Cloud & Branch Connector
Deploying Zero Trust SD-WAN Devices
Enabled by the Zscaler Zero Trust Exchange (ZTE), Zero Trust Software-Defined Wide Area Network (SD-WAN) Devices are Zscaler Branch Connector hardware devices that use Zero Trust Branch Connectivity to simplify traffic forwarding to Zscaler services. To learn more, see Understanding Zero Trust SD-WAN Devices.
To deploy a Zero Trust SD-WAN Device:
- Upon receipt of the Zero Trust SD-WAN Device, install your hardware according to the instructions provided.
- After installing your device, log in to the Zscaler Cloud & Branch Connector Admin Portal.
- Go to Administration > ZT Devices.
- On the ZT Devices page, view your Zero Trust SD-WAN Device and copy the Serial Number to a secure location.
- Go to Administration > Provisioning & Configuration > Branch Configuration.
- On the Branch Configuration Template page, click Add Branch Connector Configuration Template.
- Configure a Branch Configuration Template with the serial number of the Zero Trust SD-WAN Device.
- On the Branch Configuration Template page, under the Status column of the configuration template, change the status from Staged to Ready to Deploy.
In the Status Update Confirmation window, click Update to complete deployment. This process might take a few minutes.
The LED indicator light on the front of the Zero Trust SD-WAN Device shows the Zero Touch Provisioning (ZTP) status, as well as the status of the Zero Trust SD-WAN Device after it is deployed.
Indicator State Zero Trust Provisioning Status Zero Trust SD-WAN Device Status Solid red Initializing Not operational (control and data tunnels are down) Blinking red ZTP is pending N/A Blinking green ZTP is in progress N/A Solid green All services are running Normal operation (control and data tunnels are up)
After deployment is complete, the status of the configuration template is Deployed.
After Zero Trust SD-WAN Devices are deployed, you can:
- View the deployment, location, and status of your deployment from the Cloud & Branch Connector Monitoring page.
- Modify the Zero Trust SD-WAN Devices from the Physical Branch Devices page.
- Configure Traffic Forwarding Rules.
- Configure DNS Gateways.
If your Zero Trust SD-WAN Device is deployed in gateway mode, you can edit its configuration after deployment by clicking the edit icon on the Branch Configuration Template page.