Create a VPN Broker Domain element in the NGFW Manager

VPN Broker Domain element defines the virtual network that contains the VPN Broker gateway and the VPN Broker members.

Steps

  1. Browse to SD-WAN > VPN Broker > VPN Broker Domain.


  2. Click .
  3. Configure the settings, then click Save.

Example

Fields marked with an asterisk in the user interface are mandatory.

Table 1. VPN Broker Domain properties
Option Definition
IPv4 Network or IPv6 Network Enter the IP address and netmask of the virtual network that contains all of the members of the VPN Broker domain. You must enter an IPv4 network, an IPv6 network, or both.
Tip: We recommend that you make a note of the IP addresses for each VPN Broker Domain.
Note: With version 6.11, IP address validation is done and notified to the administrator.
VPN Broker Gateway Select the VPN Broker Gateway that belongs to the VPN Broker domain. Type part of the name of an element or browse through the drop-down list to select an element.
External VPN Broker Gateways This setting is used only in a VPN Broker high availability configuration.
MAC Address Prefix Enter a unique identifier for the VPN Broker Domain in MAC address format. The length must be three octets. The first octet must be even. The address must be a unique unicast MAC address.
Tip: We recommend that you make a note of the MAC Address Prefix for each VPN Broker Domain.
Note: With version 6.11, the MAC Address Prefix is auto-populated.
Primary VPN Broker Server This setting is used only in a VPN Broker high availability configuration.
Enabled When selected, the VPN Broker Domain element is enabled. You can temporarily disable the element without deleting it.

Next steps

Create VPN Broker Member elements to represent each NGFW Engine that is used in the VPN Broker configuration.