This document provides VMware SD-WAN Orchestrator, VMware SD-WAN Gateway, and VMware SD-WAN Edge work at different planes depending on how they function and interact
VMware SD-WAN by VeloCloud
VMware SD-WAN Orchestrator, Gateway, and Edge work at different planes depending on how they function and interact:
1 Management plane (VMware SD-WAN Orchestrator)
VMware SD-WAN Orchestrator operates at the management plane as the single point for all configuration, management, monitoring, and troubleshooting options. VMware SD-WAN Orchestrator is responsible for the management of VMware SD-WAN Gateway and VMware SD-WAN Edge.
The orchestrator sends all configuration and management instructions to the edges and gateways.
On initial activation, the edges and gateways initiate the first management traffic toward the orchestrator.
VMware SD-WAN Edge and VMware SD-WAN Gateway send heartbeat packets to VMware SD-WAN Orchestrator every 30 seconds. After missing four consecutive heartbeat packets, VMware SD-WAN Orchestrator assumes the edge or gateway is offline. VMware SD-WAN Edge also sends the flow and link statistics every five minutes to the orchestrator.
CASE#
VMware SD-WAN Edge Heartbeat connect VMware SD-WAN Orchestrator interval
2 Control plane (VMware SD-WAN Gateway)
VMware SD-WAN Gateway operates at the control plane through the controller process that runs in each gateway's software. This controller process establishes a control path between the gateways, edges, and hubs.
VMware SD-WAN Orchestrator distributes the user-defined configuration to the VMware SD-WAN Edge appliances. The edges store the configuration locally and then update the controller.
The controller performs the following functions:
• Propagates the routing information between the edges
• Detects IP addresses, bandwidth, and other WAN characteristics
• Acts as a route reflector
• Stores the routing table locally on VMware SD-WAN Edge appliances for forwarding decisions
The VMware SD-WAN controller establishes a VCMP tunnel from the VMware SD-WAN Edge appliances to the assigned gateways. These control plane communications are encrypted using IPsec.
3 Data plane (gateways, edges, and hubs)
The data plane is where user data traffic flows between VMware SD-WAN Edge and VMware SD-WAN Gateway.
Data plane traffic is encapsulated using VCMP and secured using IPsec encryption.
The local routing table entries of VMware SD-WAN Edge appliances determine the branch-to-branch flow of traffic. If VMware SD-WAN Edge loses connectivity to the management or control plane, it does not impact packet forwarding for established SD-WAN peers and prefixes. However, the operator cannot make configuration changes on VMware SD-WAN Edge while the edges are disconnected from the management and control planes.
CASE#VMware SD-WAN Dynamic Multipath Optimization (DMPO)