You can deploy Kaspersky SD-WAN for multiple tenants which can be independent clients or offices or departments of your organization. A solution deployed for a tenant is referred to as an SD-WAN instance. After deploying the solution, you need to create at least one tenant and deploy an SD-WAN instance for it.
When you create a tenant, the tenant gets its own self-service portal for managing the SD-WAN instance. The created tenants are isolated so they cannot access each other's self-service portals and their IP networks may overlap. The number of created tenants must not exceed the number of tenants that you specified in the external
section of the configuration file when deploying the solution.
To deploy an SD-WAN instance for a tenant, you need to create an SD-WAN instance template. In the SD-WAN instance template, you must specify the basic settings of the SD-WAN instance, such as quality of service and transport service settings. You also need to add the tenant to the SD-WAN instance template to have the SD-WAN instance template settings applied to the SD-WAN instance when you deploy the SD-WAN instance for that tenant.
If the tenant has not been added to any SD-WAN instance template, the Default SD-WAN template is used when deploying an SD-WAN instance for that tenant. You can assign a different SD-WAN instance template as the default.
If the settings that you specified in the SD-WAN instance template do not match the actual parameters of the SD-WAN instance, that SD-WAN instance is not deployed for the tenant. For example, an SD-WAN instance is not deployed if the number of controller nodes specified in the SD-WAN instance template does not match the actual number of controller nodes of the SD-WAN instance.
After deploying the SD-WAN instance, you can view the monitoring results and service requests of that SD-WAN instance as well as configure its controller nodes. You can also add tenants to a deployed SD-WAN instance to let them use the controller of that SD-WAN instance. This avoids the need to deploy a separate SD-WAN instance for each tenant.
You can group SD-WAN instances into SD-WAN instance pools for load balancing when a large number of CPEs are used. You can add CPE devices to an SD-WAN instance pool. If you have added a CPE device to an SD-WAN instance pool, the orchestrator automatically selects the SD-WAN instance with the lowest number of CPE devices and adds the CPE device to that SD-WAN instance. If SD-WAN instances in the SD-WAN instance pool have the same number of CPE devices, the orchestrator adds the CPE device to a randomly selected SD-WAN instance.