Introduction
This guide will assist you in setting up redundant tunnels between your Harmony SASE network and Azure Virtual WAN. By leveraging redundant tunnels, you ensure network continuity even if one of the tunnels experiences disruptions.
Breakdown of topics
- Pre-requisites
- Configuration Steps
- Verifying the Setup
- Troubleshooting
- Support Contacts
Pre-requisites
To successfully follow this guide, you should have:
- An active Harmony SASE account and network.
- The Harmony SASE app is installed on your devices.
- An active Azure account with admin permissions.
Configuration Steps
Create Harmony SASE Gateways
- Your Harmony SASE Network will need to have at least two different gateways in the same network, as listed below.
- Write down the Public IPs for both GWs. Those IPs will be used for the local network gateways on Azure.
- The gateways can be deployed in two separate Regions for comprehensive ISP redundancy.
- The network can be scaled up and adding another region should not affect the connection.
Create a Virtual WAN on Azure
Note
- You can skip this step if you already have a Virtual WAN in your Azure region
- In your Azure Portal under Virtual WANs, click on +Create
- Provide the Virtual WAN with a meaningful name.
- Select the relevant Subscription, Resource group, and Region.
- Type - Standard
- Click on Review+create
- Click on Create
Create virtual hub
Note
- You can skip this step if you already have a Virtual hub in your Azure region
Next, you will need to create a virtual hub:
- In your Azure Portal under the created Virtual WAN, select Hubs from the left pane and click on +New Hub.
- Fill in the following information on the Basics tab.
- Select the relevant Region.
- Provide the Hub with a meaningful name.
- Endpoint - IP Address.
- Hub private address space - select a CIDR range that isn't overlapping with any existing CIDR (/24 range is the minimal one).
- Address Space - Fill in your Permieter81 Address space.
- Virtual hub capacity - select the relevant option according to the maximum number of VMs to be connected through this hub.
- Fill in the following information in the Site to site tab:
- Create a Site to site - Yes
- Gateway scale units - select the appropriate option from the list
- Routing preference - Microsoft network
- Click on Review+create.
- Click on Create.
Create a site
- In your Azure Portal under the created Virtual WAN, select VPN sites from the left pane and click on +Create site.
- Fill in the following information:
- Name: Enter a meaningful name
- Region: Select the appropriate region
- Device vendor: Enter "Harmony SASE" to mark this site as providing connectivity to Harmony SASE
- Private address space: Leave empty
- Click on Next:Links to proceed to the link page and add the following information:
- Link name: Enter a meaningful name, pointing to the first Harmony SASE gateway to be connected
- Link speed: 1024
- Link provider name: Enter "Harmony SASE" to mark this site as providing connectivity to Harmony SASE
- Link IP address: The IP address of the first Harmony SASE gateway to be connected
- Link BGP address: Type any address from the permitted range
- Link ASN: Type the ASN for your Harmony SASE network
- Repeat the above step to add the details for the second connection (the second gateway):
- Click on Review+create and on the next screen click on Create.
Connect the site to your virtual hub
- In your Azure Portal under the created Virtual WAN, select Hubs from the left pane and select your hub.
- On the hub page click on VPN (Site to site) from the left pane under Connectivity.
- On the VPN (Site to site) page clear the filter to view your site in the list.
- Select the checkbox next to the created site and click on Connect VPN Sites.
- On the Connect sites screen add the following information:
- Pre-shared key: Enter a PSK to be used for this connection
- Protocol: IKEv2
- IPsec: Custom
- SA Lifetime in seconds: 28800
- IKE Phase 1:
Encryption - AES256
Integrity/PRF - SHA256
DH Group - DHGroup14 - IKE Phase 2(ipsec):
IPsecEncryption - AES256
IPsec Integrity - SHA256
PFS Group - PFS14 - Propogate Default Route: Disable
- Use policy based traffic selector: Disable
- Configure traffic selector: No
- Connection Mode: Default
- Click on Connect.
- On the VPN (Site to site) screen Configure the gateway by clicking on View/Configure
- On theEdit VPN Gateway screen add the following information:
- Under VPN Gateway Instance 0, set the Custom BGP IP Address to be from the same network range as the BGP address for the first link
- Under VPN Gateway Instance 1, set the Custom BGP IP Address to be from the same network range as the BGP address for the second link
- Click on Edit and then on Confirm.
- From the VPN (site to site) screen download the configuration by clicking on Download VPN Config
Creating the High Availability Harmony SASE Tunnel
- On Your Harmony SASE Admin console, Navigate to your network.
- Click "..." next to one of the gateways and select Add Tunnel.
- Select Redundant Tunnels.
- Select a logical name for your tunnel,
- For example, if your V-Net is located in the EU-West region of Azure, you could name the tunnel "EUWest".
- Copy the values for the first tunnel from the downloaded configuration file:
- Shared Secret: PSK
Harmony SASE gateway Internal IP: Inside IP Addresses of Customer Gateway - Remote Public IP & Remote ID: Public IP Addresses of Instance0
Remote Gateway internal IP: BGPPeeringAddress of Instance0 - Remote Gateway ASN: Azure ASN
In Harmony SASE, your Tunnel page should look like this:
- Shared Secret: PSK
- Repeat step 5 for the second Tunnel.
- Under Shared Settings, you'll want to make sure to select Any(0.0.0.0/0) for both sides. ASN number should remain the same for the Harmony SASE side.
- Under Advanced Settings match the following (unless you have configured customer settings on the Azure side):
- Click Add Tunnel.
Creating Static Routes
- Navigate to your Harmony SASE network and add the route to the corresponding subnet in Azure.
- You'll want to select "..." next to your network and then Routes Table.
- Once that has been completed be sure to select "Apply Configuration" and let the route changes propagate on the Harmony SASE side.
Verifying the Setup
Once set up, your redundant tunnels should be active. To confirm, go to your Harmony SASE dashboard, find the tunnels you started, and ensure their status shows "Up". Connect to your network with the Harmony SASE agent and try accessing resources in your Azure environment.
Troubleshooting
If you encounter issues during or after the setup, try reviewing your settings to ensure everything matches the instructions. In particular, check the IP addresses and other details you entered during setup. If issues persist, please consult our dedicated support.
Support Contacts
If you have any difficulties or questions, don't hesitate to contact Harmony SASE's support team. We offer 24/7 chat support on our website at Perimeter81.com, or you can email us at sase-support@checkpoint.com. We're here to assist you and ensure your VPN tunnel setup is a success.