Kaspersky SD-WAN includes the following main components:
To deploy the controller, you need to deploy the physical network function of the controller, which is contained in the installation archive. The controller is managed by the orchestrator.
If you want a link to be established between two standard CPE devices, you need to assign the same topology tag to them. You can make a standard CPE device a transit device to allow other CPE devices to establish links through it.
If virtual network functions are used, the architecture of the solution includes a Virtual Infrastructure Manager (VIM) that manages compute, network, and storage resources within the NFV infrastructure. A VIM connects virtual network functions using virtual links, subnets, and ports. The OpenStack cloud platform is used as the VIM.
Kaspersky SD-WAN has a distributed microservice architecture based on Docker containers (see the figure below). A controller can include one, three, or five nodes. For fault tolerance, you can deploy controller nodes on separate virtual machines or physical servers. You can specify virtual machines or physical servers for deployment of controller nodes when deploying the solution, in the ctl
section of the configuration file.
Architecture of Kaspersky SD-WAN
Page top