Master Secure SD-WAN Engine requirements
Master Secure SD-WAN Engines have specific hardware requirements.
- Each Master Secure SD-WAN Engine must run on a separate physical device. For more details, see the Forcepoint FlexEdge Secure SD-WAN Installation Guide.
- All Virtual Secure SD-WAN Engines hosted by a Master Secure SD-WAN Engine or Master Secure SD-WAN Engine cluster must have the same role and the same Failure Mode (fail-open or fail-close).
- Master Secure SD-WAN Engines can allocate VLANs or interfaces to Virtual Secure SD-WAN Engines. If the Failure Mode of the Virtual IPS engines or Virtual Layer 2 Engines is Normal (fail-close) and you want to allocate VLANs to several Secure SD-WAN Engines, you must use the Master Secure SD-WAN Engine cluster in standby mode.
- Cabling requirements for Master Secure SD-WAN Engine clusters that host Virtual IPS engines or Layer 2 Engines:
- Failure Mode Bypass (fail-open) requires IPS serial cluster cabling.
- Failure Mode Normal (fail-close) requires Layer 2 Engine cluster cabling.