1) Create 2 Paired tvi interfaces as shown below.




2) Add it as a part of the Org under Traffic Identification in Limits.


3) Add the interfaces as part of the Zones shown below:



4) Please make sure the LAN-side tvi interface is part of the "Interfaces/Networks" under Virtual Routers. This is assumping  that Static/Directly connected routes are re-distributed to the SDWAN.




5) Below os the security access Policy to allow Traffic from the remove client over SDWAN to the host IP IPv6 destination.

We would ssh to the tvi-0/2002.0 Interface IP which is part of the Global-VR.






6) Make sure to add a static return route static on the Global-Routing for the incoming ssh traffic to be pointing the LAN tvi IP.



If there is any further concerns or queires, please feel free write us back on support@versa-networks.com and we would be able to help you.