SD-WAN Internet policies vs Local Internet Breakout

Brucer
Comes here often

SD-WAN Internet policies vs Local Internet Breakout

I'm unclear about the distinction between SD-WAN Internet policies vs Local Internet Breakout on the MX. If I define an SD-WAN Internet policy, does that on it's own cause matching traffic to be locally routed directly to the Internet (DIA), or do I also need a Local Internet Breakout Policy.

If not, then what is the difference between the two?

My understanding (that I am trying to confirm via this post) is that DIA/local breakout REQUIRES a local breakout policy, but if you also want to define which WAN link to use (or load balance) then the SD-WAN policy provides this additional functionality when combined with local breakout.

Do I have it right? Thanks.

 

 

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

Local internet breakout is used when you do not want traffic to a certain destination to be sent over SD-WAN.

 

The SD-WAN internet policy is used when you want traffic to a destination on the internet to go through one of the specific WANs.

 

They are different features.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Brucer
Comes here often

thanks.. what i'm asking is whether you need both (as I think you are saying) or are SD-WAN Internet policies used on their own (without corresponding local breakout policy)?

ww
Kind of a big deal
Kind of a big deal

Sd internet works for traffic outside the tunnel.

 

If you dont use a default route in your tunnel you dont need vpn exclusions 

If you do have a default route in the tunnel you can use vpn exclusions

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels