Configure Device Settings for Edges
To configure a specific Edge:
- Select .
- The Edges page displays the existing Edges.
- Select the link to an Edge or select the View link in the Device column of the Edge.
- The configuration options for the selected Edge are displayed on the Device tab.
Figure 1. Device Tab 
- Select View to expand or collapse the view of available settings.
- Users can also view the configuration settings sorted by category or segmentation. By default, the settings are sorted by category. Sorting by segmentation groups the settings into segment-aware and segment-agnostic categories.
- For some of the settings, the configuration is inherited from the associated Profile. To edit the inherited configuration for the Edge, select the Override checkbox. The following settings appear when sorting by category:
Table 1. Connectivity Option Description VLAN Configure the VLANs with both IPv4 and IPv6 addresses for Edges. Select the IPv4 or IPv6 tabs to configure the corresponding IP addresses for the VLANs. For additional information, see Configure VLAN for Edges. Note: Whencreating a new VLAN or edit a VLAN configuration using the new Orchestrator UI, the VLAN appears as read-only in the classic Orchestrator UI. After creating or editing a VLAN with new Orchestrator UI,modify the settings of the corresponding VLAN only in the new Orchestrator UI.Loopback Interfaces Configure a logical interface to assign an IP address, which identifies an Edge. For additional information., see Loopback Interfaces Configuration. Management Traffic Configure management traffic by selecting a source IP for the Edge to transmit traffic to the Orchestrator. For additional information, see Configure Management Traffic for Edges. ARP Timeouts By default, the Edge inherits the ARP settings from the associated Profile. Select the Override and Override default ARP Timeouts checkboxes to modify the values. For additional information, see Configure Address Resolution Protocol Timeouts for Edges. Interfaces Configure the following settings for the Edge Interfaces: - Interface Settings – Configure the settings for a Switch Port (LAN) or a Routed (WAN) Interface of the selected Edge. See Configure Interface Settings for Edges.
- WAN Overlay Settings – Enables to add or modify a User-Defined WAN Overlay and modify or delete an existing auto-detected WAN Overlay. See Configure Edge WAN Overlay Settings.
Global IPv6 Enable IPv6 configurations globally. See Configure Global IPv6 Settings for Edges. Wi-Fi Radio Activate or deactivate Wi-Fi Radio and configure the band of radio frequencies. For additional information, see Configure Wi-Fi Radio Overrides. Note: The Wi-Fi Radio option is available only for the following Edge models: 500, 5X0, Edge 510, Edge 510-LTE, Edge 6X0, and Edge 610-LTE.Table 2. VPN Services Option Description Cloud VPN Enable Cloud VPN to initiate and respond to VPN connection requests. Establish tunnels in the Cloud VPN as follows: - Branch to Hub VPN
- Branch to Branch VPN
- Edge to Non SD-WAN via Gateway
Select the checkboxes as required and configure the parameters to establish the tunnels. See Configure Cloud VPN and Tunnel Parameters for Edges.
Non SD-WAN Destination via Edge Enable to establish tunnel between a branch and Non SD-WAN destination via Edge. See Configure Tunnel Between Branch and Non SD-WAN Destinations via Edge. Select Add to add Non SD-WAN Destinations. Select New NSD via Edge to create new Non SD-WAN Destination via Edge. See Configure a Non SD-WAN Destinations via Edge. Cloud Security Service Enable to establish a secured tunnel from an Edge to cloud security service sites. This enables the secured traffic being redirected to third-party cloud security sites. See Configure Cloud Security Services for Edges. Table 3. Routing and NAT Option Description Multicast Enable and configure Multicast to send data to only interested set of receivers. See Configure Multicast Settings for Edges. BFD By default, the Edge inherits the BFD configuration settings from the associated Profile. If required, select the Override checkbox to modify the settings. For additional information, see Configure BFD for Edges. LAN-Side NAT Rules Allows NAT IP addresses in an unadvertised subnet to IP addresses in an advertised subnet. See LAN-side NAT Rules at Edge Level. ICMP Probes Configure ICMP probes that check for the network continuity by pinging specified IP address at frequent intervals. See Configure ICMP Probes and Responders. ICMP Responders Configure ICMP Responders that respond to ICMP probes from a specified IP address. See Configure ICMP Probes and Responders. Static Route Settings Configure Static Route Settings for special cases in which static routes are needed for existing network attached devices, such as printers. See Configure Static Route Settings. DNS Use the DNS Settings to configure conditional DNS forwarding through a private DNS service and to specify a public DNS service to be used for querying purpose. See Configure DNS for Edges. OSPF Areas The OSPF settings configured in the associated Profile are displayed. Configure OSPF areas only for a Profile and for a Global Segment. Configure additional OSPF settings for routed interfaces on Edges. For additional information, see Configure OSPF for Edges. BGP Configure BGP settings for Underlay Neighbors and Non SD-WAN Neighbors. See Configure BGP. ECMP Configure ECMP settings. See Configure ECMP for Edges. Overlay Route Control Configure Overlay Route Control (ORC) capabilities for route prefixes advertised to the overlay. See Configure Overlay Route Control for Edges. Table 4. High Availability Option Description High Availability Enable High Availability for the selected Edge. Choose one of the following options: - None – This is the default option where High Availability is not enabled.
- Active Standby Pair – Select this option to enable HA on the selected Edge. For additional information, see Activate High Availability.
- Cluster – Select an existing Edge cluster from the drop-down list to enable High Availability on the Edge cluster. To configure Edge clusters, see Monitor Edge Clusters.
- VRRP with 3rd party router – Select this option to configure Virtual Router Redundancy Protocol (VRRP) on the selected Edge to enable next-hop redundancy in the SD-WAN Orchestrator network by peering with third-party CE router. To configure VRRP, see Configure VRRP Settings.
Table 5. Telemetry Option Description Visibility Mode Choose the visibility mode to track the network using either MAC address or IP address. See Configure Visibility Mode for Edges. SNMP Enable the required SNMP version for monitoring the network. Ensure to download and install all the required SNMP MIBs before enabling SNMP. See Configure SNMP Settings for Edges. Syslog Configure Syslog collector to receive Orchestrator bound events and firewall logs from the Edges configured in an Enterprise. See Configure Syslog Settings for Edges. Table 6. Security VNF Option Description Security VNF Configure security VNF to run the functions of a network service in a software-only form. For additional information, see Security Virtual Network Functions. Table 7. Edge Services Option Description Authentication Allows to select a RADIUS server to be used for authenticating a user. For additional information, see Configure Authentication Settings for Edges. Select New RADIUS Service to create a new RADIUS server. For additional information, see Configure Authentication Services. NTP Enable to synchronize the system clocks of Edges and other network devices. See Configure NTP Settings for Edges. - After modifying the required settings, select Save Changes.
- Select the Shortcuts option to perform the following activities:
- Monitor – Navigates to the Monitoring tab of the selected Edge. See Monitor Edges.
- View Events – Displays the Events related to the selected Edge.
- Remote Diagnostics – Enables to run the Remote Diagnostics tests for the selected Edge. See Run Remote Diagnostics.
- Generate Diagnostic Bundle– Allows to generate Diagnostic Bundle for the selected Edge. See Diagnostic Bundles for Edges.
- Remote Actions – Allows to perform the Remote actions for the selected Edge. See Perform Remote Actions.
- View Profile – Navigates to the Profile page, that is associated with the selected Edge.
- View Gateways – Displays the Gateways connected to the selected Edge.
Configure VLAN for Edges
- Configure up to 32 VLANs across 16 Segments on an Edge.
- On Profile change, the target profile removes any VLAN inherited from the Edges profile from the target Profile unless overridden at the Edge level. Any interface associated with a removed VLANsreverts to the Profile-level configuration in the target Profile, even if Edge overrides the interface.
To configure VLAN settings for an Edge, use the following steps:
Loopback Interfaces Configuration
A loopback interface is a logical interface that allows users to assign an IP address to identify a VeloCloud Edge.
Loopback interface configuration requires Edge version 4.3 or above. The Configure Loopback Interfaces area is not available for Edges running version 4.2 or lower. For such Edges, users must configure the Management IP address. For details, refer to Configure Management IP Address for Profiles.
This topic contains the following sections:
Loopback Interfaces—Benefits
- As loopback interfaces are logical interfaces that are always up and reachable, use them for diagnostic purposes as long as there is Layer 3 reachability to at least one physical interface.
- Loopback interfaces serve as the source interface for BGP. This ensures that when the BGP interface state flaps, the BGP membership does not flap if at least one Layer 3 connection remains available.
- The loopback interface IP address serves as the source IP for various services, including Orchestrator Management Traffic, Authentication, DNS, NetFlow, Syslog, TACACS, BGP, and NTP. As loopback interfaces are always up and reachable, these services can receive the reply packets if at least one physical interface configured for the Edge has layer 3 reachability.
Loopback Interfaces—Limitations
- The system supports only IPv4 addresses for loopback interfaces.
- Loopback interfaces apply exclusively to Edges and do not support Profile-level configuration.
- Configure loopback interfaces only after successful Edge activation.
- For any Edge that is not activated, the customer operator profile version is determined by whether the Management IP Address section or the Loopback Interfaces section is visible. For example, if the customer operator profile version is 4.3 or higher, the Loopback Interfaces section is visible at the Edge level. However, if the customer operator profile version is 4.2 or lower and the Edge is not activated, the Management IP Address section is visible at the Edge and Profile levels.
- Loopback interface IDs must be unique across all segments within an Edge. These IDs start from 1, as the system does not support zero (0).
- Configuring loopback interfaces and Orchestrator management traffic via API removes the availability of the default configuration keys for these properties. The user must modify the
updateConfigurationModuleAPI to configure the loopback interface and select the management traffic source interface. - Access loopback interfaces through SSH only. Loopback interface access through local Web UI is not supported.
- Consider the following while upgrading or downgrading Edges:
- If the Management IP address that is configured either at the Profile-level or at the Edge-level is not the default IP address (
192.168.1.1) and when the Edge is upgraded to version 4.3 or above, the loopback interface is automatically created at the Edge-level with the configured Management IP address as the IP address of the loopback interface. - Consider upgrading Orchestrator to version 4.3 or above, whereas the Edge still runs on version 4.2 or lower. If users update the Management IP address configuration either at the Profile-level or at the Edge-level, and then upgrade the Edge to version 4.3 or above, all changes that users made to the Management IP address configuration will be lost.
- Downgrading the Edge to a version earlier than 4.3 restores the previously configured Management IP address at both the Profile and Edge levels.
- An Edge downgrade erases any changes made to the loopback interface configuration.
- For example, assume users had the Management IP address set to
1.1.1.1. When users upgrade their Edge to version 4.3 or above, the same IP address,1.1.1.1, will be the IP address of the loopback interface at the Edge level. Then, users change the loopback interface IP address to2.2.2.2. When users downgrade their Edge to a version lower than 4.3, users will notice that the Management IP address at the Edge-level will still be1.1.1.1and the Management IP address at the Profile-level will be empty.
- If the Management IP address that is configured either at the Profile-level or at the Edge-level is not the default IP address (
Configure a Loopback Interface for an Edge
Deleting a loopback interface resets the Source Interface field to Auto for all associated services.
Interface ID.Additionally, two further scenarios trigger a reset of the Source Interface to Auto for various services:
- The Edge fails to locate the loopback interface ID.
- Selecting older API versions to configure the Edge sometimes prevents the Edge from receiving the source IP address key for services.
- The system prioritizes any advertised non-WAN interface.
- Among advertised non-WAN interfaces, the system selects the source interface according to this priority order: Loopback interfaces, VLAN interfaces, and routed interfaces.
- If more than one interface of the same type is configured and advertised, the interface with the lowest interface ID is selected. For example, if users have two loopback interfaces (LO3 and LO4), one VLAN interface (VLAN2), and two routed interfaces (GE1 and GE2) configured and advertised, and if the Source Interface field for any service is set to Auto, the Edge selects LO3 as the source interface.
| Services/Settings | Reference Link |
|---|---|
| Orchestrator Management Traffic | Configure Management Traffic for Edges |
| Authentication Settings | Configure Authentication Settings for Profiles |
| DNS Settings | Configure DNS for Profiles |
| Netflow Settings | Configure NetFlow Settings for Edges |
| Syslog Settings | Configure Syslog Settings for Edges |
| BGP Settings | Configure BGP from Edge to Underlay Neighbors for Profiles |
| NTP Settings | Configure NTP Settings for Edges |
Configure Management Traffic for Edges
Configure Address Resolution Protocol Timeouts for Edges
To override the ARP timeouts values at the Edge-level, perform the following steps:
Configure Interface Settings for Edges
Perform the following steps, to configure interface settings for a specific Edge.
Configure LACP on Edge
LACP automates the creation and management of link aggregation groups (LAGs), enabling devices to dynamically negotiate and configure link aggregation, detect link failures, and manage failover.
LACP implements load-balancing algorithms to distribute traffic across aggregated links. A hashing algorithm directs packets of the same-flow traffic using source and destination MAC, IP, or port information to the same link. This process utilizes the full bandwidth of all member links.
When a link in the LACP group fails, traffic automatically redistributes across the remaining active links. This ensures fault tolerance and maintains network connectivity.
To configure a LAG, perform the following steps:
Configure LLDP for Edges
The SD-WAN Edge uses Link Layer Discovery Protocol (LLDP) to discover vendor-neutral devices and automatically determine physical interconnections between LAN devices. By providing data on directly connected neighbors, LLDP simplifies network management and streamlines troubleshooting. It automatically generates network topology maps, enabling administrators to quickly identify the specific devices and ports connected to any edge port.
Users can enable LLDP on any routed, switched, LAG, or LACP interface using a toggle (disabled by default). Activating this toggle commands the port to send and receive LLDPDUs. In Link Aggregation Groups (LAG), all member ports send independent LLDPDUs, even if the system blocks the port.
When you enable LLDP, the Edge begins monitoring neighbors. The Edge generates an Edge Event whenever it detects a new neighbor or a change in a neighbor's information.
- LLDP is available for both Edges and Profiles.
- LLDP feature supports routed and switched interfaces. If LAG feature is available, LLDP is supported.
Configure LLDP for Edges
To configure the LLDP, perform the following steps:
Monitor LLDP
Monitoring allows the users to find the list of connected devices, last known neighbor during selected time period, Time-to-Live (TTL), Neighbor Port ID, Mac range,and so on.
Perform the below steps to view the LLDP neighbor table:
Events
Perform the following steps to view the list of Events:
Configure DHCP Server on Routed Interfaces
Perform the following steps to configure the DHCP Server settings:
Configure RADIUS on a Routed Interface
- A RADIUS server must be configured and added to the Edge. See Configure Authentication Services.
- The system allows RADIUS activation on any routed interface. This includes the interfaces for any Edge model, except for the LAN 1-8 ports on Edge models 500/520/540.
Configure RADIUS Authentication for a Switched Interface
- The administrator must configure and add a RADIUS server to the Edge. See Configure Authentication Services.
- Users may configure RADIUS on any switched interface.
The SD-WAN Edge supports both username and password (EAP-MD5) and certificate (EAP-TLS) based 802.1x Authentication methods.
Adding RADIUS authentication on a switched interface is a two-part process: first a VLAN associates with the targeted switched interface, and then the VLAN configures to use RADIUS authentication. Users can follow these steps at either the Profile or Edge level. If configured at the Profile level, every Edge associated with that Profile configures for RADIUS authentication on the specified switched interface.
MAC Address Bypass (MAB) for RADIUS-based Authentication
On routed interfaces, the system checks MAC addresses against a RADIUS server to bypass 802.1x for LAN devices that do not support it. MAC Authentication Bypass (MAB) simplifies IT operations, saves time, and enhances scalability because customers no longer need to manually configure every MAC address requiring authentication.
- Users must configure and add a RADIUS server to the Edge. For detailed steps, see the Configure Authentication Services.
- The RADIUS server must maintain a list of MAC addresses that the system should bypass to utilize the MAB feature.
- Users must configure RADIUS authentication on the Edge's routed interface or switched interface (via a VLAN) at either the Profile or Edge level.
- L2 traffic does not trigger RADIUS MAB.
- Linux-based switches do not forward L2 traffic until routed traffic appears. Since hardware switches do not filter pure L2 traffic, this behavior remains unchanged.
- If the system observes no routed traffic and RADIUS MAB times out (the system sets this to 30 minutes by default), the Edge will again block L2 traffic.
- Enabling 802.1x may cause performance degradation because the system uses additional hooks to check the authentication status for self-destined packets
- The system no longer filters traffic destined for the Edge itself—which Linux manages entirely (such as DHCP, DNS, or SSH)—prior to 802.1x authentication.
Activate MAB for Routed Interface
Activate MAB for Switched Port using a VLAN
Configure Edge LAN Overrides
To override the LAN settings for an Edge:
Configure Edge WLAN Overrides
To override the WLAN settings for an Edge:
Configure Edge WAN Overlay Settings
- Public Overlay: Enables the definition of custom VLANs, source IP addresses, and Gateway addresses for VCMP tunnels to reach the Gateway over the internet, as the Orchestrator determines.
- Private Overlay: Enables the Edge to build Overlay VCMP tunnels directly between private IP addresses within a private network.
Note: In a Partner Gateway setup with a configured Handoff Interface, when an Edge with private Interface has both IPv4 and IPv6 user-defined overlays, the Edge tries to establish IP tunnels towards the public IP address of the Gateway based on the tunnel preference.
To configure WAN Overlay settings for a specific Edge, perform the following steps:
Support for DSCP Value Tag Per User Defined Overlay
With the 5.0.0 release, network administrators can add a DSCP tag to a specific overlay link. The administrators apply the DSCP tag at the outer header of the VCMP packet traversing the overlay link, and it leverages the private network underlay DSCP tag to treat each overlay uniquely based on the QoS settings defined on the WAN underlay network.
Enable Per link DSCP Checkbox
Select this checkbox to add a DSCP tag to a specific overlay link. The administrators apply the DSCP tag to the outer header of the VCMP packet traversing this overlay link. This application enables leveraging the private network underlay DSCP tag mechanism to treat each overlay uniquely via QoS settings defined at the upstream router.
Use Case: DSCP Value Per User Defined Overlay
In this use case, the requirement is to apply the WAN overlay DSCP tag value configured on the WAN link to all traffic egressing from this link, for the tunnel originating Edge. The configured DSCP value should apply to the VCMP outer header so that the MPLS network can read it and apply differentiated services to the VCMP-encapsulated packet. The inner DSCP tag value on the LAN side of the Edge network should remain unmodified. Requirements on the tunnel destination side: The Hub or peer Edge that receives the tunnel creation request must respond with the same DSCP overlay tag value as the tunnel originator sent in the VCMP outer header. The hub or peer Edge terminating the overlay tunnel should not modify the inner DSCP tag destined for the LAN.
In the below image, the Enterprise is using DSCP values on their underlay network to provide differentiated services based on source WAN overlay link/tunnel.

Bandwidth Measurement Modes
This section discusses how the VeloCloud SD-WAN service performs bandwidth measurement on a WAN link.
After an Edge detects a WAN link, it first establishes DMPO (Dynamic Multi-Path Optimization) tunnels with one or more VeloCloud Gateways. It performs a bandwidth test with the Primary Gateway. To perform a bandwidth test, the Edge sends a bidirectional UDP stream and measures the received rate at each end. Additionally, if the Hub/Spoke topology deploys the Edge as a Spoke, it establishes tunnels with the Hub Edge and performs a bandwidth test if configured to do so.
- Slow Start Mode: In Slow Start mode, the Edge sends a smaller burst of UDP traffic followed by a larger burst of UDP traffic to the Gateway. Based on the number of packets received by the Gateway, it calculates the WAN link's speed. In this mode, the Edge sends this traffic for a fixed duration of 5 seconds. In the first 3 seconds, the Edge sends the UDP traffic at a rate of 5000 packets per second, and for the remaining 2 seconds it sends the traffic at 20000 packets per second. The packet size of this UDP traffic matches the MTU size for that WAN link.
For wired links, the Edge configures the Slow Start mode by default. The Edge sends a steady stream of packets for a short period of time (in case the ISP is throttling the beginning of a session) and then ramps up to a 200 Mbps stream and measures the amount of incoming packets. This happens because some ISPs require a gradual increase in packet rate before allowing the full packet rate under the link SLA.Note: Because of the way Slow Start mode works, the maximum measurable rate is 200 Mbps in either direction. In Edge software Release 3.3.0+, if the Edge measures 175 Mbps or greater (in upload bandwidth) with Slow Start, the Edge automatically switches to Burst Mode.
- Burst Mode: In Burst mode, the Edge sends the UDP packets as single burst (a fixed, high number of packets in one burst) to the Gateway. Based on the number of packets received by the Gateway, the Gateway calculates the speed. It starts the round with 416 packets. If the Gateway response indicates arrival of packets over a very short interval, the Edge restarts the process with 2000 packets. The packet size of this UDP traffic is the link MTU size.
For wireless links, the Edge configures the Burst mode by default. The Edge sends a 6.25 MB burst to the Gateway and calculates the total received volume and the elapsed time. Based on the Gateway's response, the Edge adjusts the size to make the burst take 0.5 seconds and then sends a second burst. The Edge adjusts again and sends a third burst. The received volume and transmission duration of the third burst define the final bandwidth setting for that link.Note: Burst Mode is effective at measuring a WAN link up to 900 Mbps in either direction. Manually configure any WAN link with an upload or download capacity exceeding 900 Mbps using User Defined mode.
- User Defined Mode (Define Manually): In this mode, the user can configure the WAN link bandwidth manually in the Orchestrator UI. User Defined mode is helpful in the following cases:
- For WAN links with greater than 900 Mbps capacity (either upload or download).
- For WAN links on Edges functioning as Hubs.
Note: This applies to Hubs or any Edge with a high number of tunnels.
- For private links like MPLS, Arista recommends configuring the link with a user-defined value because a private link must perform a bandwidth measurement test with every other private link in the customer's network.
- Consider a network with multiple private peer links, each with bandwidth values of 5 Mbps, 1 Mbps, and 500 Kbps, respectively. The private link performs a bandwidth test on each of those private peer links and may end up reporting the lowest peer link value. In a large network with many private links, this is undesirable because each bandwidth measurement consumes link resources.
- If the bandwidth measurement fails for that WAN link and the system does not register a value.
- If specific user preferences deliberately limit the link capacity that the Edge utilizes.
Configuration
Configure the bandwidth measurement modes through Orchestrator by navigating to .
- USB modems are not compatible with the slow start mode of measurement. The recommended bandwidth measurement mode for a USB modem is “Burst Mode” (configured by default). The recommended bandwidth measurement mode for wired WAN links is “Slow Start” (also configured by default).
- Arista recommends Dynamic Bandwidth adjustment on links where available bandwidth can vary over time (especially wireless links). This setting tracks WAN congestion and packet loss and adjusts the bandwidth down and up as needed. The system maintains bandwidth at or below the originally measured value to prevent congestion.
- Bandwidth is measured only along the local Gateway path unless the Edge is also a Spoke Edge in a Hub/Spoke topology. In that case, the system measures bandwidth between the Spoke Edge and the Hub Edge.
- In a Hub/Spoke topology where the Hub Edge and a connected Spoke Edge have different bandwidth measurement modes (for example, the user sets the Hub Edge WAN link to User-Defined mode while configuring the Spoke Edge WAN link to either Slow Start or Burst mode), the system performs a link measurement. However, SD-WAN prefers the user-defined value if the measured value is greater than it. Bandwidth measurement events appear on the Hub Edge because the system triggers these checks from the Spoke Edge, regardless of the Hub's User Defined mode settings.
- When measuring the path to the local Gateway, the rest of the paths display
WAITING_FOR_LINK_BW. After the measurement to the local Gateway path is complete, the rest of the paths update their values and exchange them with their peers. This behaviour also applies when a Spoke Edge measures the Hub Edge in a Hub/Spoke topology. - The wireless links always default to Burst Mode of measurement.
- For wired links, the system updates the cache only on a successful measurement, and this value is valid for 7 days. Bandwidth measurement happens only if a tunnel flaps or comes up, and there is no cache, or if there is a value in the cache, but the last measurement was 7 days back. Wireless links exhibit similar behavior, but in their case, the cache only needs to be older than 24 hours, and the system requires a tunnel flap to trigger another bandwidth measurement.
- If the Automatic bandwidth measurement fails, a user can manually trigger a bandwidth measurement from the Orchestrator by navigating to .
- If the Automatic bandwidth measurement measures less than 90% of the originally measured (cached) value, it does not update the bandwidth. For example, if a user has a 1Gig link and downgrades to a 500Mbps link, the bandwidth measurement continues to show the old 1Gig value. As a workaround, the support team must delete the cached bandwidth measurement, then run a new "WAN Link Bandwidth Test" from Remote Diagnostics.
- Hub Edges and Gateways process one bandwidth test at a time to ensure accurate results. This approach is relevant to customers who either manually trigger multiple bandwidth measurements in a short time or make a bulk change via an API that can trigger multiple bandwidth measurements, where all the tests use the same Hub Edge or Gateway.
SD-WAN Service Reachability via MPLS
An Edge with only Private Multiprotocol Label Switching (MPLS) links can reach the Orchestrator and Gateways in the public cloud using the SD-WAN Service Reachable option.
On a site with no direct public Internet access, the SD-WAN Service Reachable option allows the private Wide Area Network (WAN) to be used for private site-to-site VCMP tunnels and as a path for communicating with an Internet-hosted Arista service.
- If the Edge is a Hub, and Spoke Edges are using that Hub Edge as the Internet breakout, their tunnels to the Gateway may not come up because the Hub Edge may forward those flows back out the private link.
- An Edge device with this incorrect setting may appear offline in Orchestrator because it may use the private link to contact Orchestrator.
MPLS-only Sites
Arista supports private WAN deployments with a hosted service for customers with hybrid environments who deploy in sites with only a private WAN link.
- Enabled SD-WAN service reachability through a private link
- Enabled NTP override using private NTP servers
The following image shows a Regional Hub with an Internet connection and an Edge with only an MPLS connection.

When an Edge uses MPLS-only links, the system routes traffic to the Orchestrator and Gateway through a Regional Hub. This hub acts as a secure bridge, allowing the private MPLS traffic to break out to the public cloud or internet-based services SD-WAN Service Reachable option allows the Edge to remain online and manageable from the Orchestrator. It allows public Internet connectivity through the Gateway, irrespective of whether or not there is public link connectivity.
Dynamic Failover via MPLS
If all public Internet links fail, the user can fail over critical Internet traffic to a private WAN link. The following image illustrates the Resiliency of Orchestrator and Non-SD-WAN Destination, Zscaler.

- Orchestrator Resiliency - The Orchestrator connects to the Internet. If the Internet fails, the Orchestrator will connect through MPLS. The Orchestrator establishes connection using the IP address advertised over MPLS. The connectivity leverages the public Internet link in the Regional Hub.
- Zscaler Resiliency - The Zscaler connectivity is established through the Internet. If the public link fails, then Zscaler connects through MPLS.
Configure SD-WAN Service Reachable
Configure Class of Service
For each Edge consisting of public or private Wide Area Network (WAN) links, the user can define the CoS.
Configure Hot Standby Link
To configure a Hot Standby link on an Edge, ensure that the Edge is upgraded to software image version 4.0.0 or later.
When the path from Edge to Primary Gateway on Active links goes down, and the number of UP Active links is less than the configured Minimum Active Links, the Hot Standby link will come up. The system routes traffic through the Hot Standby path only when the primary link becomes unavailable.
When the path to Primary Gateway appears in Active links, and the number of Active links exceeds the configured Minimum Active Links, the Hot Standby link enters STANDBY mode. The traffic flow switches over to the Active links.The user can monitor the Hot Standby links in the monitoring dashboard. See Configure Interface Settings for Edges and Monitor Hot Standby Links.
Monitor Hot Standby Links
To view the status of Hot Standby links:
Configure DHCPv6 Prefix Delegation for Edges
The Dynamic Host Configuration Protocol for IPv6 (DHCPv6) Prefix Delegation feature allows packet exchange between a DHCP Client and a DHCP Server. The Edge requests that the server provide prefixes via the Wide Area Network (WAN) interfaces for delegation to clients on the Local Area Network (LAN) side. The server provides a prefix to the Edge in response. The Edge then configures an IP address on the LAN interface using this delegated prefix. The Edge starts sending out router advertisements with this prefix.
Configure DHCPv6 Prefix Delegation on an Edge WAN Interface
Configure DHCPv6 Prefix Delegation on an Edge LAN Interface
Configure DHCPv6 Prefix Delegation on an Edge VLAN Interface
Configure Wireless Link Management for Edges
By default, the system applies Profile configurations to all Edges associated with that Profile. If the network requirements vary, the user can manually override these settings for a specific Edge.
For additional information, see Configure Wireless Link Management for Profiles.As a prerequisite to configure the Wireless Link Management feature, the user must set the type of Wide Area Network (WAN) link to "Wireless" at the Edge level by navigating to .
To configure Wireless Link Management settings for an Edge, perform the following steps:
Configure Global IPv6 Settings for Edges
To activate global settings for IPv6 at the Edge level:
Configure Wi-Fi Radio Overrides
To override the Wi-Fi Radio settings at the Edge level, perform the following steps:
Configure Automatic SIM Switchover
- Users must insert SIM cards into both SIM slots on the Edge.
- Users can activate this feature only on a standalone Edge that has High Availability (HA) deactivated. The system prevents activation if it detects an HA configuration. An error displays in Orchestrator when the user activates both the High Availability and Automatic Switchover features.
- Navigate to , and make sure that the IP Type, L2 Settings, and WAN Overlay settings are the same for both Cell1 and Cell2. Other parameters, such as SIM PIN, Network, and APN, do not need to be the same.
- Users must activate both the Cell1 and Cell2 interfaces before the user can enable the Automatic Switchover feature. For additional information, see Configure Interface Settings for Edges.
To configure this feature, perform the following steps:
- To monitor the Edge Switchover status, go to , and then click the link to an Edge. The Overview page appears by default.
Figure 55. Monitor Edge Switchover Status 
- The Auto Dual-Mode SIM column displays the Edge's status with respect to the Automatic Switchover feature configured on that Edge and applies to Edge 610-LTE and Edge 710 5G. See the following table for the color code details:
Table 33. Color Code Details Color Status Green This state indicates that the user has inserted the Secondary SIM and have activated the Automatic Switchover feature. Amber / Orange This state indicates that the user has inserted the Secondary SIM, but have deactivated the Automatic Switchover feature. Purple Indicates that the Secondary SIM is not inserted and the Automatic Switchover feature is activated. Red This state indicates that the user has activated the Automatic Switchover feature, but have not inserted the Secondary SIM. Because the system expects a backup card to be present for failover, it will trigger an alert or status warning. - The Signal column displays the signal strength of the Edge. The system indicates this strength through a series of bars that increase or decrease as the signal quality changes. See the following table for details:
Table 34. Signal Strength Signal Strength (dB) Number of Bars -10 to-85 4 -86 to-102 3 -103 to-110 2 -111 to-120 1 -121 to-999 0 For additional information, see Monitor Edges.
- The user can view the Switchover status on the page. The following two events are displayed on the screen when the Automatic Switchover feature is activated.
Table 35. Switchover Status Events Event Description EDGE_AUTO_SIM_SWITCH This event is triggered in the following scenarios when the Automatic Switchover feature is activated or deactivated: - The Automatic Switchover feature fails to get activated after the Orchestrator sends the configuration to the Edge.
- During the switchover process, when there is at least one active WAN link on the Edge.
EDGE_CELL_SWITCHOVER This event is triggered after the cell switchover process, irrespective of whether the process was successful or not. For additional information, see Monitor Events.
Configure Common Criteria Firewall Settings for Edges
To configure the CC Firewall settings at the Edge level, perform the following steps:
Configure Cloud VPN and Tunnel Parameters for Edges
Configure Cloud Security Services for Edges
When users assign a profile to an Edge, the Edge automatically inherits the Cloud Security Service (CSS) and attributes configured in the profile. Users can override the settings to select a different cloud security provider or modify the attributes for each Edge.
- In the SD-WAN service of the Enterprise portal, go to . The Edges page displays the existing Edges.
- Select the link to an Edge or click the View link in the Device column of the Edge.
- Under the VPN Services category, in the Cloud Security Service area, the Orchestrator UI displays the CSS parameters of the associated profile.
- In the Cloud Security Service area, select the Override checkbox to select a different CSS or to modify the attributes inherited from the profile associated with the Edge. For additional information on the attributes, see Configure Cloud Security Services for Profiles.
- Click Save Changes in the Edges window to save the modified settings.
Manual Zscaler CSS Provider Configuration for Edges
At the Edge level, for a selected manual Zscaler CSS provider, users can override the settings inherited from the profile andconfigure additional parameters manually based on the tunneling protocol selected for tunnel establishment.
If users prefer to manually configure an Internet Protocol Security (IPsec) tunnel in addition to the inherited attributes, users must specify a Fully Qualified Domain Name (FQDN) and a Pre-Shared Key (PSK) for the IPsec session.

- Under GRE Tunnels, click +Add.
Figure 60. Add GRE Tunnel 
- When the Configure Tunnel window appears, configure the following GRE tunnel parameters, and click Update.
Figure 61. Configure Tunnel 
Table 37. Configure Tunnel - Options and Descriptions Option Description WAN Links Select the specific WAN interface that the Edge will use as the source for the GRE tunnel. Tunnel Source Public IP Select the IP address that the Tunnel will use as a public IP address. Users can either select the WAN Link IP or the Custom WAN IP. Ifa user selects Custom WAN IP, then enter the IP address that the tunnel will use as a public IP. Source public IPs must differ across segments when Cloud Security Service (CSS) is configured across multiple segments. Primary Point-of-Presence Enter the primary Public IP address of the Zscaler Data Center. Secondary Point-of-Presence Enter the secondary Public IP address of the Zscaler Data Center. Primary Router IP/Mask Enter the primary IP address of the Router. Secondary Router IP/Mask Enter the secondary IP address of the Router. Primary Internal ZEN IP/Mask Enter the primary IP address of the Internal Zscaler Public Service Edge. Secondary Internal ZEN IP/Mask Enter the secondary IP address of the Internal Zscaler Public Service Edge.
- Zscaler provides the Router IP/Mask and ZEN IP/Mask.
- VeloCloud SD-WAN supports only one Zscaler cloud and one domain for each Enterprise.
- VeloCloud SD-WAN supports only one CSS with GRE per Edge. An Edge cannot have more than one segment with Zscaler GRE automation enabled.
- GRE-WAN - Edge supports a maximum of 4 public WAN links for a Non SD-WAN Destination (NSD), and each link can have up to 2 tunnels (primary/secondary) per NSD. So, for each NSD, the user can have a maximum of 8 tunnels and 8 Border Gateway Protocol (BGP) connections from one Edge.
- GRE-LAN - Edge supports 1 link to a Transit Gateway (TGW) and can have up to 2 tunnels (primary/secondary) per TGW. So, for each TGW, the user can have a maximum of 2 tunnels and 4 BGP connections from one Edge (2 BGP sessions per tunnel).
Automated Zscaler CSS Provider Configuration for Edges
- IPsec/GRE Tunnel Automation
- Zscaler Location/Sub-Location Configuration
IPsec/GRE Tunnel Automation
- In the SD-WAN service of the Enterprise portal, go to .
- Select the Edge to establish automatic tunnels on.
- Select the link to an Edge or click the View link in the Device column of the Edge. The Orchestrator UI displays the configuration options for the selected Edge on the Device tab.
- Under the VPN Services category, in the Cloud Security Service area, the CSS parameters of the associated profile are displayed.
- In the Cloud Security Service area, select the Override checkbox to select a different CSS or to modify the attributes inherited from the profile associated with the Edge. For additional information on the attributes, see Configure Cloud Security Services for Profiles.
- From the Cloud Security Service drop-down menu, select an automated CSS provider and click Save Changes.
Figure 62. IPsec/GRE Tunnel Automation 
The system creates a tunnel within the segment for each Edge public WAN link with a valid IPv4 address. Even in a multi-WAN link deployment, the system selects only one primary WAN link to send user data packets at any given time. The Edge chooses the WAN link with the best Quality of Service (QoS) score using bandwidth, jitter, loss, and latency as criteria. The system automatically creates a Location when the Edge establishes a tunnel to the service provider. The user can view the details of tunnel establishment and WAN links in the Cloud Security Service section.
Zscaler Location/Sub-Location Configuration
After the user has established an automatic IPsec/GRE tunnel for an Edge segment, a Location is automatically created and appears under the Zscaler section of the Edge Device page.
- The user selects that the tunnel is established from the selected Edge, and the system automatically creates a associated Location in the cloud security provider's portal. The user will not be allowed to create a Sub-location if the VPN credentials or GRE options are not set up for the Edge. Before configuring Sub-locations, ensure to understand Sub-locations and their limitations. See https://help.zscaler.com/zia/understanding-sublocations.
- The user selects the same Cloud Subscription that was previously used to create the Automatic CSS.
- In the SD-WAN service of the Enterprise portal, go to .
- Select the link to an Edge or click the View link in the Device column of the Edge. The Orchestrator UI displays the configuration options for the selected Edge on the Device tab.
- Go to the Zscaler section and turn on the toggle button.
Figure 63. Zscaler Location/Sub-Location Configuration 
- From the Cloud Subscription drop-down menu, select the same Cloud Subscription that the user utilized to create the Automatic CSS. The Cloud Name associated with the selected Cloud Subscription automatically appears.
Note:
- Cloud Subscription must have the same Cloud name and Domain name as CSS.
- If the user wants to change the provider for "Cloud Subscription", the user must first remove the "Location" by deactivating CSS and Zscaler, and then perform the creation steps with the new provider.
In the Location table, selecting View under the Action Details column displays the actual values for the configuration fetched from Zscaler, if present. If the user wants to configure the Gateway options and Bandwidth controls for the Location, click the Edit button under Gateway Options. For additional information, see the "Configure Zscaler Gateway Options and Bandwidth Control" section.
- To create a Sub-location, select the + icon in the Sub-Locations table's Action column.
- In the Sub-Location Name textbox, enter a unique name for the Sub-location. The Sub location name should be unique across all Edge segments. The name can contain alphanumeric characters and has a maximum length of 32 characters.
- From the LAN Networks drop-down menu, select a VLAN configured for the Edge. The Subnet for the selected LAN network will be populated automatically.
Note: For a selected Edge, Sub-locations should not have overlapping Subnet IPs.
- Click Save Changes.
Figure 64. Sub-Locations
Note: After the user creates at least one Sub-location in the Orchestrator, an “Other” Sub-location is automatically created on the Zscaler side, and it appears in the Orchestrator UI. The user can also configure the “Other” Sub-location’s Gateway options by selecting the Edit button under Gateway Options in the Sub-Locations table. For additional information, see the "Configure Zscaler Gateway Options and Bandwidth Control" section. - After creating a Sub-location, the user can update the Sub-location configurations from the same Orchestrator page. After clicking Save Changes, the Sub-location configurations on the Zscaler side will be updated automatically.
- To delete a Sub-location, select the - icon under the Action column.
Note: When the user deletes the last remaining Sub-location from the table, the system automatically deletes the "other" Sub-location as well.
Configure Zscaler Gateway Options and Bandwidth Control
To configure Gateway options and Bandwidth controls for the Location and Sub-location, click the Edit button under Gateway Options in the respective table.

Configure the Gateway options and Bandwidth controls for the Location and Sub-location, as needed, and click Save Changes.
The Zscaler Gateway Options and Bandwidth Control parameters that can be configured for Locations and Sub-locations differ slightly; however, the Gateway Options and Bandwidth Control parameters for Locations and Sub-locations are the same ones that can be configured in the Zscaler portal. For additional information about Zscaler Gateway Options and Bandwidth Control parameters, see https://help.zscaler.com/zia/configuring-locations
| Option | Description |
|---|---|
| Gateway Options for Location/Sub-Location | |
| Use XFF from Client Request | Enable this option if the location uses proxy chaining to forward traffic to the Zscaler service, and the user wants the service to discover the client IP address from the X-Forwarded-For (XFF) headers that the on-premises proxy server inserts in outbound HTTP requests. The XFF header contains the client IP address, which the service can leverage to identify the client’s sub-location. Using the XFF headers, the service can apply the appropriate sub-location policy to the transaction. If Enable IP Surrogate is turned on for the location or sub-location, the appropriate user policy is applied to the transaction. When the service forwards traffic to its destination, it removes the original XFF header. It replaces it with one containing the client gateway's IP address (the organization’s public IP address), ensuring that the organization's internal IP addresses are never exposed externally.
Note: This Gateway option is only configurable for the Parent location.
|
| Enable Caution | If the user has not enabled Authentication, enable this feature to display a caution notification to unauthenticated users. |
| Enable AUP | If the user has not enabled Authentication, enable this feature to display an Acceptable Use Policy (AUP) for unauthenticated traffic and require users to accept it. If the user enables this feature:
|
| Enforce Firewall Control | Select to enable the service's firewall control.
Note: Before enabling this option, the user must ensure that their Zscaler account has a subscription for "Firewall Basic".
|
| Enable IPS Control | If the user has enabled Enforce Firewall Control, select this to enable the service's IPS controls.
Note: Before enabling this option, the user must ensure that its Zscaler account has a subscription for "Firewall Basic" and "Firewall Cloud IPS".
|
| Authentication | Enable users from the Location or Sub-location to authenticate to the service. |
| IP Surrogate | If the user has enabled Authentication, select this option to map users to device IP addresses. |
| Idle Time for Dissociation | If the user has enabled Surrogate IP for Known Browsers, specify the time limit for the Zscaler service to use IP address-to-user mapping to authenticate users sending traffic from known browsers. After the defined period elapses, the service will refresh and revalidate the existing IP-to-user mapping to continue authenticating users in browsers. The user can specify the Refresh Time for re-validation of Surrogacy in minutes (default), or hours, or days.
|
| Surrogate IP for Known Browsers | Enable the use of the existing IP address-to-user mapping (acquired from the surrogate IP) to authenticate users sending traffic from known browsers. |
| Refresh Time for re-validation of Surrogacy | If the user has enabled Surrogate IP for Known Browsers, specify the length of time that the Zscaler service can use IP address-to-user mapping for authenticating users sending traffic from known browsers. After the defined period of time elapses, the service will refresh and revalidate the existing IP-to-user mapping so that it can continue to use the mapping for authenticating users on browsers. Users can specify the Refresh Time for re-validation of Surrogacy in minutes (default), or hours, or days.
|
| Bandwidth Control Options for Location | |
| Bandwidth Control | Enable bandwidth controls for the location. If enabled, specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). All sub-locations will share the bandwidth limits assigned to this location. |
| Download | If the user has enabled Bandwidth Control, specify the maximum download bandwidth limit in Mbps. The allowable range is from 0.1 to 99999. |
| Upload | If the user has enabled Bandwidth Control, specify the maximum Upload bandwidth limit in Mbps. The allowable range is from 0.1 to 99999. |
Bandwidth Control Options for Sub-Location (if Bandwidth Control is enabled on Parent Location)
![]() Note: The following bandwidth control options are configurable for sub-location only if the user has bandwidth control enabled on the parent location. If bandwidth control is not enabled at the parent location, the sub-location's bandwidth control options are the same as the location's (Bandwidth Control, Download, and Upload).
|
|
| Use Location Bandwidth | If the user has bandwidth control enabled on the parent location, select this option to enable bandwidth control on the sub-location and use the download and upload maximum bandwidth limits as specified for the parent location. |
| Override | Select this option to enable bandwidth control on the sub-location and then specify the maximum bandwidth limits for Download (Mbps) and Upload (Mbps). This bandwidth is dedicated to the sub-location and not shared with others. |
| Disabled | Select this option to exempt the traffic from any Bandwidth Management policies. In this sub-location, this option can only select up to the available shared bandwidth at any given time. |
Limitations
- In the 4.5.0 release, the system automatically saves the "Other" Sub-location when the user creates a new Sub-location. This marks a shift from earlier versions, where the "Other" category remained unsaved. If the user has recently upgraded to the 4.5.0 release, the system automatically imports the "Other" Sub-location only after the user creates a new, standard (non-Other) Sub-location through the automation interface.
- Zscaler Sub-locations cannot have overlapping IP addresses (subnet IP ranges). Attempting to edit (add, update, or delete) multiple Sub-locations with conflicting IP addresses may cause the automation to fail.
- Users cannot update the bandwidth of Location and Sub-location at the same time.
- Sub-locations support the Use Location Bandwidth option for bandwidth control when its Parent Location bandwidth control is enabled. When the user turns off the Location bandwidth control on a Parent Location, the Orchestrator does not select or update the Sub-location bandwidth control option proactively.
Configure Zscaler Settings for Edges
Configure Multicast Settings for Edges
The Multicast settings apply to all Edges associated with the Profile. The user can select to override the Multicast settings for an Edge:
Configure BFD for Edges
Use the following steps to override the configuration for a specific Edge:
LAN-side NAT Rules at Edge Level
By default, the Edges inherit LAN-Side NAT Rules associated with the Profile. To override the NAT-Side NAT Rules at the Edge level, perform the steps below.
For additional information, see Configure LAN-Side NAT Rules at Profile Level.
0.0.0.0/0.Configure ICMP Probes and Responders
- Configure ICMP Probes:
- Configure ICMP Responders:
Configure Static Route Settings
To configure the Static Route settings:
Configure DNS for Edges
The user can use the DNS Service for either a public DNS provider or a private DNS service managed by a company. To ensure high availability, the system allows the user to specify both a Primary Server and a Backup Server. If the user chooses the public option, the system preconfigures the service to use Google and OpenDNS servers.
The DNS settings apply to all Edges associated with the Profile. The user can override the DNS settings for an Edge as follows:
Configure OSPF for Edges
The Edges inherit the OSPF settings from the associated Profile. The user can override the OSPF settings for an Edge as follows:
Configure BGP from Edge to Underlay Neighbors for Edges
If required, the user can override the configuration for a specific Edge as follows:
Configure ECMP for Edges
ECMP is a routing strategy in which packet forwarding to a single destination can occur over multiple best paths with equal routing priorities. Most routing protocols select the Multi-path routing because it is a per-hop, local decision made independently at each router. It can substantially increase bandwidth by load-balancing traffic over multiple paths. However, there may be significant problems in deploying it in practice.
High throughput allows large branches to support multiple 1G and 10G interfaces effectively. Customers can select multiple interfaces for their LAN network to maximize throughput and resilience. These paths support routing via BGP, OSPF, or static routing protocols.
To configure ECMP for Edges, perform the following steps:
- BGP with AS Multipath-Relax allows multiple paths from different AS numbers if AS path length is same.
- When the user turns on the AS-Path Multipath-Relax toggle button, the system enables BGP AS-Path relax, allowing ECMP on routes with the same AS path length but different AS path content.
- In the SD-WAN service of the Enterprise portal, go to .
- Select New to create a new Non SD-WAN Destinations via Edge.
- Select the Site Subnets tab to view the Next Hop column.
Figure 81. Site Subnets 
- Enter details for Primary VPN Gateway and Secondary VPN Gateway in the Next Hop column.
Note: If no values are defined for Next Hop, the existing bandwidth, latency, and jitter-based load balancing values are applied.
Configure Overlay Route Control for Edges
When the user configures Overlay Route Control (ORC) capabilities for a profile, the settings automatically apply to the Edges associated with the profile. If required, the user can override the ORC configuration for a specific Edge. VeloCloud SD-WAN allows network administrators to configure a community value and an ASN value for route prefixes that they advertise to the overlay without enabling Border Gateway Protocol (BGP) at the Edges.
To override the ORC configuration for a specific Edge, perform the following steps:
Configure High Availability Settings for Edges
Configure VRRP Settings
Configure Virtual Router Redundancy Protocol (VRRP) on an Edge to enable next-hop redundancy in the Orchestrator network by peering with third-party CE router. Configure an Edge to be a primary VRRP device and pair the device with a third-party router.
- Users can enable VRRP only between the Edge and a third-party router on the same subnet via an L2 switch.
- Users can add only one Edge to the VRRP HA group in a branch.
- Users cannot enable both Active-Standby HA and VRRP HA at the same time.
- The Orchestrator supports VRRP on primary routed port, subinterface, and VLAN interfaces.
- Configure the Edge as the primary VRRP device by setting a higher priority to steer traffic through SD-WAN.
- When acting as a DHCP server, the Edge assigns the Virtual IP address as the default gateway for clients. When implementing a separate DHCP relay for the LAN, the administrator must configure the VRRP virtual IP address as the default Gateway.
- When enabling a DHCP server on both the Edge and a third-party router, split the DHCP pool to avoid IP address overlap.
- The Orchestrator does not support VRRP on interfaces with an active WAN Overlay. To use the same link for LAN, create a subinterface and configure VRRP on the subinterface.
- The Orchestrator supports only one VRRP group per broadcast domain within a VLAN, preventing the addition of extra VRRP groups for secondary IP addresses.
- Do not add a Wi-Fi link to the VRRP-configured VLAN. Since link failures never occur, the Edge always remains the primary device.

To configure VRRP settings:
Monitor VRRP Events
Users can monitor the events related to changes in VRRP status.
In the SD-WAN service of Enterprise portal, select .
To view the events related to VRRP, use the Filter option to select a filter from the drop-down menu for querying VRRP events.
Select the CSV option to download a report of the Edge VRRP events in CSV format.
- VRRP HA updated to primary
- VRRP HA updated out of primary
- VRRP Failed
Configure Visibility Mode for Edges
By default, the Edges associated with the Profile inherit the visibility mode. To configure the visibility mode for an Edge:
Configure SNMP Settings for Edges
- In the SD-WAN service of the Enterprise portal, go to .
- Select the required Edge link, and then go to the MIBs for Edge area.
- Select VELOCLOUD-EDGE-MIB from the drop-down menu, and then select Run.
- Copy and paste the results onto a local machine.
- The client host requires all MIBs specified by VELOCLOUD-EDGE-MIB, including SNMPv2-SMI, SNMPv2-CONF, SNMPv2-TC, INET-ADDRESS-MIB, IF-MIB, UUID-TC-MIB, and VELOCLOUD-MIB.
Note: The Remote Diagnostics page provides all of these MIBs for download.
- SNMP MIB-2 System
- SNMP MIB-2 Interfaces
- VELOCLOUD-EDGE-MIB
At the Edge level, override the SNMP settings specified in the Profile, by selecting the Override checkbox. The Edge Override option enables editing of the Edge-specific settings, and discontinues further automatic updates from the configuration Profile for this module. For ongoing consistency and ease of updates, Arista recommends setting configurations at the Profile level rather than the Edge level.
To configure SNMP settings for Edges:
Configure Syslog Settings for Edges
To override the Syslog settings at the Edge level, perform the following steps:
For additional information about Firewall settings at the Edge level, see Configure Edge Firewall.
Configure NetFlow Settings for Edges
To override the NetFlow settings at the Edge level, perform the following steps:
Security Virtual Network Functions
Virtual Network Functions (VNFs) are individual network services, such as routers and firewalls, running as software-only virtual machine (VM) instances on generic hardware. For example, a routing VNF implements all the functions of a router but runs in software-only form, alone or alongside other VNFs, on generic hardware. VNFs are administered and orchestrated within the NFV architecture.
- Configure network services at optimal locations to ensure appropriate security. For example, insert a VNF firewall directly at an Internet-connected branch office. This allows the user to secure traffic locally rather than incurring the inefficiency of a Multiprotocol Label Switching (MPLS) link to hairpin traffic through a distant data center.
- Optimize application performance. Traffic can follow the most direct route between the user and the cloud application using a VNF for security or traffic prioritization. In a VM environment, several VNFs may run simultaneously, isolated from each other, and can be independently changed or upgraded.
The following tables list the third-party firewalls supported by Arista, along with the support matrix:
| VeloCloud Edge Platform | Edge 520v | Edge 840 | Edge 620 | Edge 640 | Edge 680 |
|---|---|---|---|---|---|
| Recommended VM Series Firewall Models | VM-50 Lite | VM-100 | VM-50 Lite | VM-100 | VM-100 |
| Number of vCPUs available for VM-Series Firewall | 2 | 2 | 2 | 2 | 2 |
| Memory available for VNF | 4.5 GB | 6.5 GB | 4.5 GB | 6.5 GB | 6.5 GB |
| Storage space available on Edge for VNF | 64 GB | 120 GB | 64 GB | 120 GB | 120 GB |
| Arista software version | Release 3.2.0 or later | Release 3.2.0 or later | Release 3.4.3 or later | Release 3.4.3 or later | Release 3.4.3 or later |
| Panorama version | Release 8.0.5 or later | Release 8.0.5 or later | Release 8.0.5 or later | Release 8.0.5 or later | Release 8.0.5 or later |
| VeloCloud Edge Platform | Edge 520v | Edge 840 | Edge 620 | Edge 640 | Edge 680 |
|---|---|---|---|---|---|
| Memory available for VNF | 2 GB | 4 GB | 2 GB | 4 GB | 4 GB |
| Number of vCPUs available for VNF | 2 | 2 | 2 | 2 | 2 |
| Storage available on Edge for VNF | 64 GB | 100 GB | 120 GB | 120 GB | 120 GB |
| Maximum Throughput of SD-WAN and Checkpoint VNF | 100 Mbps | 1 Mbps | 300 Mbps | 600 Mbps | 1 Gbps |
| Arista software version | Release 3.3.2 or later | Release 3.3.2 or later | Release 3.4.3 or later | Release 3.4.3 or later | Release 3.4.3 or later |
| Checkpoint VNF OS version | Release R77.20 or later | Release R77.20 or later | Release R77.20 or later | Release R77.20 or later | Release R77.20 or later |
| Checkpoint manager software version | Release 80.30 or later | Release 80.30 or later | Release 80.30 or later | Release 80.30 or later | Release 80.30 or later |
| VeloCloud Edge Platform | Edge 520v | Edge 840 | Edge 620 | Edge 640 | Edge 680 |
|---|---|---|---|---|---|
| Recommended VM Series Firewall Models | VM00, VM01, VM01v | VM00, VM01, VM01v, VM02, VM02v | VM00, VM01, VM01v | VM00, VM01, VM01v, VM02, VM02v | VM00, VM01, VM01v, VM02, VM02v |
| Memory available for VNF | 2 GB | 4 GB | 2 GB | 4 GB | 4 GB |
| Number of vCPUs available for VNF | 2 | 2 | 2 | 2 | 2 |
| Storage available on Edge for VNF | 64 GB | 100 GB | 64 GB | 100 GB | 100 GB |
| Maximum Throughput of SD-WAN and FortiGate VNF | 100 Mbps | 1 Mbps | 300 Mbps | 600 Mbps | 1 Gbps |
| Arista software version | Release 3.3.1 or later | Release 3.3.1 or later | Release 4.0.0 or later | Release 4.0.0 or later | Release 4.0.0 or later |
| FortiOS version | Release 6.0 and 6.2.0 starting from release 4.0.0, FortiOS version 6.4.0 and 6.2.4 are supported. | Release 6.0 and 6.2.0 starting from release 4.0.0, FortiOS version 6.4.0 and 6.2.4 are supported. | Release 6.4.0 and 6.2.4 | Release 6.4.0 and 6.2.4 | Release 6.4.0 and 6.2.4 |
Users can deploy and forward traffic through a VNF on an Edge.
Configure VNF Management Service
Choose the third-party firewall and configure the settings accordingly. Users may need to configure additional settings in the third-party firewall as well. Refer to the deployment guides for the corresponding third-party firewall for additional configuration details.
For the VNF Types Check Point Firewall and Fortinet Firewall, configure the VNF image by using the System Property edge.vnf.extraImageInfos. Users must be an Operator user to configure the system property. If the user do not have the Operator role access, contact the Operator to configure the VNF Image.
The user must provide the correct checksum value in the system property. The Edge computes the checksum of the downloaded VNF image and compares it with the value available in the system property. The Edge deploys the VNF only when both checksum values match.
Configure Security VNF with High Availability
The Enterprise users can configure a security Virtual Network Function (VNF) on Edges configured with High Availability (HA) to provide redundancy.
- Orchestrator and activated Edge running software version 4.0.0 or later. For additional information on the supported Edge platforms, refer to the Support Matrix in Security Virtual Network Functions.
- Configured Check Point Firewall VNF Management service. For additional information, see Configure VNF Management Service.
- In a standalone Edge, enable HA and VNF.
- In Edges configured with HA mode, enable VNF.
- LAN interface to VNF
- WAN interface to VNF
- Management Interface - VNF communicates with its manager
- VNF Sync Interface - Synchronizes information between VNFs deployed on Active and Standby Edges
The Edges have the HA roles as Active and Standby. The VNFs on each Edge run with Active-Active mode. The Active and Standby Edges learn the VNF's state via Simple Network Management Protocol (SNMP). The VNF daemon on the Edges polls SNMP every 1 second.
The system uses the VNF in Active-Active mode, forwarding user traffic only from the associated Edge that is currently Active. On the standby VM, where the Edge in the VM is in standby, the VNF will have only traffic to the VNF Manager and data sync with the other VNF instance.
The following example shows how to configure HA and VNF on a standalone Edge.
Users can insert the security VNF into both the VLAN and routed interface to redirect the traffic from the VLAN or the routed interface to the VNF. See Configure VLAN with VNF Insertion.
Configure Security VNF without High Availability
The Enterprise users can deploy and forward traffic through VNF on the Edge, using third-party firewalls.
- Orchestrator and activated Edge running software versions that support deploying a specific security VNF. For additional information on the supported software versions and Edge platforms, refer to the Support Matrix in Security Virtual Network Functions.
- Configured VNF Management service. For additional information, see Configure VNF Management Service.
Only an Operator can activate the Security VNF configuration. If the Security VNF option is not available, contact the Operator.
Define Mapping Segments with Service VLANs
When the user wants to redirect multiple traffic segments to the security VNF, define a mapping between Segments and service VLANs.
Configure VLAN with VNF Insertion
The Enterprise user can insert the security Virtual Network Function (VNF) into both the Virtual Local Area Network (VLAN) and the routed interface.
Map the segments with service VLANs to enable VNF insertion into the VLANs. See Define Mapping Segments with Service VLANs.
Monitor VNF for an Edge
The Enterprise users can monitor the status of VNFs and VMs on an Edge, and view the VNF network services configured for the Enterprise.
To monitor the status of VNFs and VMs of an Edge:
- In the SD-WAN service of the Enterprise portal, select . The list of Edges, along with the details of configured VNFs, appears as shown in the following screenshot.
Figure 104. Monitor VNF for an Edge 
- Hover over the VNF type (for example, Check Point) in the VNF column to view additional details of the VNF type.
- Hover over the link in the VNF VM Status column to view VNF Virtual Machine Status for the Edge. Selecting the link in the VNF VM Status column opens the VNF Virtual Machine Status window, where the user can view the deployment status for the Edge. For VNFs configured on Edge with High Availability, the VNF Virtual Machine Status window includes an additional column that displays the Edges' Serial Numbers, as shown in the following screenshot.
Figure 105. VNF Virtual Machine Status 
- In the SD-WAN service of the Enterprise portal, go to . The list of Edges, along with details of configured VNFs, is displayed.
Figure 106. Monitor VNF and VM Status 
Monitor VNF Events
The Enterprise users can view Events when the system deploys a VNF VM, when users change its configuration, or enable VNF insertion on a VLAN.
In the SD-WAN service of the Enterprise portal, select .
To view VNF-related events, click the filter option. Select the drop-down arrow next to the Search option and choose to filter either by the Event or by the Message column.
VNF VM config changed" when the configuration changes. The Message column displays the corresponding change as follows:
- VNF deployed
- VNF deleted
- VNF turned off
- VNF error
- VNF is DOWN
- VNF is UP
- VNF power off
- VNF power on
- VNF insertion turned off
- VNF insertion turned on

Configure VNF Alerts
The Enterprise users can configure to receive alerts and notifications for the VNF events.
To configure alerts and notifications related to the VNF events:
Configure Authentication Settings for Edges
At the Edge-level, choose to override the Authentication settings configured for the Profile, by following the steps below:
Configure NTP Settings for Edges
- NTP Clients can synchronize to the LAN/loopback IP address of the Edge as an NTP server, but cannot synchronize to the WAN IP address.
- The Orchestrator does not support NTP synchronization from another segment to LAN interface.
To override NTP settings at the Edge-level, perform the following steps:



























































































