Guide: MultiPath Konnect (MPK) Tunnel Support

Overview

MultiPath Konnect (MPK) Tunnel Support enables organizations to establish secure Hub-based tunnels between Edge devices and a centralized Konnect Hub. The feature provides high-performance and resilient WAN connectivity by allowing traffic to be routed through the Hub while leveraging multiple WAN interfaces.

MPK Tunnel Support extends the existing Hub functionality by introducing:

  • Configurable MultiPath Konnect operating modes

  • Advanced transport optimization features

  • Intelligent WAN utilization

  • Enhanced dashboard monitoring

  • Hub service management

Depending on the deployment requirements, administrators can configure the Hub to operate in PEP or Tunnel mode and apply advanced transport settings such as TCP Transport, Forward Error Correction (FEC), Packet Balancing, and Packet Duplication.

How MPK Tunnel Support Works

MPK Tunnel Support establishes a secure tunnel between an Edge device and a Konnect Hub server.

image-20260804-164256.png
Flowchart

Unlike traditional WAN routing, traffic is forwarded through the Hub, allowing centralized internet breakout, improved resiliency, and WAN optimization.

Deployment Workflow

A typical MPK deployment consists of the following steps:

  1. Configure the Hub service.

  2. Select the required MultiPath Konnect mode.

  3. Configure Hub listener settings.

  4. Configure Edge client settings.

  5. Configure WAN priorities.

  6. Configure advanced MPK transport options.

  7. Verify Hub status from the Dashboard.

MultiPath Konnect Operating Modes

MPK supports two operating modes.

PEP (Performance Enhancing Proxy)

PEP improves performance over high-latency WAN links by using TCP acceleration and compression.

Recommended for:

  • VSAT

  • Satellite links

  • High-latency networks

Approximate throughput:

  • 300 Mbps

Tunnel

Tunnel mode enables the complete MultiPath Konnect feature set.

Additional capabilities include:

  • TCP Transport

  • Forward Error Correction (FEC)

  • Packet Balancing

  • Packet Duplication

Tunnel mode supports multi-Gbps throughput depending on available hardware resources.

image-20260804-164556.png
Feature Compatibility

Configuration Workflow

The MPK feature is configured across multiple pages.

Configuration

Page

Hub configuration

Hub Settings

Edge configuration

Client Settings

WAN transport optimization

WAN Profiles

Monitoring

Dashboard

Hub Settings

Overview

The Hub Settings page is used to configure the Konnect Hub server.

Administrators can:

  • Enable or disable the Hub service

  • Select the MPK operating mode

  • Configure Hub listener settings

  • Configure WAN interfaces

  • Configure optional authentication

  • View NAT mappings

Steps

  • Navigate to: HubHub Settings.

  • Enable Konnect Hub Services - Enable the Konnective Hub Services option to activate the Hub server. When disabled, the device does not accept MPK client connections.

2 (26)-20260716-082954 (1) (1)-20260804-174758.png
Hub Settings
  • Select the MPK Mode - The MultiPath Konnect Mode determines how the Hub processes traffic. Available modes:

    • PEP

    • Tunnel

  • Selecting the Information icon displays a description of both modes.

  • Change the MPK Mode - Changing the MPK mode requires a Hub reboot.

    • When you save the new mode:

      • A confirmation dialog is displayed.

      • Selecting Save & Reboot saves the configuration.

      • The Hub restarts automatically.

      • Existing administrator sessions end.

      • You are redirected to the login page after reboot.

Note: Existing Hub traffic is interrupted while the Hub restarts.

  • Configure Hub Service Settings:

    • Select WAN Interface(s): Select one or more WAN interfaces that accept MPK client connections.

    • Listen Port: Specify the TCP/UDP port used by the Hub server.

    • Password: Optionally configure a password for client authentication.

  • NAT Table - Displays outbound NAT rules. Information includes:

    • Edge Device

    • WAN Interface

    • Access Network

    • NAT Type

    • NAT Destination

  • Inbound NAT / Route Table - Displays inbound DNAT mappings configured for Hub clients.

Client Settings

Overview

The Client Settings page configures the Edge device that connects to a Hub.

Like Hub Settings, Client Settings provides the MultiPath Konnect Mode selector.

Unlike the Hub, changing the client mode:

  • interrupts existing traffic sessions,

  • applies immediately,

  • does not require a Hub reboot.

image-20260716-074455 (1)-20260804-174908.png
Client Settings

WAN Profiles – MPK Advanced Settings

Overview

When a WAN Profile operates in Tunnel mode, the Advanced Settings dialog includes a MultiPath Konnect tab. This tab provides advanced transport configuration options for each WAN priority.

To access the settings:

  1. Navigate to SD-WAN > WAN Profiles.

  2. Select a WAN profile configured for Tunnel mode.

  3. Click the gear icon for the required WAN priority.

  4. Open the MultiPath Konnect tab.

The dialog also contains the existing Link Bonding and Internet Priority tabs.

image-20260717-121010-20260804-175049.png
WAN Profiles
image-20260716-103020 (1)-20260804-175151.png
MultiPath Konnect

TCP Transport

  • Routes MPK tunnel traffic over TCP instead of UDP.

  • Use TCP Transport when UDP traffic is blocked or restricted.

Limitations

TCP Transport cannot be enabled if any of the following features are already selected:

  • Forward Error Correction (FEC)

  • Packet Balancing

  • Packet Duplication

Selecting TCP Transport automatically disables these features.

Forward Error Correction (FEC)

FEC improves communication across unreliable WAN links by transmitting redundant packets, allowing lost packets to be reconstructed without retransmission.

Available levels:

  • Auto

  • High

  • Medium

  • Low

When enabled, the selected FEC level is displayed as a badge beside the WAN priority.

Packet Balancing

Packet Balancing distributes traffic across multiple WAN interfaces assigned to the same priority.

Benefits include:

  • Higher aggregate bandwidth

  • Improved throughput

  • Better utilization of available WAN links

Requirement: The selected WAN priority must contain more than one WAN interface.

Packet Duplication

Packet Duplication sends identical packets over every WAN interface assigned to the same priority.

Benefits include:

  • Increased reliability

  • Reduced packet loss

  • Improved resiliency during WAN degradation

Requirement: The selected WAN priority must contain more than one WAN interface.

Dashboard Enhancements

Hub Status

When the device is licensed as a Hub, the Dashboard displays a Hub status indicator.

Status

Indicator

Hub Services Enabled

Green

Hub Services Disabled

Red

image-20260722-074741-20260804-175301.png
Dashboard

Hub Status Tooltip

Hovering over the Hub indicator displays:

  • Selected MultiPath Konnect Mode

  • Installed License Type

Hub Status Navigation

Selecting the Hub status opens different pages depending on the current Hub state.

Hub Status

Opens

Green

Konnect Hub Service Status page

Red

Hub Settings page

Konnect Hub Service Status

When Hub Services are enabled, the Konnect Hub Service Status page provides centralized monitoring of Hub activity.

Summary Information

The page displays:

  • Hub Status

  • Current MPK Mode

  • Number of Connected Sites

  • Number of Active Connections

Aggregate Statistics (Last 24 Hours)

The page also displays:

  • Total Usage across all connected clients

  • Average Rate (Mbps)

Dashboard Behavior for Edge (Non-Hub) Licenses

For devices using an Edge license, the Dashboard still displays the Hub status indicator.

Hovering over the indicator displays:

  • Selected MPK Mode

  • Selected Hub Alias

  • Hub IP Address and Port

  • Installed License Type

Selecting the Hub indicator redirects administrators to the Client Settings page, where the client's MPK configuration can be viewed or modified.

Best Practices

  • Use PEP mode for VSAT or other high-latency deployments where TCP acceleration and compression improve performance.

  • Use Tunnel mode when advanced MPK transport capabilities such as TCP Transport, FEC, Packet Balancing, or Packet Duplication are required.

  • Enable Fall-Through Mode if uninterrupted connectivity is preferred when the MPK tunnel becomes unavailable.

  • Configure Packet Balancing or Packet Duplication only when multiple WAN interfaces are assigned to the same WAN priority.

  • Configure FEC for WAN links that experience intermittent packet loss.

 

For detailed information about each configuration and monitoring page, refer to the following topics::