Transmission of traffic between CPE devices and client devices using transport services

About transport services

You can use transport services to transmit traffic between CPE devices and client devices connected to them. Transport services are built on top of segments and consist of service interfaces. Kaspersky SD-WAN supports creating the following transport services:

When creating or editing transport services, you can add backup service interfaces. A backup service interface makes it possible to continue data transfer in the event of a failure of the primary service interface. Backup and primary service interfaces can be created on the same CPE device or on different CPE devices.

Traffic can be mirrored or forwarded between service interfaces of CPE devices. In this case, service interfaces can be added to the transport service.

Managing transport services in an SD-WAN instance template or in a CPE template

You can create P2M services and M2M services as well as L3 VPN services in an SD-WAN instance template and then use it when deploying an SD-WAN instance. Transport services created in the SD-WAN instance template are automatically created for the deployed SD-WAN instance. In this way, you can create transport services before you deploy the SD-WAN instance.

Transport services created for a deployed SD-WAN instance can be added to a CPE template, and then you can specify the template when adding or manually registering CPE devices. This automatically creates service interfaces that are mapped to OpenFlow ports, which are mapped to SD-WAN interfaces of the LAN type of CPE devices. Automatically created service interfaces are added to the transport services that you added to the CPE template. In this way, you do not have to manually connect each CPE device to transport services.

Management transport service

When a CPE device is registered, it automatically connects to a management transport service. The management transport service transmits SSH console traffic, runs scripts, and sends API commands to manage the VIM deployed on a uCPE device.

By default, a P2M management transport service is created in each SD-WAN instance template. When creating or editing a P2M service or an M2M service in the SD-WAN instance template, you can make that P2M service or M2M service the management service.

If necessary, Zabbix monitoring traffic, as well as Syslog and NetFlow protocol traffic can be transmitted through the management transport service. Zabbix monitoring traffic is encrypted by default, but to have Syslog and NetFlow traffic encrypted, such traffic must be transmitted through the management transport service. Transmission of Syslog and NetFlow traffic through the management transport service is governed by routing and forwarding table settings of the CPE device.

In this Help section

Directing application traffic to a transport service

Managing Point-to-Point (P2P) transport services

Managing Point-to-Multipoint (P2M) transport services

Managing Multipoint-to-Multipoint (M2M) transport services

Managing L3 VPN transport services

Managing IP multicast transport services

Managing transport services in an SD-WAN instance template

Managing transport services in a CPE template

Traffic mirroring and forwarding between CPE devices

Page top