With the release of NetCloud OS 7.25.100, a Secure Connect site may be configured for microtunnel when selecting a site router that supports microtunnel.
Complete the following steps to add a site and a resource:
Log into NetCloud Manager.
Select in the left-side navigation panel.
Select the Secure Connect network's tile.
Select in the top-right corner of the page.
Select the Sites tab and then .
Enter a descriptive name for the site.
Optional: Enter a descriptive name for a tag to apply to this new site and then select . An existing tag may be applied, if needed.
Note
All tag names default to lowercase and cannot contain spaces or special characters.
Tagging allows the grouping of sites or resources with a common purpose, for example ATMs that all have the same access policy. Once tagged, a single access policy can be created that impacts all the tagged site groups and routers within those groups. Minimum software version required for tags is 7.24.80.
Check the Microtunnel box, if the Secure Connect network is configured with microtunnel.
This enables microtunnel per site. If it is not selected, the site works with IPsec.
Select .
Select the router to add to the site.
Note
If the Secure Connect network is configured for FIPS, only available FIPS routers are shown as options.
A valid Hybrid Mesh Firewall license is required for any router being added to a Secure Connect network with Hybrid Mesh Firewall.
Select on the Add Router page.
Optional: Select the Advanced DNS Options box to configure a domain name system (DNS) server or use the router as the DNS, instead of using the automatically generated fully qualified domain name (FQDN) for the new site.
Optional: Enter the Primary DNS server IP address.
If a DNS server exists on the new site’s local area network that resolves DNS requests from other network sites, enter the IP address for the site's DNS server.
If there is not a site DNS server, the Ericsson Cradlepoint router can be configured to serve as the DNS server for that site by selecting Router as DNS. The IP address of the DNS server (192.0.2.127) is predetermined for Secure Connect networks when first selecting Router as DNS, when toggling the setting, or if making any other changes on the DNS/Router page after the site was created.
Note
If a primary or secondary DNS server is not specified, the Secure Connect network defaults to the DNS server of its host environment, if available. Otherwise, the NCX Service Gateway uses dns.google.com to resolve DNS requests through the UDP port 53 to IP address 8.8.8.8. The network's primary and secondary DNS settings configure the Secure Connect network-level DNS, which resolves DNS requests for anything that does not have a fully qualified domain name (FQDN) explicitly defined.
Optional: Enter the Secondary DNS server IP address if a primary DNS server was added.
Note
Secondary DNS is not enabled if Use Router as DNS is selected.
Optional: Enter a Domain Suffix.
Select .
Select .
Optional: Add a resource to the site if the network uses name-based routing or an IP subnet.
Note
Ericsson Enterprise Wireless Solutions recommends creating application-based resources versus TCP or UDP generic resources to support application layer policies and visibility.
Select on the Resources page.
Enter a descriptive name for the resource.
Select the Resource Type from the drop-down menu.
Note
Options include FQDN, Wildcard FQDN, and IP Subnet. If using IP Subnet, the field uses CIDR notation for the subnet, and for a single IP address, the subnet is /32 (for example, 192.168.1.2/32). Typical subnet requirements apply.
If using IP Subnet and a single IP address, an FQDN is automatically generated for the new resource. See AutoFQDN Overview for more information.
If FQDN or Wildcard FQDN was selected as the Resource Type, enter the domain's FQDN in the Domain field.
If IP Subnet was selected as the Resource Type, enter the IP address in the IP field.
Note
When configuring a Secure Connect network internal resource subnet, ensure that the subnet does not overlap the NCX Service Gateway or WAN interface IP address.
An IP address of 0.0.0.0/0 is not recommended since it treats all traffic flows as a part of this 0.0.0.0/0 protected subnet and returns only prime NAT IP addresses to the client.
Select one of the Protocols options to allow only traffic of that specified protocol to the resource.
Optional: Enter a descriptive name for a tag to apply to the new resource and then select . An existing tag may be applied, if needed.
Note
All tag names default to lowercase and cannot contain spaces or special characters.
The route-mgmt tag is created by default for automatically generated resources.
Tagging allows the quick collection of a set of network resources to be represented by a single logical tag. Once tagged, a single access policy can be created that impacts all the tagged resources, so they have a uniform and simpler approach.
Select on the Add Resource panel.
The new resource appears in the table on the Resources page, along with the following automatically generated resources:
<Site Name>-console – Provides an SSH interface for access to the Secure Connect site router's Console.
<Site Name>-managment-ui – Provides an HTTPS interface for access to Remote Connect for the Secure Connect site router.
Note
The automatically generated resources are accessed only by auto-FQDN and overlay IP addresses through configured access policies and are not applicable for sites created under a site group or a single arm Virtual Edge.
Select .
Completing this task associates the site and router within the NetCloud Exchange Service Gateway and creates the Secure Connect tunnel between the two.
Note
Secure Connect tunnels follow the priority of the interfaces shown in Connection Manager.
The site appears in the table on the Sites page.
Note
Warning appears in the Status column if a configured site does not have an associated Ericsson Cradlepoint router. For example, the router was unregistered after the site was created. The status does not apply to the site's tunnels.
All Ericsson Cradlepoint routers are automatically configured with Primary LAN and Guest LAN local IP networks. Adding an Ericsson Cradlepoint router to a network site automatically creates the DNS LAN local IP network, which ensures that DNS traffic continues to flow if a LAN is deleted or added. The source IP address of DNS queries is automatically set to the DNS LAN IP address (192.0.2.127).
Repeat this procedure for any additional sites.
Note
When using SD-WAN, it is required that site routers are left at the default settings and that traffic steering is only configured through SD-WAN policies due to conflicts between NetCloud OS and NetCloud Exchange Service Gateway configuration options. See Configuration Conflicts Between NetCloud OS and NetCloud Exchange for more information.