Citrix SD-WAN

Direct Internet Breakout at Branch with Integrated Firewall

The Internet Service can be utilized in the various deployment modes supported by Citrix SD-WAN.

  • Inline Deployment Mode (SD-WAN Overlay)

Citrix SD-WAN can be deployed as an overlay solution in any network. As an overlay solution, SD-WAN generally is deployed behind existing edge routers and/or firewalls. If SD-WAN is deployed behind a network firewall, the interface can be configured as trusted and Internet traffic can be delivered to the firewall as an internet gateway.

  • Edge or Gateway Mode

Citrix SD-WAN can be deployed as the edge device, replacing existing edge router and/or firewall devices. Onboard firewall feature allows SD-WAN to protect the network from direct internet connectivity. In this mode, the interface connected to the public internet link is configured as untrusted, forcing encryption to be enabled, and firewall and Dynamic NAT features are enabled to secure the network.

For information on how to configure an Internet service through Citrix SD-WAN Orchestrator service, see Internet Service.

localized image

Direct Internet Breakout at Branch with Integrated Firewall