Using a Domain Name When Configuring a Business Policy - Limitations and Workarounds
search cancel

Using a Domain Name When Configuring a Business Policy - Limitations and Workarounds

book

Article ID: 330730

calendar_today

Updated On:

Products

VMware SD-WAN by VeloCloud

Issue/Introduction

How does the edge match traffic to a business policy using a Domain Name?

When a client sends traffic to a specific IP, if that IP is listed in the edge DNS cache as being associated to a domain, it will match it to the business policy that uses that domain.


Expected behavior and limitations:
  • Edges build this DNS cache by snooping the DNS Answers that traverse the edge in response to a DNS query.  This means if the DNS queries don't traverse the edge, they cannot use domains to match in business policies.
  • The TTL for these entries should match the TTL in the DNS Records.
  • The edge can associate multiple IP addresses to the same domain name(as of 3.4.x), helpful for websites that use multiple different IPs.
  • The edge cannot associate multiple domains to the same IP (more on this in the "Known limitation" section below).



Domain.JPG



Environment

VMware SD-WAN by VeloCloud

Resolution

Some alternatives to using domain names in business policies:

If the website uses one specific subnet, the user can configure the business policy to match based on that destination subnet. If on the other hand it uses many subnets the user can modify the application map to create a new application that matches based on the list of subnets, and then create a business policy that matches based on this new application.

If the customer enterprise is using a VMware SD-WAN Orchestrator hosted by VMware, the user may need to open a support ticket with VMware SD-WAN Support if a customized application map is needed.  Please consult CS - VMware SD-WAN – Support (83702) for questions regarding using the support portal.

Another option that is available when the destination subnets are known, is to use Object Groups. The advantage of using Object Groups is that there's no need to make changes to the application map.  The prerequisite for using Object Groups is that both the Edges and the Orchestrator must be using Release 3.4.0 or higher.
 

Known limitations:
1. The edge only caches an IP address to a single domain at a time. 
A possible workaround is to add all the domains associated to the same IP to the business policy.

2. The ability of this feature to work depends on the ability of the edge to add all the required DNS entries, which is limited by the DNS Cache Limit for each platform System Memory RAM.

4 GB - 6k
8 GB - 12k
32 GB - 48k

For platform System Memory (RAM) values refer: https://sase.vmware.com/content/dam/digitalmarketing/vmware-sase/pdfs/sdwan-712-edge-platform-spec-ds-0320.pdf


To learn more about Object Groups, please consult our documentation.