Kaspersky SD-WAN

About the interaction of the CPE device and the Controller

April 17, 2024

ID 269169

After a CPE device is registered, an encrypted or unencrypted management session is established between each of its SD-WAN interfaces of the WAN type and the available Controllers. One of these sessions is the primary session, and the others are in standby mode.

Through the primary session, the CPE device receives tasks related to managing the virtual switch, for example, modifying path settings. If the primary session is terminated, a new primary session is selected in accordance with the settings that you can specify when configuring the connection of the CPE device to the orchestrator and Controller.

The figure below shows sessions established between three Controllers and a CPE device with two SD-WAN interfaces of the WAN type:

  • 10.0.1.1 → ctl1:6653
  • 10.0.2.1 → ctl1:6654
  • 10.0.1.1 → ctl2:6653
  • 10.0.2.1 → ctl2:6654
  • 10.0.1.1 → ctl3:6653
  • 10.0.2.1 → ctl3:6654

    Connection diagram of multiple CPE devices with three Controllers

    Sessions between a CPE device and three Controllers

To display the table of CPE devices with information about management sessions, go to the Infrastructure menu section, click Management → Configuration menu next to the SD-WAN Controller to which the devices are connected, and in the displayed controller settings menu, go to the Switches section. Information about management sessions is displayed in the following table columns:

  • Name is the name of the CPE device.
  • ID is the sequence number of the CPE device. The device with the lowest sequence number was the first to connect to the Controller.
  • Status is the status of the CPE device in relation to the Controller:
    • Active means the device can be used to relay traffic.
    • Inactive means the device cannot be used to relay traffic.
  • Connection is the status of the CPE device connection to the Controller:
    • Connected means a management session is established between the device and the Controller.
    • Disconnected means no management session is established between the device and the Controller.
  • MAC is the MAC address of the CPE device.
  • Interface are SD-WAN interfaces of the WAN type from which management sessions are established with the Controller.
  • Primary session is the SD-WAN interface of the WAN type from which the primary management session is established with the Controller.
  • IP is the IP address of the SD-WAN interface of the WAN type from which the management session is established with the Controller.
  • Created is the date and time when the CPE device was registered.
  • Location is the address of the CPE device location.
  • Latency (ms.) is the latency in milliseconds of the management session between the CPE device and the Controller.
  • Description is a brief description of the CPE device.

See also

Automatic registration of CPE (ZTP) devices

Repeated registration of CPE devices

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.