In the dynamic landscape of modern business, a secure and reliable network infrastructure is paramount. Exium's Secure Access Service Edge (SASE) solution incorporates a powerful built-in Software-Defined Wide Area Networking (SD-WAN) feature to elevate your network performance, ensuring robust connectivity and heightened security.
Key Capabilities of Multi-WAN Feature of the cyber Gateway
1
Failover Support
Exium's SD-WAN seamlessly manages multiple Wide Area Network (WAN) or Internet Service Provider (ISP) links. In the event of a link failure, the solution dynamically reroutes traffic to the available and operational links, ensuring uninterrupted connectivity. This inherent failover capability provides businesses with continuous access to critical applications and resources, even in the face of network disruptions.
2
Load Balancing
The built-in SD-WAN intelligently distributes network traffic across two or more WAN links, optimizing the utilization of available bandwidth. This load balancing feature prevents network congestion, enhances overall performance, and ensures efficient resource utilization. This results in a smoother user experience and improved productivity across the organization.
3
Application-Aware Routing
Exium's SD-WAN goes beyond conventional routing by offering application-aware intelligence. It identifies and categorizes network traffic based on the application type, allowing for customized routing decisions. For instance, the solution can prioritize latency-sensitive applications like Microsoft Teams by steering their traffic over the WAN link with lower latency. This application-aware routing optimizes the user experience for real-time communication and collaboration tools.
4
Enhanced Security
The integration of SD-WAN within Exium's SASE solution extends beyond performance optimization to fortify security measures. By dynamically steering traffic based on application characteristics, the solution aids in traffic segmentation, preventing security threats from spreading across the network. This proactive security approach ensures a resilient defense against emerging cyber threats.
Achieve optimal network performance through dynamic load balancing and intelligent traffic routing, enhancing user experience and productivity.
2
Continuous Connectivity
Ensure uninterrupted access to critical applications and resources by leveraging failover support across multiple WAN links.
3
Application-Centric Prioritization
Prioritize critical applications based on business needs, enhancing the performance of latency-sensitive applications like Microsoft Teams.
4
Security Resilience
The integrated SD-WAN enhances network security by enabling traffic segmentation, reducing the risk of cyber threats and ensuring a robust defense posture.
Exium support both Single-interface and Multi-interface versions for the Cyber Gateways deployment. However, the Multi-WAN support (as obvious) is only provided in the Multi-interface version. You can deploy the Cyber Gateways on Hardware, in a VM or on Public Cloud of your choice.
A Multi-WAN scenario where the hardware or VM supports multiple network interfaces is shown below. An example of recommended hardware for the Cyber Gateway that supports 4 physical network interfaces is HUNSN Micro Firewall Appliance.
A Multi-WAN deployment scenario with high-availability (HA) is provided below. In the HA deployment, we recommend using a switch on the WAN side as it simplifies the cabling and also accommodate cases where the ISP modem/ router provides only one or limited network interfaces for connectivity.
In case where the Cyber Gateway does not have enough physical network interfaces, Exium can also create virtual network interfaces on the same physical interface to accommodate the Multi-WAN. At a minimum you need a box that supports two physical interfaces, one for the LAN and the other for the WAN to keep the LAN and WAN traffic physically separate.
Click on Sites → Cyber Gateways in the left menu bar → Add Gateway (Skip if CGW already exists)
Toggle Multi WAN to switch to Yes in SD-WAN configuration section
Toggle WAN Static IP to switch to Yes in SD-WAN configuration section, if you want to use static IP addresses on both WAN interfaces, Skip and refer below section for Dynamic IPs on WAN interfaces in case you don't have static IPs for WAN interfaces.
Add WAN1 IP (Primary) and WAN1 Gateway (Primary) details as shown in picture
Add WAN2 IP (Secondary) and WAN2 Gateway (Secondary) details as shown in picture
¶ Modification on existing CGW where Multi WAN is already enabled?
If Multi WAN configuration is enabled on existing CGW, redeployment/reinstallation of CGW will be required. Dynamic Update will not work.
During reinstallation or fresh installation, you must choose LAN, WAN1 and WAN2 when input is prompted to select interfaces. Refer section Steps to Install the Cyber gateway in document Multi Interface CGW deployment.
In case CGW is already deployed with Multi WAN option and both WAN IPs were already configured statically, modification of WAN interface and Gateway IPs does not require reinstallation. They will be updated automatically within ~5 mins on CGW machine.
In case, CGW is already deployed with Multi WAN option and both WANs were not configured with static IPs, then you can add WAN IPs statically with their Gateway IPs. They will be updated automatically within ~5 mins on CGW machine.
To use Dynamic IPs on WAN Interfaces in case Multi Interface option is enabled:
Select WAN Static IP as No in section SD-WAN
Select Multi WAN as Yes in section SD-WAN
Save the configuration.
If Multi WAN configuration is enabled on existing CGW, redeployment/reinstallation of CGW will be required. Dynamic Update will not work.
During reinstallation or fresh installation, you must choose LAN, WAN1 and WAN2 when input is prompted to select interfaces. Refer section Steps to Install the Cyber gateway in document Multi Interface CGW deployment.
¶ Configuring Multi-WAN Load Balance traffic distribution
To configure Multi-WAN Load-balance traffic distribution
Continuation to above step to configure CGW with Multi-WAN configuration, for WAN load balancing
In Load Balance section, select Weightage
Update Traffic Distribution weightage between 2 WAN links (in percentages)
Save the configuration. CGW will be updated automatically in few mins.
Exium's SASE solution, fortified with built-in SD-WAN capabilities, empowers organizations to navigate the complexities of modern networking. By combining reliability, performance optimization, and advanced security features, businesses can foster a resilient and secure network infrastructure to meet the demands of the digital era.
To learn more about implementing SASE for your organization and explore tailored solutions that meet your unique requirements, contact Exium at partners@exium.net for a consultation or demonstration. If you are ready to get started, check out our testing and onboarding process.