Internal Subnets

Configuration > Overlays & Security > Internal Subnets

Use the Internal Subnets dialog box to define which subnets are internal to your SD-WAN fabric and which are external (internet-bound). This classification determines how appliances route traffic, as follows:

  • Internal traffic: Destinations that match an entry in the Internal Subnets table are considered part of your internal network. This traffic is sent over configured overlay tunnels to other branches or hubs within the SD-WAN fabric. EdgeConnect appliances ship with default private addresses: RFC 1918 for IPv4 and ULA for IPv6. Traffic marked as Internal is not subject to local breakout, HPE SSE, Zscaler, Netskope, or Service Orchestration handling.

  • External traffic: Destinations that do not match any entry in the Internal Subnets table are internet-bound. External traffic enters the Breakout Traffic to Internet & Cloud Services pipeline as depicted on the Business Intent Overlays tab. This traffic is routed based on the preferred policy order configured in the Business Intent Overlay (BIO).

The Internal Subnets configuration is part of the Business Intent Overlays tab and is common across all BIOs and all appliances within the fabric. For more information, see Business Intent Overlays.

Add Internal Subnets

You can configure internal subnets for the global segment or for specific VRF segments. The Internal Subnets table supports both IPv4 and IPv6 subnets (up to 512 for each).

NOTE: You can include non-default routes as internal subnets to significantly extend the number of destinations that can be classified as internal. See Consider Non-default Routes as Internal Subnets below.

To add an internal subnet:

  1. Navigate to Configuration > Overlays & Security > Internal Subnets.

    The Internal Subnets dialog box opens.

  2. Click Add.

    A second Internal Subnets dialog box opens.

  3. From the Segment drop-down list, select All for the global segment or select a specific VRF segment. Listed VRF segments are defined on the Routing Segmentation (VRF) tab.

  4. In the Subnet / Mask field, enter the subnet in CIDR notation (for example, 10.0.0.0/8 for IPv4 or 2001:db8::/32 for IPv6).

  5. Click Save.

  6. On the initial Internal Subnets dialog box, click Save.

NOTE: To edit an internal subnet, hover over the Actions column for the subnet and click the edit icon. To delete an internal subnet, hover over the Actions column for the subnet and click the delete icon.

Add or Replace Internal Subnets in Bulk

You can add internal subnets in bulk to the Internal Subnets table or replace the current list of internal subnets in the table with a new list.

  1. On the Internal Subnets dialog box, click Bulk Add/Replace.

    The Bulk Add/Replace Internal Subnets dialog box opens.

  2. From the Segment drop-down list, select All for the global segment or select a specific VRF segment.

  3. In the unlabeled box below the Segment field, enter subnets in CIDR notation separated by commas.

  4. To add the subnets to the Internal Subnets table, click Save, or click Replace to replace the subnets currently listed in the table with these new subnets.

  5. On the Internal Subnets dialog box, click Save.

Consider Non-default Routes as Internal Subnets

In addition to manually configured subnets, you can include non-default routes as internal subnets. This provides a way to significantly extend the number of destinations you can classify as internal. It ensures that internal traffic is not inadvertently sent to the internet due to a missing entry in the Internal Subnets table.

Manually configured internal subnets are evaluated first. If no match is found, Orchestrator does a non-default route lookup.

To set this up, on the Internal Subnets dialog box, click the Consider non-default routes as internal subnets check box, and then click Save.