated so that packets can only pass between them through one or more routers; such a domain is referred to as a Virtual Local Area Network, Virtual LAN, or VLAN. for an uplink interface on the Branch Gateway:

  7. Click Save Settings.

Configuring an MPLS, Metro-Ethernet, or an INET Uplink

To configure an MPLS Multiprotocol Label Switching. The MPLS protocol speeds up and shapes network traffic flows. , or a Metro-Ethernet Ethernet is a network protocol for data transmission over LAN., or an INET uplink, select the uplink type from the drop-down list, and enter details for the parameters provided in the following table:

Table 1: MPLS, Metro-Ethernet, or an INET Uplink Configuration Parameters

Parameter

Description

Link Name

Specify the name of the uplink.

Interface VLAN ID

Specify the VLAN ID that you want to assign to the uplink.

Operation state

Use this check box to disable or re-enable the uplink. By default, uplinks are enabled.

Use only as backup link

By default, all uplinks operate as active uplinks. If you want to use the uplink in the standby mode, select this check box.

Backup health check

If you want to check the reachability of the uplink, select this check box.

NOTE: This option is available only if Use only as backup link option is selected.

Probe Frequency Use this field to configure a custom value for probe frequency to enable Health Check probing for Backup Uplink. By default, the value will be set as 1500 sec.

Bandwidth Percentage

Use this field to configure bandwidth percentage for uplink utilization. This field is available only for the Uplink utilization load balancing mode.

Source NAT VLAN

You can select a VLAN, which is set to Force operational status UP, to perform source NAT Source NAT changes the source address of the packets passing through the router. Source NAT is typically used when an internal (private) host initiates a session to an external (public) host. on all IP unicast packets exiting from an uplink.

For more information on configuring Force operational status UP, see Configuring Other Parameters for VLAN.

Speed

You can configure a custom value for uplink speed to optimize performance. The allowed range of values is 1–10000 Mbps. If not set, the WAN uplink speed defaults to auto-negotiated port speed for INET, MPLS, and Metro-Ethernet. Based on the speed and bandwidth threshold allowed for an uplink, Branch Gateways assign session traffic.

Weight

For Round Robin and Session Count load balancing modes, you can define a value for Weight within a range of 1–100.

By default, this is set to 10. In an active-active uplink scenario, an uplink with a higher weight is assigned more session traffic than an uplink with a lower weight.

Tunnel max bandwidth threshold

To limit the amount of traffic transmitted from an HPE Aruba Networking gateway, configure the maximum transmit rate based on the WAN uplink bandwidth. For example, if the bandwidth of a WAN uplink is 15 Mbps and you want to limit the traffic transmission to 1.5 Mbps, you must configure the maximum bandwidth threshold as 10%. To apply the tunnel limits, a tunnel renegotiation followed by a tunnel flap is triggered on the Branch Gateway.

NOTE: The maximum bandwidth threshold is applied on the VPNCs during the next tunnel rekey.

SD-WAN Overlay Tunnels Over L2 Networks

EdgeConnect SD-Branch Gateways can build SD-WAN Software-Defined Wide Area Network. SD-WAN is an application for applying SDN technology to WAN connections that connect enterprise networks across disparate geographical locations. overlays over L2 circuits such as VPLS networks, dark fiber networks or point-to-point links. EdgeConnect SD-Branch Gateways and VPNCs can exist in the same L2 WAN and connect to each other either by hub-spoke or branch-mesh topologies with IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnels. In all the supported environments, orchestrated IPsec tunnels are established between two peers that are in the same L2 or broadcast domain. This applies to all the supported topologies such as Hub and Spoke, Hub MESH, or even Branch MESH.

To enable this behavior, no configuration changes are required. When EdgeConnect SD-Branch Gateways detect that the other side of the tunnel is in the same L2 domain, they automatically switch their behavior to adjust to the nature of the circuit.

L2 WAN Circuits are only supported when the uplink type is set to MPLS.

You need to configure a default gateway on the L2 WAN uplink either by static configuration or using a Dynamic Host Configuration Protocol (DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. ).

To establish communication with Classic Central through an L2 WAN interface, a default gateway should be associated to that Uplink VLAN. Other HPE Aruba Networking Gateways participating in the SD-WAN overlay cannot serve as that default gateway that enables communication with Classic Central or other external resources.

Configuring an LTE Uplink

To configure an LTE Long Term Evolution. LTE is a 4G wireless communication standard that provides high-speed wireless communication for mobile phones and data terminals. See 4G. uplink, select LTE from the drop-down list, and enter details for the parameters provided in the following table:

Table 2: LTE Uplink Configuration Parameters

Parameter

Description

Link Name

Specify the name of the uplink.

Connection type

Specify one of the following connection types:

By default, USB is selected.

NOTE: For a 9004-LTE Branch Gateway, the default connection type is Internal.

Model vendor/model

Specify one of the following Model vendor/model name:

  • HPE Aruba Networking
  • Third party

If you have selected HPE Aruba Networking as the Model vendor ,enter details for the following parameters:

Access point name (APN) Enter the name of the Access Point to which the uplink connects.
Public land mobile network (PLMN Public Land Mobile Network. PLMS is a network established and operated by an administration or by a Recognized Operating Agency for the specific purpose of providing land mobile telecommunications services to the public.) A PLMN ID is a six digit ID which is a combination of Mobile Country Code and Mobile Network Code. Each service provider has their own PLMN code. This field allows you to restrict roaming. Select Auto or Manual for the PLMN mode. If you have selected Manual, enter the PLMN ID in the text box. By default, PLMN is on Auto mode.
Mode

Select one of the following network modes:

  • Auto—This mode keeps both 3G and 4G LTE options open and switches based on availability.
  • 4G LTE—Connects to the 4G LTE cellular network and takes the default frequency band.
  • 3G—Connects to the 3G cellular network and takes the default frequency band.
  • Custom—If you want to select one of the supported frequency bands for 3G and 4G LTE, select Custom.
3G Third Generation of Wireless Mobile Telecommunications Technology. See W-CDMA. Band Band refers to a specified range of frequencies of electromagnetic radiation. selection Select the desired 3G band from the drop-down list.
4G Fourth Generation of Wireless Mobile Telecommunications Technology. See LTE. LTE Band selection Select the desired 4G LTE band from the drop-down list.

Interface VLAN ID

The VLAN ID assignment is not configurable for 4G LTE USB and Internal uplinks. By default, VLAN ID 4095 is assigned to the 4G LTE USB and Internal uplinks.

NAT Outside Enable the check box.
Use only as backup link Enable the check box. By default, all uplinks operate as active uplinks. If you want to use the uplink in the standby mode, select this check box.

Low frequency probe

This is a global configuration for all LTE connections. Use this check box to enable less-frequent health check probing on the LTE uplink. LTE uplinks normally have lower bandwidth compared to wired uplinks, therefore you may want to enable less frequent probing on the LTE uplinks. When Low frequency probe is enabled, health check probes are sent every 15 seconds with a burst size of 2 packets for all LTE uplink interfaces configured on the Branch Gateway.

Weight For Round Robin and Session Count load balancing modes, you can define a value for Weight within a range of 1–100. By default, this is set to 10. In an active-active uplink scenario, an uplink with a higher weight is assigned more session traffic than an uplink with a lower weight.

Speed

You can configure a custom value for uplink speed to optimize performance. The allowed range of values is 1–10000 Mbps. If not set, the WAN uplink speed defaults to100 Mbps for LTE. Based on the speed and bandwidth threshold allowed for an uplink, Branch Gateways assign session traffic.

If you have selected Third party as the Model vendor , enter details for the following parameters:

Access point name (APN)

Enter the name of the Access Point to which the uplink connects.

Public land mobile network (PLMN)

A PLMN ID is a six digit ID which is a combination of Mobile Country Code and Mobile Network Code. Each service provider has their own PLMN code. This field allows you to restrict roaming. Select Auto or Manual for the PLMN mode. If you have selected Manual, enter the PLMN ID in the text box. By default, PLMN is on Auto mode.

Mode

Select one of the following network modes:

3G Band selection

Select the desired 3G band from the drop-down list.

4G LTE Band selection

Select the desired 4G LTE band from the drop-down list.

Interface VLAN ID

The VLAN ID assignment is not configurable for 4G LTE USB and Internal uplinks. By default, VLAN ID 4095 is assigned to the 4G LTE USB and Internal uplinks.

NAT Network Address Translation. NAT is a method of remapping one IP address space into another by modifying network address information in Internet Protocol (IP) datagram packet headers while they are in transit across a traffic routing device. Outside

Enable the check box.

Use only as backup link

Enable the check box. By default, all uplinks operate as active uplinks. If you want to use the uplink in the standby mode, select this check box.

Low frequency probe

This is a global configuration for all LTE connections. Use this check box to enable less-frequent health check probing on the LTE uplink. LTE uplinks normally have lower bandwidth compared to wired uplinks, therefore you may want to enable less frequent probing on the LTE uplinks. When Low frequency probe is enabled, health check probes are sent every 15 seconds with a burst size of 2 packets for all LTE uplink interfaces configured on the Branch Gateway.

Weight

For Round Robin and Session Count load balancing modes, you can define a value for Weight within a range of 1–100. By default, this is set to 10. In an active-active uplink scenario, an uplink with a higher weight is assigned more session traffic than an uplink with a lower weight.

Speed

You can configure a custom value for uplink speed to optimize performance. The allowed range of values is 1–10000 Mbps. If not set, the WAN uplink speed defaults to100 Mbps for LTE. Based on the speed and bandwidth threshold allowed for an uplink, Branch Gateways assign session traffic.

Huawei E3372h-320 modem:

Enable the check box to select the modem.

The following animation shows you how to configure uplink interfaces on Branch Gateways.