Overview of SteelConnect SD-WAN
SD-WAN lets enterprises simplify their network configuration and management. With SD-WAN, enterprises can intuitively manage networks based on parameters relevant to their businesses such as applications, users, locations, performance, and security.
The Riverbed SD-WAN solution provides an intelligent and intuitive approach to designing, deploying, and managing distributed networks for the modern hybrid enterprise. The solution consists of appliances and a centralized management console that the administrator uses to view network health, deploy appliances, and make changes to policies. SteelConnect high-level architecture shows the high-level architecture.
SteelConnect high-level architecture
SteelConnect components comprise the following:
SteelConnect Manager
SteelConnect gateways
SteelConnect switches
SteelConnect access points
SteelConnect Manager
SteelConnect Manager (SCM) is a web-based, management portal that lets you design the network before deploying any hardware. You can use SCM to push configurations to the devices for deployment of infrastructure without the need for an engineer to be on site. After deployment, SCM provides network visibility for manageability and troubleshooting.
The SCM server currently resides in the global Amazon Web Services (AWS) cloud public infrastructure and orchestrates a series of services hosted by Riverbed. Each service has dependencies that function as a part of the collective SteelConnect infrastructure. These services include:
Management console
Global certificate authorities (CAs)
Network Time Protocol (NTP)
Dynamic Domain Name System (DNS)
IP address reflectors, which are simple mechanisms for all gateways to find their public IP address per uplink and report the address to SCM.
Structured Query Language (SQL) relational databases that keep track of which SCMs are associated with which organizations, sites, and devices.
SteelConnect appliances (gateways, switches, and access points) connect to core services, and the services associated with them, to find their assigned server. After an appliance is paired with SCM, it connects only to its corresponding SCM. Each SCM communicates through various services for updates regarding the appliance registration and management changes. All communication between the appliances and SCM, as well as all interoperating services inside of SCM, are authenticated through x509 certificate validation. These Riverbed-owned certificates are exchanged and validated for authenticity.
SCM manages all appliances, including all firmware upgrades.
SteelConnect gateways
SteelConnect gateways are physical and virtual secure WAN gateways that provide unified connectivity (point-to-point and full-mesh) and enforcement of global policy across on-premises and cloud network environments, zero-touch provisioning, and secure automated VPN management.
Gateways are categorized into hardware and software appliances. The gateways automatically map into connected network segments, called zones, to:
provide basic network services.
handle one or more uplinks, either by concurrent use or as backup.
enable policy enforcement.
enforce security.
enable extended reporting for connected zones.
connect multiple sites with a secure, full-mesh VPN or a hub-and-spoke VPN deployment.
The SteelConnect gateway comes in various form factors to accommodate a variety of network architectures:
Branch gateways - SDI-130, SD-130W, SDI-330, SDI-1030
Data center gateway - SDI-5030
SteelHead SD - 570-SD, 770-SD, 3070-SD models deliver the benefits of SteelHead WAN optimization and SteelConnect SD-WAN while providing the flexibility of a single box solution.
SteelConnect gateway virtual machine (VM) - Available for various virtualization platforms in these image types:
VMware
VirtualBox
KVM
Hyper-V
XenCenter
Amazon EC2
Virtual gateways on IaaS cloud environments - Instances of the SteelConnect gateway of various sizes can be deployed on AWS or Azure. When you deploy a gateway in your cloud or multiple clouds, the RouteVPN feature lets you connect your data center to the cloud, or even multiple clouds with each other.
SteelConnect switches
Enable plug-and-play multizone Layer 2 connectivity.
Provide Power over Ethernet (PoE) to PoE-enabled appliances, including third-party devices.
SteelConnect access points
Provide network access to WiFi clients.
Prioritize applications and enforce policies at the edge of the network.