Skip to content

Topology Custom Policy

Configure topology custom policies for fine-grained control over route advertisement and path selection in the SD-WAN overlay.

Site targeting (inbound_sites/outbound_sites, and sequences[].match_entries.sites) also accepts network hierarchy groups and regions via the paired inbound_site_groups/outbound_site_groups/match_entries.site_groups keys - each group name expands to every site nested under it, unioned with any sites listed directly. See Example-4 and the version note below.

Diagram

topology_profiles (sdwan.feature_profiles)

Section titled “topology_profiles (sdwan.feature_profiles)”
NameTypeConstraintMandatoryDefault Value
custom_policiesList[custom_policies]No

custom_policies (sdwan.feature_profiles.topology_profiles)

Section titled “custom_policies (sdwan.feature_profiles.topology_profiles)”
NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[^&<>! "]{1,128}$Yes
default_actionChoiceaccept, rejectNoreject
sequencesList[sequences]No
inbound_regionsListStringNo
inbound_sitesListStringNo
inbound_site_groupsListStringNo
levelChoicesites, wan_regionsNosites
outbound_regionsListStringNo
outbound_sitesListStringNo
outbound_site_groupsListStringNo
roleChoiceborder, edgeNo

sequences (sdwan.feature_profiles.topology_profiles.custom_policies)

Section titled “sequences (sdwan.feature_profiles.topology_profiles.custom_policies)”
NameTypeConstraintMandatoryDefault Value
sequence_idIntegermin: 1, max: 6553Yes
sequence_nameStringRegex: ^[^&<>! "]{1,128}$No
action_entriesClass[action_entries]No
base_actionChoiceaccept, rejectNoreject
protocolChoiceipv4, ipv6, bothNoipv4
match_entriesClass[match_entries]No
typeChoiceroute, tlocNoroute

action_entries (sdwan.feature_profiles.topology_profiles.custom_policies.sequences)

Section titled “action_entries (sdwan.feature_profiles.topology_profiles.custom_policies.sequences)”
NameTypeConstraintMandatoryDefault Value
affinityIntegermin: 1, max: 63No
communityStringNo
community_additiveBooleantrue, falseNo
export_to_lan_vpn_namesListString[Regex: ^[^&<>! "]{1,128}$]No
omp_tagIntegermin: 0, max: 4294967295No
preferenceIntegermin: 0, max: 4294967295No
serviceClass[service]No
service_chainClass[service_chain]No
tlocClass[tloc]No
tloc_actionChoicebackup, ecmp, primary, strictNo

match_entries (sdwan.feature_profiles.topology_profiles.custom_policies.sequences)

Section titled “match_entries (sdwan.feature_profiles.topology_profiles.custom_policies.sequences)”
NameTypeConstraintMandatoryDefault Value
carrierChoicedefault, carrier1, carrier2, carrier3, carrier4, carrier5, carrier6, carrier7, carrier8No
color_listStringRegex: ^[^&<>! "]{1,128}$No
community_listStringRegex: ^[^&<>! "]{1,128}$No
domain_idIntegermin: 1, max: 4294967295No
expanded_community_listStringRegex: ^[^&<>! "]{1,128}$No
group_idIntegermin: 0, max: 4294967295No
ipv4_prefix_listStringRegex: ^[^&<>! "]{1,128}$No
ipv6_prefix_listStringRegex: ^[^&<>! "]{1,128}$No
omp_tagIntegermin: 0, max: 4294967295No
originChoiceaggregate, bgp, bgp-external, bgp-internal, connected, eigrp, ospf, ospf-inter-area, ospf-intra-area, ospf-external1, ospf-external2, rip, static, eigrp-summary, eigrp-internal, eigrp-external, lisp, nat-dia, natpool, isis, isis-level1, isis-level2No
originatorIPNo
path_typeChoicehierarchical-path, direct-path, transport-gateway-pathNo
preferenceIntegermin: 0, max: 4294967295No
roleChoiceborder, edgeNo
sitesListStringNo
site_groupsListStringNo
tlocClass[tloc]No
lan_vpn_namesListString[Regex: ^[^&<>! "]{1,128}$]No
wan_regionsListStringNo

service (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)

Section titled “service (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)”
NameTypeConstraintMandatoryDefault Value
tloc_colorChoice3g, biz-internet, blue, bronze, custom1, custom2, custom3, default, gold, green, lte, metro-ethernet, mpls, private1, private2, private3, private4, private5, private6, public-internet, red, silverNo
tloc_encapsulationChoiceipsec, greNo
tloc_ipIPNo
tloc_listStringRegex: ^[^&<>! "]{1,128}$No
typeChoiceFW, IDS, IDP, netsvc1, netsvc2, netsvc3, netsvc4No
vpnIntegermin: 0, max: 65530No

service_chain (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)

Section titled “service_chain (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)”
NameTypeConstraintMandatoryDefault Value
nameChoiceSC1, SC2, SC4, SC5, SC6, SC7, SC8, SC9, SC10, SC11, SC12, SC13, SC14, SC15, SC16No
tloc_colorChoice3g, biz-internet, blue, bronze, custom1, custom2, custom3, default, gold, green, lte, metro-ethernet, mpls, private1, private2, private3, private4, private5, private6, public-internet, red, silverNo
tloc_encapsulationChoiceipsec, greNo
tloc_ipIPNo
tloc_listStringRegex: ^[^&<>! "]{1,128}$No
vpnIntegermin: 0, max: 65530No

tloc (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)

Section titled “tloc (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.action_entries)”
NameTypeConstraintMandatoryDefault Value
colorChoice3g, biz-internet, blue, bronze, custom1, custom2, custom3, default, gold, green, lte, metro-ethernet, mpls, private1, private2, private3, private4, private5, private6, public-internet, red, silverNo
encapsulationChoiceipsec, greNo
ipIPNo
listStringRegex: ^[^&<>! "]{1,128}$No

tloc (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.match_entries)

Section titled “tloc (sdwan.feature_profiles.topology_profiles.custom_policies.sequences.match_entries)”
NameTypeConstraintMandatoryDefault Value
colorChoice3g, biz-internet, blue, bronze, custom1, custom2, custom3, default, gold, green, lte, metro-ethernet, mpls, private1, private2, private3, private4, private5, private6, public-internet, red, silverNo
encapsulationChoiceipsec, greNo
ipIPNo
listStringRegex: ^[^&<>! "]{1,128}$No

Example-1: This example demonstrates a custom control policy that accepts routes originating from connected networks with a specific OMP tag, and sets a preference value. The policy is applied site-level inbound from SITE_100 and outbound to SITE_200.

sdwan:
feature_profiles:
topology_profiles:
- name: topology_profile_1
description: custom control topology
custom_policies:
- name: custom_control_policy_1
default_action: reject
level: sites
inbound_sites:
- SITE_100
outbound_sites:
- SITE_200
sequences:
- sequence_id: 1
sequence_name: accept_connected
base_action: accept
type: route
protocol: ipv4
match_entries:
origin: connected
omp_tag: 100
action_entries:
preference: 200
omp_tag: 150

Example-2: This example demonstrates a custom control policy targeting regions instead of sites, with service chaining and TLOC actions.

sdwan:
feature_profiles:
topology_profiles:
- name: topology_profile_2
description: regional custom control
custom_policies:
- name: regional_policy
default_action: accept
level: wan_regions
role: border
inbound_regions:
- region_west
outbound_regions:
- region_east
sequences:
- sequence_id: 1
sequence_name: service_chain_rule
base_action: accept
type: route
protocol: ipv4
match_entries:
tloc:
ip: 1.1.1.1
color: mpls
encapsulation: ipsec
color_list: my_color_list
sites:
- SITE_100
action_entries:
service:
type: FW
vpn: 100
tloc_action: strict

Note: For the above example, my_color_list must be defined under sdwan.feature_profiles.policy_object_profile.color_lists.

Example-3: This example demonstrates a custom control policy with community matching, LAN VPN export, and service chain configuration.

sdwan:
feature_profiles:
topology_profiles:
- name: topology_profile_3
description: advanced custom control
custom_policies:
- name: advanced_policy
default_action: reject
level: sites
sequences:
- sequence_id: 1
sequence_name: community_match
base_action: accept
type: route
protocol: ipv4
match_entries:
community_list: my_community_list
lan_vpn_names:
- Corporate
- Guest
action_entries:
export_to_lan_vpn_names:
- Corporate
community: 100:200
community_additive: true
service_chain:
name: SC1
vpn: 100
tloc_ip: 10.0.0.1
tloc_color: mpls
tloc_encapsulation: ipsec

Note: For the above example,

  • my_community_list must be defined under sdwan.feature_profiles.policy_object_profile.standard_community_lists.
  • Corporate and Guest must be defined as LAN VPN names under a service profile (sdwan.feature_profiles.service_profiles[].lan_vpns[].name) that is associated with a configuration group.
  • If a VPN referenced in lan_vpn_names or export_to_lan_vpn_names needs renumbering, create a new LAN VPN feature with the desired VPN ID rather than modifying the existing one in-place.

Example-4: This example demonstrates targeting by network hierarchy group instead of listing individual sites. EMEA and AMER are groups declared under sdwan.network_hierarchy; each expands to every site nested under it.

sdwan:
manager_version: "20.18.4"
network_hierarchy:
groups:
- name: EMEA
sites:
- name: SITE_100
site_id: 100
- name: SITE_200
site_id: 200
- name: AMER
sites:
- name: SITE_300
site_id: 300
feature_profiles:
topology_profiles:
- name: topology_profile_4
description: group-targeted custom control
custom_policies:
- name: custom_control_by_group
default_action: reject
level: sites
inbound_site_groups:
- EMEA
outbound_site_groups:
- AMER
sequences:
- sequence_id: 1
sequence_name: accept_all
base_action: accept
type: route
protocol: ipv4
match_entries:
site_groups:
- EMEA
action_entries:
preference: 200

Note: site targeting and Manager version

  • A group name (inbound_site_groups, outbound_site_groups, sequences[].match_entries.site_groups) must be declared as a group or region under sdwan.network_hierarchy, and a plain site name must be declared as a site there too - either directly, or nested under any group/region. An undeclared name fails validation, and (if it slips past validation, e.g. a var.model caller) fails the Terraform plan by name.
  • When sdwan.network_hierarchy is declared, every resolved site is sent as a network hierarchy UUID on Manager 20.18.1 and later - this is also what makes a sequences[].match_entries targeting a site actually render in the 20.18 Manager GUI; a site name is accepted by the API there but shows blank. An unset manager_version is treated as 20.18.1+.
  • Set manager_version below 20.18 (e.g. "20.15") to send plain site names on the wire instead, for Managers that predate hierarchy UUIDs. manager_version is required whenever sdwan.network_hierarchy is declared - validation rejects the combination of a declared hierarchy and an unset version.