Citrix SD-WAN Platforms
Deployment overview
To deploy SD-WAN WANOP on Microso Azure:
1. Deploy a Citrix ADC VPX instance on the Azure cloud. For more information, see Deploy a Citrix
ADC VPX instance on Microso Azure. Configure four network interfaces in four dierent subnets
and enable IP forwarding on all the network interfaces. The four network interfaces are used as:
• Management interface
• WAN side interface, for IPsec tunnel
• LAN side interface, to connect to the server
• WANOP communication interface, to communicate with the Citrix SD-WAN WANOP VPX on
the Azure cloud.
2. Deploy a Citrix SD-WAN WANOP VPX on Azure cloud. For more information, see the deployment
procedure below.
Note: Enable IP forwarding on WANOP interface.
3. Configure an IPsec tunnel between the on-premises appliance and the Citrix ADC VPX on Azure
cloud, using the public IP address of Citrix ADC WAN interface. For more information on config-
uring IP tunnels see, IP Tunnels.
4. Configure Citrix ADC VPX to redirect the packets to Citrix SD-WAN WANOP VPX. Use the private
IP address of WANOP communication interface and create a load balancing virtual server. For
more information, see Create a load balancing virtual server
5. Configure the following route tables on Azure:
• Route table for WANOP facing interface on Citrix ADC VPX – Route table entries must have
source and destination address as client and server subnets respectively. The Citrix ADC
VPX’s WANOP facing interface IP address is the next hop.
• Route table for Citrix SD-WAN WANOP interface - Route table entries must have source and
destination address as client and server subnets respectively. The Citrix SD-WAN WANOP
interface IP address is the next hop.
In the above example, when the source tries to access an application on the cloud destination, the
packets flow through the established IPsec tunnel. At the Azure cloud VNET end, the Citrix ADC VPX
receives the packets, decrypts, and forwards it to the Citrix SD-WAN WANOP VPX. The Citrix SD-WAN
WANOP VPX processes the packets, optimizes it, and sends it back to Citrix ADC VPX. The Citrix ADC
VPX sends the packet to the destination. On the return path, the Citrix ADC VPX forwards the packets
to Citrix SD-WAN WANOP VPX for optimization. The optimized packets are transmitted back to the
source through the established IPsec tunnel.
© 1999-2021 Citrix Systems, Inc. All rights reserved. 392