跳至内容

关闭虚拟设备广域网/管理接口

网络边缘用户可以关闭特定虚拟设备 (VNF) 类型的 WAN 接口。此用例提供了一种将虚拟设备 (VNF) 与 Internet 完全隔离的方法。本主题提供了支持从虚拟设备级别配置关闭 WAN 接口的虚拟设备供应商和产品型号列表。

注意

VNF接口的关闭是在虚拟设备接口配置级别进行的。这与使用主访问控制列表(PAC)进行流量控制不同。您可以为特定虚拟设备禁用PAC,但仍允许某些引导和服务通信(包括DNS服务、SD-WAN控制器管理和许可服务器通信)。

SD-WAN 设备类型不支持关闭 WAN 接口,因为该接口用于与 SD-WAN 控制器通信。关闭该接口所需的配置信息可在各厂商提供的产品文档中找到。

Vendor NameDevice TypeModelInterface Shutdown SupportInterface NameComments
AristaSD-WANVeloCloud SD-WAN EdgeNoGE3
ArubaSD-WANEdgeConnectNowan0
CheckPointFirewallCloudGuardPethXWAN Interface is used for:
Communication with SMS Server
NTP
Software Update
VPN Tunnel
CiscoRouterCSR1000vPGigabitEthernetXCSR1000v Permanent License Reservation (PLR) through offline method should be used.
RouterCatalyst 8000vPGigabitEthernetXLicense Reservation through offline method should be used.
SD-WANCSR1000vNoGigabitEthernetX
FirewallASAvPGigabitEthernet0/XASAv Permanent License Reservation (PLR) through offline method should be used.
FirewallFTDvNoGigabitEthernet0/XMgmt / WAN Interface is used to communicate with licensing server and software / security update purpose.
F5 NGINXLoadBalancerNGiNX PlusNoens3WAN Interface is used for:
Management Access (Monitoring via HTTP / s )
Configuration
FortinetFirewallFortiGateNoPortXFortinet Firewall uses WAN interface to communicate with the license server.
SD-WANFortiGateNoPortX
JuniperFirewallvSRXPge-0/0/X
SD-WANvSRX SD-WANNoge-0/0/X
Palo AltoFirewallVM SeriesPethernet1/XWAN Interface is used to communicate with licensing server and software / security update purpose. Ensure BYOC interface can be used to perform update before shutting down the interface. After the device is licensed, WAN interface can be shutdown. All the security updates and software updates needs to be done manually.
SD-WANPrisma Virtual IONNoPort1WAN Interface is used to communicate with the Controller .
VersaSD-WANFlexVNFNovni-0/0
此页面有帮助吗?