> Source: [sk181997](https://support.checkpoint.com/results/sk/sk181997)

# sk181997 - SD-WAN for Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk181997 |
| Date Created | 2024-02-06 |
| Last Modified | 2024-11-11 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Solution

**Table of Contents:**

1. Introduction
2. Requirements for SD-WAN
3. Unsupported Features
4. SD-WAN Feature Overview
5. Getting Started
6. Smart SD-WAN Feature
7. Monitoring and Controlling SD-WAN
8. Defining a New Steering Object
9. Link Aggregation or Prioritization
10. Monitoring Link Quality
11. Monitoring Traffic
12. Internet Connection as Backup
13. VPN
14. Conclusion
15. Feedback
16. Support

(1) Introduction {#Introduction}
--------------------------------

Welcome to the SD-WAN Guide for Locally Managed Quantum Spark appliances.

SD-WAN technology centralizes network management, improving performance and reducing costs by dynamically routing traffic over the most optimal path.

By providing real-time visibility and control, and automatic rerouting during outages, SD-WAN enhances network reliability.

For more information, see the [R81.10.X Quantum Spark Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Default.htm).

(2) Requirements for SD-WAN {#Requirements for SD-WAN}
------------------------------------------------------

A Locally Managed Quantum Spark appliance must meet these requirements to work with SD-WAN:

* **Check Point Appliances:** Supported on 1500, 1600, 1800, 1900, 2000 models running the firmware [R81.10.10 and higher](https://support.checkpoint.com/results/sk/sk179615).

* **Internet Connections:** Must have a minimum of two Internet connections configured with two different ISPs.

* **SD-WAN Breakout Policy:** Only Local Breakout policy is supported.

* **Required Software Blades:** Must enable the Firewall, URL Filtering, and Application Control blades.

(3) Unsupported Features {#Unsupported Features}
------------------------------------------------

* IPv6

* QoS

* Dynamic Routing

* Layer 2 Lines

* Bridge interfaces

* Alias interfaces

(4) SD-WAN Feature Overview {#SD-WAN Feature Overview}
------------------------------------------------------

SD-WAN in Locally Managed Quantum Spark appliances provides an intuitive interface, offering detailed visibility and control. The comprehensive monitoring section provides real-time status updates of all the active internet connections, helping you efficiently assess the network performance.

The SD-WAN Rule Base has a combination of manual rules that you can tailor to your specific needs and predefined Smart SD-WAN rules offering best-practice configurations. Each rule allows granular control over the network traffic flow, allowing you to configure specific parameters such as source, destination, application, and service.

One of the key components in these rule configurations is the 'Steering Object.' This element intelligently guides the direction of your traffic based on the real-time status of the internet connection. Whether prioritizing specific applications, managing traffic during peak hours, or handling failover scenarios, the Steering Object dynamically optimizes your network performance, ensuring a seamless connectivity experience.

(5) Getting Started {#Getting Started}
--------------------------------------

SD-WAN requires a minimum of two Internet connections:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan1202402071244131.png)

1. Navigate to the **Access Policy** view \> **Firewall** section \> **SD-WAN** page.

   Note - The SD-WAN blade and Smart SD-WAN rules are enabled by default.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan2202402071245302.png)
2. To see the SD-WAN policy, in the bottom section, click the **Policy** tab.

3. To add a new Steering Object, click **Manage Steering Objects**.

   See more information in the section "Defining a New Steering Object".

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan3202402071248223.png)
4. To add new rules, click **New**.

   Note - You can select multiple objects in the **Source** column and in the **Applications / Services** column.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan4202402071250074.png)

(6) Smart SD-WAN Feature {#Smart SD-WAN Feature}
------------------------------------------------

Smart SD-WAN is a special feature unique to Quantum Spark. It includes predefined rules with predetermined behaviors for each category.

For example, in the case of Web Conferencing, Smart SD-WAN gives preference to the internet connection with the lowest latency. It utilizes all links that meet the predefined thresholds to enhance network performance.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/Picture1202402061639461.png)

You can disable it with the toggle on the left side:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan5202402071255185.png)

(7) Monitoring and Controlling SD-WAN {#Monitoring and Controlling SD-WAN}
--------------------------------------------------------------------------

To monitor your traffic, in the bottom section, click the **Performance** tab.

On this tab you can see:

* What Internet connections are used in each steering object.

* How many connections are going out of each interface for each steering object.

* The amount of traffic going out of each interface for each steering object.

* What is the current status of each link comparing to the steering thresholds.

Examples:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan6202402071756041.png)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan7202402071756222.png)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan8202402071756423.png)

(8) Defining a New Steering Object {#Defining a New Steering Object}
--------------------------------------------------------------------

The Quantum Spark SD-WAN allows you to define a new steering object. You can select which interfaces will be part of the SD-WAN selection and set your thresholds.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/Picture2202402061640042.png)

(9) Link Aggregation or Prioritization {#Link Aggregation or Prioritization}
----------------------------------------------------------------------------

You can configure Smart SD-WAN to use Link Aggregation or Prioritize and it will apply on all Smart SD-WAN rules.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan9202402071302159.png)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan9202402071757334.png)

(10) Monitoring Link Quality {#Monitoring Link Quality}
-------------------------------------------------------

Ensure optimal performance by regularly monitoring link quality. The Quantum Spark SD-WAN interface offers real-time monitoring tools for this purpose.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/moni202402061641103.png)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan10202402071757535.png)

(11) Monitoring Traffic {#Monitoring Traffic}
---------------------------------------------

With Quantum Spark SD-WAN, monitor both transmitted and received traffic. Keep track of your network usage and adjust as needed to maintain smooth operations.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/gr202402061642335.png)

(12) Internet Connection as a Backup {#Internet Connection as Backup}
---------------------------------------------------------------------

When managing your SD-WAN network, you might have an internet connection that you prefer to use only as a backup, i.e. should only be active when other connections are not operational. This could be useful in scenarios where you have a more expensive, but reliable connection that you want to reserve for emergencies, or a slower connection that you only want to use when necessary.

To configure an Internet connection as a backup:

1. Navigate to the **Device** view \> **Network** section \> SD-**Internet** page.

2. Double-click the Internet onnection you wish to designate as a backup.

3. Modify the settings to ensure this connection is only activated when other preferred connections are not up.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181997/sdwan11202402071758496.png)

(13) VPN {#VPN}
---------------

**Note** - Implementing Quantum Spark SD-WAN does not interfere with existing Virtual Private Network (VPN) configurations. Your VPN and the traffic it carries will continue to function just as it did prior to enabling SD-WAN.

Quantum Spark SD-WAN is designed to seamlessly integrate with your existing network setup, including VPN connections and routing.

(14) Conclusion {#Conclusion}
-----------------------------

SD-WAN technology will revolutionize network management for Quantum Spark Appliances. With Quantum Spark SD-WAN, you can enjoy more control, better performance, and lower costs, all with the simplicity of Local Management.

(15) Feedback {#Feedback}
-------------------------

For feedback, [send us an email](mailto:orihal@checkpoint.com;zachis@checkpoint.com;noaal@checkpoint.com?subject=sk181997%20-%20SD-WAN%20for%20Locally%20Managed%20Quantum%20Spark%20Appliances&body=Hello%20Ori%2C%20Zachi%2C%20and%20Noa%0A%0AENTER%20YOUR%20FEEDBACK%20HERE%0APROVIDE%20AS%20MANY%20DETAILS%20AS%20POSSIBLE).

(16) Support {#Support}
-----------------------

Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
