Lysora || SD-WAN: Planning and Eligibility Requirements ||

Lysora || SD-WAN: Planning and Eligibility Requirements ||

SD-WAN: Planning and Eligibility Requirements 


Article Description

This guide details what your infrastructure requires to utilize Lysora's built-in, subscription-free SD-WAN features.


Lysora SD-WAN is a license-free, cloud-managed networking solution engineered to connect multiple business sites or offices seamlessly over the internet. By utilizing intelligent NAT tunnel traversal, Lysora eliminates traditional VPN complexities and the requirement for dedicated public static IPs, facilitating fast, automated site-to-site connectivity. 


Requirements / Before You Begin

• Hardware Dependencies: You must use Lysora Cloud-Managed Routers at each site (such as the Lysora LR300G-P or LR100G). The embedded software functions natively as the SD-WAN edge device. 

• Management Credentials: An active account on the Lysora Cloud platform via the mobile app or web console is required. 

• ISP (internet service provider) active and connected to the internet.


Procedure

Quick Deployment Overview

Once planning is complete, provisioning multiple sites follows an automated flow:

  1. Local Setup: Connect the Lysora router's WAN port to your internet modem. Log into the local management gateway (192.168.100.1) using default or customized admin keys to confirm initial internet handshakes via DHCP or PPPoE.

  2. Cloud Onboarding: Use the Lysora Cloud App to discover new system hardware automatically via its self-organizing network engine.

  3. One-Click SD-WAN: Navigate to the network-wide layout, enable SD-WAN features, and let the cloud system dynamically link multiple offices using visual traffic management interfaces. 

Hub Spoke Networking

In the Hub Spoke networking mode, branches are connected only to the headquarters, and cannot communicate with each other.

(1) Select the Hub Spoke networking mode, and click Next.

image.png

(2) Select the project where the headquarters gateway is located.

image.png

(3) Select the projects where the branch gateways are located.

image.png

(4) To configure WAN ports, click WAN Settings, and select the WAN port that permits access over tunnels for each node.

When multiple WAN ports are selected, you can configure the WAN policy:

  • Auto: The system automatically detects the WAN port state, and selects the WAN port intelligently.

  • Active/Standby: The system automatically switches to the standby WAN port when the active WAN port is unavailable.

The default value of WAN Port for Tunnel Access is All WAN Ports, and the default value of WAN Policy is Auto. After the configuration is complete, click OK.

image.png

(5) Once network projects are designated, choose Next and assign the VLAN configuration for each site within the SD-WAN deployment.

Note: Confirm that subnet IP addresses assigned to the SD-WAN group do not overlap with existing network infrastructure devices.

Subnet Creation: Select the plus icon beside the target project, then specify the description, IP distribution mechanism, VLAN tag, and gateway address to deploy a VLAN.

Subnet Conflict Resolution: Overlapping subnets are automatically flagged in red. Adjust settings manually following system prompts or initiate the Smart Adjustment tool to correct address collisions.

image.png

(6) Upon confirming the VLAN parameters, select Create an SD-WAN Group. Once the setup pushes successfully, choose View monitoring dashboard to review operational metrics. Additional information regarding this console is available in Introduction to SD-WAN Monitoring Dashboard.

image.png

Mesh Networking

In the Mesh topology, every SD-WAN branch maintains direct interconnectivity with all other sites, establishing a completely unified peer network.

(1) Choose the Mesh topology option and proceed by clicking Next.

image.png

(2) Select the projects for mesh networking.

image.png

(3) To configure WAN ports, click WAN Settings, and select the WAN port that permits access over tunnels for each node.

If multiple WAN interfaces are designated, you can specify the routing policy as follows:

  • Auto: The platform continuously evaluates WAN interface conditions to dynamically choose the optimal path.

  • Active/Standby: Traffic seamlessly fails over to the secondary interface if the primary link becomes unreachable.

By default, WAN Port for Tunnel Access is set to All WAN Ports, and WAN Policy defaults to Auto. Select OK once your settings are finalized.image.png

(4) Once network projects are designated, choose Next and assign the VLAN configuration for each site within the SD-WAN deployment.

Note: Confirm that subnet IP addresses assigned to the SD-WAN group do not overlap with existing network infrastructure devices.

Subnet Creation: Select the plus icon beside the target project, then specify the description, IP distribution mechanism, VLAN tag, and gateway address to deploy a VLAN.

Subnet Conflict Resolution: Overlapping subnets are automatically flagged in red. Adjust settings manually following system prompts or initiate the Smart Adjustment tool to correct address collisions.

image.png

(5) Upon confirming the VLAN parameters, select Create an SD-WAN Group. Once the setup pushes successfully, choose View monitoring dashboard to review operational metrics. Additional information regarding this console is available in Introduction to SD-WAN Monitoring Dashboard.

Custom Networking

In Custom topology, you can manually establish interconnectivity paths between individual SD-WAN edge nodes to suit tailored deployment requirements.

(1) Choose the Custom networking option and proceed by clicking Next.


image.png

(2) Select the projects for customized networking.

image.png

(3) To configure WAN ports, click WAN Settings, and select the WAN port that permits access over tunnels for each node.

If multiple WAN interfaces are designated, you can specify the routing policy as follows:

  • Auto: The platform continuously evaluates WAN interface conditions to dynamically choose the optimal path.

  • Active/Standby: Traffic seamlessly fails over to the secondary interface if the primary link becomes unreachable.

By default, WAN Port for Tunnel Access is set to All WAN Ports, and WAN Policy defaults to Auto. Select OK once your settings are finalized.

image.png

(4) Establish customized link interconnections.

Approach 1: Diagram View

a. Select the Diagram View tab located in the upper right section.

b. Choose a target project, pick the corresponding projects for interconnectivity, and select Confirm.

c. Upon finishing initial adjustments, review the updated topological status. Replicate step b for remaining sites until full deployment is achieved, then click Next.

image.png

Approach 2: List View

a. Select the List tab located in the upper right section.

b. Choose a target project and pick the corresponding projects for interconnectivity.

c. Upon finishing initial adjustments, navigate to the Diagram View tab to review the topological status.

d. Proceed by clicking Next.

image.png

(5) Once network projects are designated, choose Next and assign the VLAN configuration for each site within the SD-WAN deployment.

Note: Confirm that subnet IP addresses assigned to the SD-WAN group do not overlap with existing network infrastructure devices.

Subnet Creation: Select the plus icon beside the target project, then specify the description, IP distribution mechanism, VLAN tag, and gateway address to deploy a VLAN.

Subnet Conflict Resolution: Overlapping subnets are automatically flagged in red. Adjust settings manually following system prompts or initiate the Smart Adjustment tool to correct address collisions.

image.png

(6) Upon confirming the VLAN parameters, select Create an SD-WAN Group. Once the setup pushes successfully, choose View monitoring dashboard to review operational metrics. Additional information regarding this console is available in Introduction to SD-WAN Monitoring Dashboard.



4 Modifying Networking Configuration

Adding a Project

(1) Click Networking to access the Project List page.

(2) Click +Project to add projects to the SD-WAN group.

image.png

(3) Select the projects to be added in the project list and click Next.

image.png

(4) When using Custom topology, establish customized link interconnections. This step is not required for alternative deployment modes.

a. Pick the target project, designate additional sites for cross-site link routing, and select Confirm.

b. Upon finishing initial adjustments, review the updated topological status, then click Next.

image.png

(5) Select the VLANs of the new projects, and click Add.

image.png

(6) The newly added projects are displayed in the Project List.


image.png


Verification

Remote connection to LAN devices offsite should be available afterwards as the network should be expanded to include both sites as one larger network.   


Things to Keep In Mind

Default LAN Conflicts: Local routers default to the 192.168.100.1 subnet. Setting up an SD-WAN to bridge multiple branch offices without changing each site’s default local subnet will result in routing conflicts, rendering site-to-site communication impossible. 

Overlooking Client Capacity: When connecting a branch to a core site via SD-WAN, engineers sometimes deploy lower-end hardware (like the LR100G) that supports a max of 100 concurrent clients, forgetting that cross-site SD-WAN traffic will rapidly exhaust the session table limits. 

Neglecting Micro-Segmentation: Lysora is widely deployed for CCTV and security networks. Failing to separate security cameras, corporate workstations, and guest Wi-Fi through programmatic micro-segmentation allowing lateral threat movement across the SD-WAN tunnel.