Create one VPN Broker Domain element in the SMC

Create one VPN Broker Domain element and import the exported configuration file from the NGFW Manager.

Note: The configuration of the VPN Broker Domain element must contain information about all VPN Broker gateways and VPN Broker members in the same VPN Broker domain.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Open the Management Client.


  2. Select Configuration, then browse to SD-WAN.
  3. Browse to VPN Broker Domains.
  4. Select New > VPN Broker Domain.


  5. Configure the settings.
    1. (Optional) Enter a name for the element.
      If you do not enter a name, the name is automatically generated based on the name of the configuration file.
    2. In the Mac Prefix field, enter the first three octets of the MAC address that is used by all members of the VPN Broker domain.
      This MAC address prefix must be the same as the MAC address prefix that is used in the VPN Broker Domain element that you created in the NGFW Manager.
    3. Next to the Configuration File field, click Browse, then select the configuration file that you exported from the NGFW Manager.
    4. Click OK.

Example

Table 1. VPN Broker Domain properties
Option Definition
Name

(Optional)

The name of the element.
Mac Prefix Enter the first three octets of the MAC address that is used by all members of the VPN Broker domain. This MAC address prefix must be the same as the MAC address prefix that is used in the VPN Broker Domain element that you created in the NGFW Manager.
Configuration File Click Browse to select the configuration file that you exported from the NGFW Manager.
Link Usage Profile

(Optional)

To use dynamic link selection for Multi-Link VPNs, select a Link Usage Profile element.

When you select a Link Usage Profile element in the properties of a policy-based VPN, route-based VPN tunnel group, or a VPN broker domain, the settings defined in the Link Usage Profile element are applied to all tunnels in the VPN according to their link types.

Next steps

Add a VPN Broker Interface to all NGFW Engines that are used as VPN Broker members.