TalalTayyaroğlu's Posts

Good day, I have a problem where I need to route traffic destined for certain networks/hosts to a gateway other than the default router (currently an Edge). Since the Edge which acts as a default g... See more...
Good day, I have a problem where I need to route traffic destined for certain networks/hosts to a gateway other than the default router (currently an Edge). Since the Edge which acts as a default gateway and DHCP server does not support DHCP Option 121, I had to temporarily solve this by configuring static route entries on the workstation level. Something upper management does not look warmly upon (TBH, neither do I). Is it possible to configure internal routing in the Edge to solve this problem? Lets assume the Edge VLAN1 IP address is 10.0.0.1. A Cisco router on the same network handing L2L VPN is at 10.0.0.2 (the Cisco's LAN interface that is). The edge needs to route traffic sent to it (as the default gateway) destined for specific destinations (for example 10.10.0.0/24) to the local IP address of the Cisco router within VLAN1 before applying any other logic to it. Currently, I am using the following command added to Windows to achieve the same result: route -p add 10.10.0.0 MASK 255.255.255.0 10.0.2
Good day @KLC_Engineer ,   Thanks for the great information. I did not test this with the diagnostic tools, but we literally used this to block the backup traffic for a customer who is not paying ... See more...
Good day @KLC_Engineer ,   Thanks for the great information. I did not test this with the diagnostic tools, but we literally used this to block the backup traffic for a customer who is not paying for their backup link. So, I know it works because they started complaining.
Good day, I am trying to configure DHCP option 121. I know it is not officially supported on the Edge (I asked tech support). I tried to do something we have done with pfSense: use the "custom" set... See more...
Good day, I am trying to configure DHCP option 121. I know it is not officially supported on the Edge (I asked tech support). I tried to do something we have done with pfSense: use the "custom" setting and force it to mimic Option 121. However, in Edge, it specifically forbids me from doing so as can be seen in the attached photo. Anyone had some luck with this before?
Good day @KLC_Engineer  I am using 510 with version 5.0.1.4 and we are not experiencing this issue. Are your edges on 5.2.0?
Hello @khirom ,   What is astonishing is the fact that VMware has yet to publish a document describing the series of messages we see in the Events tab. I know for sure that other vendors (Cisco fo... See more...
Hello @khirom ,   What is astonishing is the fact that VMware has yet to publish a document describing the series of messages we see in the Events tab. I know for sure that other vendors (Cisco for example) provide extensive and well prepared documents that covers every single parameter in detail
Hello @khirom  After the latest Orchestrator update, I can no longer access the Legacy Orchestrator since the button to access it has been removed. Also since VMware are shifting their focus on the... See more...
Hello @khirom  After the latest Orchestrator update, I can no longer access the Legacy Orchestrator since the button to access it has been removed. Also since VMware are shifting their focus on the new UI, it would be better to learn to use it. I have been using it solely since we migrated to this platform
Hello, I would highly suggest you talk to your VMware partner/reseller. Their presales engineers will have much more reliable answer than any of us here. Note that this is a new product, with not m... See more...
Hello, I would highly suggest you talk to your VMware partner/reseller. Their presales engineers will have much more reliable answer than any of us here. Note that this is a new product, with not much information circulating on the web.
No it can't do any of these. DHCP option 121 not supported. NATing traffic between VLANs, also not supported.
So The final cut: VMware claims that they support Edge to "Generic IKEv1/2 Router" VPN, but they NEVER define the word "Generic". I have been configuring generic IKEv1 and v2 IPsec VPNs on Cisco ASA... See more...
So The final cut: VMware claims that they support Edge to "Generic IKEv1/2 Router" VPN, but they NEVER define the word "Generic". I have been configuring generic IKEv1 and v2 IPsec VPNs on Cisco ASA and ISR for the past 9 years. We connected to various peers, some Cisco, some IBM, Palo Alto, Juniper. We even connected to software peers like pfSense. Never have I asked what the other side was. We agree on the VPN version, share parameters, PSK, subnets, and before you know it, a VPN is up and running with end to end connectivity. No fuss. Yet, I have failed to connect to the Edge. I only managed to connect to a Gateway, albeit, with many many limitations.
Ok guys so here is the 101 after I got our first site online for production: Never compare the Edge with a Cisco router (even the smallest one). The VMware Edge (and the entire VMware SASE solution... See more...
Ok guys so here is the 101 after I got our first site online for production: Never compare the Edge with a Cisco router (even the smallest one). The VMware Edge (and the entire VMware SASE solution) is immature. It cannot function as a full fledged router. The amount of limitations is staggering You CAN configure trunks, assign which VLAN is untagged, which VLANs are allowed on a switched trunk interface, BUT, you CANNOT NAT/PAT where you like. You ARE LIMITED to NAT/PAT between a LAN destination and (what SASE considers to be) a WAN. You definitely CANNOT nest NAT/PAT, and you CANNOT reroute/PAT traffic between VLANs. Believe me, I tried. I escalated this to support who stated that this feature is simply NOT SUPPORTED The DHCP server feature, although does support SOME common options, DOES NOT SUPPORT option 121. Again I asked tech support, and they confirmed it. What all my might and knowledge on the subject, I could not get the Edge-to-Cisco ISR VPN tunnel to work. I have been doing this for the past 9 years (VPN from Cisco ASA/ISR to various platforms, HW and SW), but I have finally met me arch nemesis. Tech support were as usual, no help and I got the "we will check and come back" thing. They never came back. Please make sure you know the product's abilities and limitations BEFORE you sign the contract. Hope this helps some of you Best regards, Talal
Good day, I have just had the same issue but when connecting to a Cisco ISR. I have since resolved this but you will need to know the limitations: The setup is limited to what the Gateway supports... See more...
Good day, I have just had the same issue but when connecting to a Cisco ISR. I have since resolved this but you will need to know the limitations: The setup is limited to what the Gateway supports. For example, to connect to a Cisco ISR, you are limited to using a Tunnel interface routing method, and cannot use a Crypto ACL. Also in my case, I am stuck with IKEv1, and with SHA hashing. SHA-256 and above are not supported. Trying to connect a Cisco ISR router to the Gateway using the "Generic IKEv1/2 Router" method has failed so far.  What option did you use to connect to your Fortigate? I could not spot such an option? Can you share the configuration on your Fortigate and on Orchestrator? I might be able to spot some discrepancies.  regards, Talal
The secondary IP addresses and sub-interfaces ended up not being the solution. Here is the bottom line: Switched Ports (like you mentioned before) do not support Overlay. They are used for LAN onl... See more...
The secondary IP addresses and sub-interfaces ended up not being the solution. Here is the bottom line: Switched Ports (like you mentioned before) do not support Overlay. They are used for LAN only. In order to terminate multiple WAN links on a single interface, the interface must be routed, and, at the Edge level, multiple User-Defined WAN links must be created and then linked to that routed interface. The exact method had been lost to me since the deprecation of the old GUI after the Orchestrator upgrade to SD-WAN software version 5.2. Once I figure it out, I will publish a walkthrough
Good day, So we have just migrated our first site to VMware SD-WAN. NOT the most pleasant experience but we managed it somehow. I knew there was a learning curve but I didn't think it would be this... See more...
Good day, So we have just migrated our first site to VMware SD-WAN. NOT the most pleasant experience but we managed it somehow. I knew there was a learning curve but I didn't think it would be this steep, given the fact that I have been Cisco and Comptia certified for the past 14 years. Anyways. Our provider had limited us to Edge version 5.0.1.4. On September 9th, Orchestrator and the Gateways were updated to SD-WAN software 5.2. With this update, the classic/Legacy GUI was gone. Good riddance IMHO, but it was still needed as our support used the old interface to do things. Now I am unable to configure a couple of things but I will manage somehow. Support turned out to be less than helpful, so whatever. The question here is: Which version of SD-WAN am I running, system-wise? 5.2 or 5.0.1.4? I am asking this because I want to know which features I have access to? the one in 5.0.1.4 or the ones added in 5.2? Regards, Talal
Sorry for the late reply.  What I meant to say that I was applying the LAB method on production environment, so there were no pages.
On the same page that I was trying to save the changes to, the Edge configuration page. Also what is a P.94?
Good day, So if I configure it as a routed port (and assign the correct VLAN to it), and add a secondary interface (and add the correct VLAN to it), how do I program the opposite Cisco switch interf... See more...
Good day, So if I configure it as a routed port (and assign the correct VLAN to it), and add a secondary interface (and add the correct VLAN to it), how do I program the opposite Cisco switch interface (switched)? in a trunk mode or what? 
Good day, At a branch, I have configured the active 510 GE4 as DHCP client (routed port mode). This works (as expected) by bringing the Edge to the network and it shows up in Orchestrator. The prob... See more...
Good day, At a branch, I have configured the active 510 GE4 as DHCP client (routed port mode). This works (as expected) by bringing the Edge to the network and it shows up in Orchestrator. The problem is in GE3: I have configured this port as switched trunk, and added two VLANs that I have already configured with static IP addresses, each representing a different WAN. How can I add default gateways for each VLAN so it can communicate with the internet. I added default routes as can be seen in the attached screenshot but will the Edge be able to identify which CLAN is connected with which route? Also will it use it to build overlays? After I have done this, the Edge still shows as having one link, meaning the VLANs did not register as WAN links. Am I missing something here?   Just to confirm one thing, I can ping both VLAN IP addresses from outside.  This means the default routes worked. However Orchestrator still shows the edge have only one link rather than 3
Good day, I was trying to setup a static IP address at the Edge level, I followed the HoL-2340-1-net LAB guide method to the letter. Yet when I try to save changes, I get "invalid probe interval fo... See more...
Good day, I was trying to setup a static IP address at the Edge level, I followed the HoL-2340-1-net LAB guide method to the letter. Yet when I try to save changes, I get "invalid probe interval for interface GE4" error. Googling this error returns 0 results. I am getting a feeling we made a mistake choosing VMware. Don't get me wrong, their ESXi and Workstation Player products are phenomenal, but the eco system is disappointing to say the least. I think we should have gone with Cisco.
Many Thanks
Good day @khirom    The problem with these labs is that they are preconfigured. I need something from scratch to reflect my current state