SonicOS 8.2.1 SD-WAN FAQs

Description

This article provides frequently asked questions about SD-WAN in SonicOS 8.2.1. These enhancements introduce improved interface grouping, application-aware path selection, and real-time path health monitoring to enable intelligent traffic steering across multiple WAN connections. 

 

What is SD-WAN in SonicOS

SD-WAN in SonicOS is a policy-based traffic steering mechanism that dynamically selects the best path for network traffic across multiple WAN interfaces.Path selection is based on real-time link conditions, application requirements, and administrator-defined policies rather than static routing

What are the key SD-WAN enhancements in SonicOS 8.2.1

SonicOS 8.2.1 enhances SD-WAN capabilities in these primary areas:

  • Flexible interface grouping strategies
  • Application-aware path selection using SLA policies
  • Real-time path health monitoring and visibility
    • Bandwidth usage monitoring
    • HTTP/HTTPS probe options
    • Load Balancing Mode in Path Selection Profile
  • Schedule per rule support

These enhancements allow administrators to move from basic failover and load balancing to policy-driven, application-centric traffic steering.


What are the recommended interface grouping categories

There are four functional interface categories:

  • VPN tunnel interfaces
  • Direct internet (non-VPN) interfaces
  • General WAN interfaces
  • Private circuit interfaces such as MPLS or leased lines

These categories help ensure correct traffic steering and maintain separation between different network domains.

Are SD-WAN interface groups predefined or selectable options in the user interface

No. SD-WAN interface groups are not predefined or automatically generated in the user interface.They are design guidelines that help administrators organize WAN interfaces based on their role, security characteristics, and routing behavior. In SonicOS SD-WAN, administrators manually create interface groups by selecting interfaces. While the system does not provide predefined group templates, it enforces key architectural boundaries during configuration.

SonicOS does not allow VPN and Non-VPN interfaces to be placed in the same SD-WAN group.

This restriction ensures that traffic cannot automatically switch between encrypted and unencrypted paths within a single group, preserving security boundaries by design.

The recommended grouping strategies such as

  • VPN tunnels
  • direct internet interfaces,
  • general WAN interfaces, and
  • private circuits

represent best practices for structuring SD-WAN deployments. These categories reflect how different interface types behave in terms of trust, encryption, and routing.

 

For example:

  • VPN tunnel interfaces provide encrypted, authenticated connectivity to specific peers
  • Direct internet interfaces provide general outbound access without tunnel-level encryption
  • Private circuits such as MPLS operate in isolated and controlled network environments

 

By organizing interfaces according to these guidelines, administrators can:

  • Ensure traffic remains within the intended security domain
  • Prevent unintended failover across different trust boundaries
  • Apply more precise SD-WAN policies based on application requirements
  • Maintain predictable behavior during failover or path degradation

 

Although SonicOS enforces certain constraints, following these design principles is essential for building a secure and reliable SD-WAN deployment.

 

Why should VPN and direct internet interfaces not be placed in the same group

VPN and direct internet interfaces operate in different security domains.A VPN tunnel provides encrypted and authenticated communication with a trusted peer, while a direct internet interface carries unencrypted traffic to external destinations.Mixing these interfaces in the same group can result in unintended traffic shifts between secure and non-secure paths during failover or path switching. 

 

How does application-aware path selection work

SonicOS 8 uses per-application SLA policies to determine the best path for traffic.

Administrators define thresholds such as:

  • Latency
  • Jitter
  • Packet loss
  • Bandwidth utilization
  • Interface cost (priority)

The firewall continuously evaluates path performance and automatically selects the best available path for each application based on these thresholds. 

 

How are applications identified for SD-WAN decisions

Applications are identified using Application Control, which classifies traffic through Deep Packet Inspection (DPI) rather than relying solely on traditional attributes such as IP address, port number, or protocol.

This allows the firewall to accurately determine the actual application generating the traffic, even in cases where:

  1. Multiple applications share the same ports (for example, HTTPS over port 443)
  2. Applications use dynamic or randomized ports
  3. Cloud and SaaS services operate over common infrastructure

Once identified, the application is mapped to an Application Control signature or category. SD-WAN policies can then use this classification to apply per-application path selection.

For example:

Real-time applications such as voice or video can be steered to low-latency, low-jitter links.Business-critical SaaS applications can be routed over the most reliable ISP.Bulk or non-sensitive traffic can be directed to lower-cost or backup links.

This level of identification ensures that SD-WAN decisions are based on the actual application experience, not just network-level assumptions, resulting in more precise and effective traffic steering.

What happens when a path does not meet SLA thresholds

If a path fails to meet the defined SLA thresholds for an application, traffic is automatically redirected to the next best available path.If no path meets the SLA requirements, the firewall uses the best available path instead of dropping traffic. 

 

How does SonicOS monitor path health

SonicOS continuously monitors each interface using probe traffic.Metrics such as latency, jitter, and packet loss are updated in real time and used to drive path selection decisions.Probe methods include ICMP or HTTP-based monitoring to configured targets. 

 

What probe methods are supported for path monitoring

SonicOS supports multiple probe types for monitoring path health:

  • ICMP
  • TCP
  • HTTP
  • HTTPS

These probes provide flexibility in validating reachability and measuring real-world application performance across different types of networks.

 

What is interface cost-based routing

Interface cost-based routing allows administrators to assign priority or preference to specific WAN links.Lower-cost interfaces are preferred for traffic forwarding, while higher-cost links are used as backup or overflow paths.This provides predictable routing behavior aligned with business or cost requirements.

 

Can SD-WAN policies include private circuits such as MPLS

Yes. Private circuit interfaces such as MPLS and leased lines can be included in SD-WAN policy groups.These interfaces are typically grouped separately to ensure that sensitive or compliance-driven traffic remains on private networks and does not traverse the public internet. 

 

Can SD-WAN be used in multi-ISP environments

Yes. SonicOS SD-WAN supports deployments with multiple WAN connections, including broadband, LTE/5G, MPLS, and VPN tunnels.
(VPN and Non-VPN interfaces cannot be part of the same SD-WAN group)

Traffic can be dynamically steered across these links using SD-WAN policies based on defined SLA thresholds such as latency, jitter, and packet loss.In addition to SLA-based path selection, SonicOS supports bandwidth-based spillover behavior. In this model, a primary interface is used until its configured bandwidth threshold is reached. Once the threshold is exceeded, additional traffic is automatically distributed (spilled over) to other available interfaces in the SD-WAN group.

When a path degrades, becomes congested, or fails to meet SLA conditions, traffic is redirected to the next best available path, ensuring continuity and performance.Administrators can also control how different types of traffic use these links by defining separate SD-WAN policies and interface groups, ensuring that traffic is routed according to both performance requirements and security considerations.

 

What is bandwidth-based spillover in SD-WAN?

Bandwidth-based spillover allows traffic to be distributed across multiple interfaces based on utilization thresholds. A primary interface carries traffic until it reaches a defined bandwidth limit. Once exceeded, additional traffic is automatically routed through secondary interfaces.This helps prevent congestion and ensures efficient utilization of available bandwidth across all WAN links.

 

Where can I find the SDWAN Feature Guide for reference?

For full configuration details, see the official feature guide: SonicOS 8 SD-WAN — About SD-WAN

 

Related Articles

  • GVC 2FA Not Working on NSA 2700 (Gen7)
    Read More
  • Enforce Default Browser for SAML Authentication in NetExtender 10.3.4
    Read More
  • How to troubleshoot a "Login failed - HTTPS User login not allowed from here" Error?
    Read More
not finding your answers?