Citrix SD-WAN Orchestrator

Citrix SD-WAN Orchestrator service

Citrix SD-WAN Orchestrator service is a cloud-hosted, multitenant management service available to Do It Yourself enterprises and Citrix Partners. Citrix partners can use Citrix SD-WAN Orchestrator service to manage multiple customers with a single pane of glass, and suitable role based access controls.

Citrix SD-WAN Orchestrator service provides a single-pane of glass management platform for Citrix partners to manage multiple customers centrally, with suitable role based access controls.

The following are some of the key capabilities:

  • Multi-tenancy & RBAC: The service enables Citrix partners to on-board and manage multiple SD-WAN customers, with a single pane of glass and suitable role based access controls.
  • Centralized configuration: Centralized configuration of SD-WAN networks, with guided workflows, visual aids, and profiles.
  • Zero touch provisioning: Seamless bring up of the network and connections.
  • Application-centric policies: Application based traffic steering, Quality of Service (QoS), and Firewall policies, configurable globally or per site.
  • Hierarchical summarization of health: Ability to centrally monitor the health, usage, quality, and performance of a network as a whole, with the ability to drill down into individual sites and associated connections.
  • Troubleshooting: Device and Audit Logs, Diagnostic utilities such as Ping, Traceroute, Packet Capture to troubleshoot network connectivity issues.

Prerequisites for Citrix SD-WAN Orchestrator service usage

  • Appliances: A minimum of two appliances (Standard Edition - Physical or Virtual) is required. For information on provisioning a new SDWAN VPX instance, see Citrix SD-WAN VPX.

    Each SD-WAN appliance or virtual instance must have an IP address configured statically or via DHCP and must include DNS entry to resolve the Fully Qualified Domain Name (FQDN) to Citrix Cloud Services.

  • Internet Connectivity: Each of the branch and DC sites must have Internet connectivity to access Citrix SD-WAN Orchestrator service.

  • Appliances need access to the following mentioned domain names. Citrix recommends whitelisting *.citrixnetworkapi.net:443. Here is a list of individual cloud service URLs that have to be whitelisted on the appliance firewall for zero-touch deployment:

    • Global endpoints:

      • sdwan-home.citrixnetworkapi.net:443
      • sdwanzt.citrixnetworkapi.net:443
      • sdwan-applmgr.citrixnetworkapi.net:443
      • download.citrixnetworkapi.net:443
    • Region specific endpoints [where region is us1, eu1, ap1, or ap2]

      • download-region.citrixnetworkapi.net:443
      • sdwan-applmgr-region.citrixnetworkapi.net:443
      • sdwan-logging-region.citrixnetworkapi.net:443
      • sdwan-statistics-collector-region.citrixnetworkapi.net:443
      • sdwan-saasgw-region.citrixnetworkapi.net:443
      • sdwan-policy-region.citrixnetworkapi.net:443
  • Citrix SD-WAN software version 10.1.1 is the minimum appliance software supported on Citrix SD-WAN Orchestrator service.

Here’s a demo video providing an overview of the solution.

Citrix SD-WAN Orchestrator service Overview

Citrix SD-WAN Orchestrator service