Manage Gateway Pools and Gateways
An Arista network consists of multiple service Gateways deployed at top tier network and cloud data centers. The Gateway provides the advantage of cloud-delivered services and optimized paths to all applications, branches, and data centers. Service providers can also deploy their own Partner Gateways in their private cloud infrastructure.
This topic contains the following sections:
Manage Gateway Pools
Organize Gateways into pools and then assign the pools to a network. After installing Orchestrator, an unpopulated default Gateway pool becomes available. If required, create additional Gateway pools.
As a Partner Super user and Partner Admin user,create, manage, download, and delete Gateway pools created by a Partner user or a Partner Managed Gateway pools created by the Operator.
Only Partners with Gateway management access can configure the New Gateway Pool and Download options. If the Gateway management access deactivates for a Partner, then the Partner has only read-only permission for the configured Gateway pools. To request Gateway Management access, Partners must contact the Operator Super user.
To manage Gateway pools, perform the following steps:
- New Gateway Pool – Creates a new Gateway pool. See Create a New Gateway Pool.
- Clone – Creates a new Gateway pool by cloning the existing configurations from the selected Gateway pool. See Clone a Gateway Pool.
- Download- Downloads the CSV file for all Gateway pools or the selected Gateway pool.
- Delete – Deletes the selected Gateway pool. You cannot delete a Gateway pool already in use by an Enterprise Customer.
- You can also configure the existing Gateway pools by selecting the name link of the Gateway pool. See Configure Gateway Pools.
Create a New Gateway Pool
Clone a Gateway Pool
Configure Gateway Pools
- For a new customer, see Create a New Partner Customer.
- For an existing customer, see Configure Partner Customers.
Manage Gateways
By default, Orchestrator installs gateway-1 and gateway-2, and you can create additional Gateways.
Partner Super user and Admin with Gateway management access activated can create, manage, and delete Gateways created by a Partner or Partner managed Gateways created by an Operator. The Partner IT support users can only view the configured Gateways.
To manage Gateways, perform the following steps:
- New Gateway – Creates a new Gateway. See Create a New Gateway.
- Delete Gateway – Deletes the selected Gateway. You cannot delete a Gateway that is already being used by an Enterprise Customer.
- Support Request – Redirects to a Knowledge Base article that has instructions on how to file a support request.
Create a New Gateway
To create a Gateway, perform the following steps:
To configure additional settings for the Gateway, see Configure Gateways.
Configure Gateways
To configure an existing Gateway:
Monitor Gateways
To monitor the Gateways, use the following steps:
VeloCloud Gateway Migration
VeloCloud Orchestrator provides a self-service migration functionality to migrate from your existing Gateway to a new Gateway without an Operator’s support.
- Achieve operational efficiency.
- Decommission old Gateways.
Gateways have specific role configurations. For example, a Gateway with data plane role forwards data plane traffic from source to destination. Similarly, a Gateway with Control Plane role, a Super Gateway, assigned to an Enterprise. Edges within the Enterprise connect to the Super Gateway. A Gateway with Secure VPN role establishes an IPsec tunnel to a Non SD-WAN destination (NSD). The migration steps may vary based on the role configured for the Gateway. For additional information about the Gateway roles, see the Configure Gateways section in the VeloCloud SD-WAN Operator Guide.
The following figure illustrates the migration process of the Secure VPN Gateway:

In this example, a VeloCloud Edge connects to an NSD through a Secure VPN Gateway, VCG1. The VCG1 Gateway undergoes a decommissioning. Before decommissioning, create a new Gateway, VCG2, and assign it the same role and then attach it to the same Gateway pool as VCG1. Replace VCG1 with VCG2. The service state of VCG1 changes to Quiesced. No new tunnels or NSDs can be added to VCG1. However, the existing assignments remain in VCG1. Configuration changes to the IP address of VCG2 occur in the NSD, an IPsec tunnel establishes between VCG2 and NSD, and the traffic switches from VCG1 to VCG2. After confirming an empty VCG1, decommissioning finalizes.
The following provides a high-level workflow of Secure VPN Gateway migration based on the User roles:

VeloCloud Gateway Migration- Limitations
- Partner Gateways do not support self-service migration.
- There a minimum service disruption occurs based on the time taken to switch Non SD-WAN Destinations (NSDs) from the quiesced Gateway to the new Gateway, and to rebalance the Edges connected to the quiesced Gateway.
- If configuring NSD with redundant Gateways and one of the Gateways quiesces, the redundant Gateway cannot replace the quiesced Gateway.
- During self-service migration of a quiesced Gateway, the replacement Gateway must have the same Gateway Authentication mode as the quiesced Gateway.
- For a customer deploying an NSD via Gateway with BGP configured, if you migrate the NSD to a different Gateway using the Self-Service Gateway Migration feature on the Orchestrator, the BGP configurations do not migrate and drops all BGP sessions post-migration.
In this scenario, the existing Gateway assigned to the NSD has a quiesced state and requires migration to another Gateway. Navigate to on the Orchestrator and initiates the Gateway Migration process to move the NSD to another Gateway. Post-migration, the BGP Local ASN & Router ID information does not populate the new Gateway and NSD BGP sessions do not come up with all routes lost and disrupts traffic using those routes until you manually recreates all BGP settings.
While the Gateway Migration feature accounts for many critical NSD settings, the NSDdoes not account for BGP settings and expect their loss post-migration.
Workaround: The migration of a Gateway should be performed in a maintenance window only. Prior to the migration, you should document all BGP settings and manually reconfigure these settings post-migration to minimize impact to customer users.
Migrate Quiesced Gateways
Before you migrate the Edges and NSDs,if configured, from the quiesced Gateway to the new Gateway, ensure you schedule a maintenance window as traffic may be disrupted during migration.
To avoid any service disruption, ensure you migrate to the new Gateway within the Migration Deadline in the notification email.
To migrate from a quiesced Gateway to a new Gateway, perform the following steps:
Actions When Switch Gateway Action Fails
Select View Events in the Gateway Migration page to view the history of migration events in the page.
Diagnostic Bundles for Gateways
Run diagnostics for Gateways to collect diagnostic bundles and packet capture files for troubleshooting purpose.
This topic contains the following sections:
Request Diagnostic Bundles for Gateways
To generate a new Diagnostic bundle, use the following steps:
- Download Diagnostic Bundle- You can download the generated Diagnostic bundles to troubleshoot an Edge. To download a generated bundle, select the link next to Complete in the Request Status column or select the bundle and select Download Bundle. The bundle downloads as a ZIP file. You can send the downloaded bundle to a Arista Support representative for debugging the data.
- Delete Diagnostic Bundle- The completed bundles delete automatically on the date displayed in the Cleanup Date column. You can select the link to the Cleanup Date, or select the bundle and then to modify the Date.
Figure 30. Update Cleanup Date 
In the Update Cleanup Date dialog, specify the date to delete the selected Bundle.
If you want to retain the Bundle, select Keep Forever and the Bundle does not automatically delete.
To delete a bundle manually, select the bundle and select Delete.
Request Packet Capture Bundle for Gateways
To generate a PCAP bundle:
























