A Secure Connect site may be configured with two routers to enable site redundancy. It is the network administrator's responsibility to ensure site resources are accessible from both routers.
Requirements for site redundancy:
Minimum software version 7.25.20 or later
Virtual Router Redundancy Protocol (VRRP) configured on the routers. See Configuring Virtual Router Redundancy Protocol for instructions.
Note
VRRP is not supported when using the Ericsson Cradlepoint S400 and S700 routers or the NetCloud Virtual Edge.
WAN Verify configured on the routers. See Configuring WAN Verify for instructions.
With the release of NetCloud OS 7.25.100, a Secure Connect site may be configured for microtunnel when selecting a site router that supports microtunnel.
Complete the following steps to add a site with two routers and a resource:
Log into NetCloud Manager.
Select in the left-side navigation panel.
Select the Secure Connect network's tile.
Select in the top-right corner of the page.
Select the Sites tab and then .
Enter a descriptive name for the site.
Optional: Enter a descriptive name for a tag to apply to this new site and then select . An existing tag may be applied, if needed.
Note
All tag names default to lowercase and cannot contain spaces or special characters.
Tagging allows the grouping of sites or resources with a common purpose, for example ATMs that all have the same access policy. Once tagged, a single access policy can be created that impacts all the tagged site groups and routers within those groups. Minimum software version required for tags is 7.24.80.
Note
Tags apply to both routers when two routers are configured for redundancy.
Check the Enable Site Redundancy box if adding two routers for site redundancy.
Check the Microtunnel box, if the Secure Connect network is configured with microtunnel.
This enables microtunnel per site. If it is not selected, the site works with IPsec.
Select .
Select the router with the higher VRRP priority as the primary router for the Secure Connect site.
Note
If the Secure Connect network is configured for FIPS, only available FIPS routers are shown as options.
A valid Hybrid Mesh Firewall license is required for any router being added to a Secure Connect network with Hybrid Mesh Firewall.
Select on the Add Router page.
Select again and select the router with the lower VRRP priority as the standby router for redundancy.
Select the VRRP LAN Name option on which the VRRP is configured.
If a Secure Connect site router is running VRRP on multiple LAN networks, all the LAN networks must share a single physical interface configured for VLAN trunking.
Note
The VRRP LAN Name defaults to the first LAN in the list and should be changed, if needed.
See Configuring Virtual Router Redundancy Protocol for detailed steps to configure VRRP.
Optional: Select the Advanced DNS Options box to configure a domain name system (DNS) server or use the router as the DNS, instead of using the automatically generated fully qualified domain name (FQDN) for the new site.
Optional: Enter the Primary DNS server IP address.
If a DNS server exists on the new site’s local area network that resolves DNS requests from other network sites, enter the IP address for the site's DNS server.
If there is not a site DNS server, the Ericsson Cradlepoint router can be configured to serve as the DNS server for that site by selecting Router as DNS. The IP address of the DNS server (192.0.2.127) is predetermined for Secure Connect networks when first selecting Router as DNS, when toggling the setting, or if making any other changes on the DNS/Router page after the site was created.
Note
If a primary or secondary DNS server is not specified, the Secure Connect network defaults to the DNS server of its host environment, if available. Otherwise, the NCX Service Gateway uses dns.google.com to resolve DNS requests through the UDP port 53 to IP address 8.8.8.8. The network's primary and secondary DNS settings configure the Secure Connect network-level DNS, which resolves DNS requests for anything that does not have a fully qualified domain name (FQDN) explicitly defined.
Optional: Enter the Secondary DNS server IP address if a primary DNS server was added.
Note
Secondary DNS is auto populated if Use Router as DNS is selected on a redundant site.
Optional: Enter a Domain Suffix.
Select .
The Primary or Standby role for each router appears in the Router table. If needed, select the Exchange button to switch the roles.
Select .
Optional: Add a resource to the site if the network uses name-based routing or an IP subnet.
Note
Ericsson Enterprise Wireless Solutions recommends creating application-based resources versus TCP or UDP generic resources to support application layer policies and visibility.
Select on the Resources page.
Enter a descriptive name for the resource.
Select the Resource Type from the drop-down menu.
Note
Options include FQDN, Wildcard FQDN, and IP Subnet. If using IP Subnet, the field uses CIDR notation for the subnet, and for a single IP address, the subnet is /32 (for example, 192.168.1.2/32). Typical subnet requirements apply.
If using IP Subnet and a single IP address, an FQDN is automatically generated for the new resource. See AutoFQDN Overview for more information.
If FQDN or Wildcard FQDN was selected as the Resource Type, enter the domain's FQDN in the Domain field.
If IP Subnet was selected as the Resource Type, enter the IP address in the IP field.
Note
When configuring a Secure Connect network internal resource subnet, ensure that the subnet does not overlap the NCX Service Gateway or WAN interface IP address.
An IP address of 0.0.0.0/0 is not recommended since it treats all traffic flows as a part of this 0.0.0.0/0 protected subnet and returns only prime NAT IP addresses to the client.
Select one of the Protocols options to allow only traffic of that specified protocol to the resource.
Optional: Enter a descriptive name for a tag to apply to the new resource and then select . An existing tag may be applied, if needed.
Note
All tag names default to lowercase and cannot contain spaces or special characters.
The route-mgmt tag is created by default for automatically generated resources.
Tagging allows the quick collection of a set of network resources to be represented by a single logical tag. Once tagged, a single access policy can be created that impacts all the tagged resources, so they have a uniform and simpler approach.
Select on the Add Resource panel.
The new resource appears in the table on the Resources page, along with the following automatically generated resources:
<Site Name>-console – Provides an SSH interface for access to the Secure Connect site router's Console.
<Site Name>-managment-ui – Provides an HTTPS interface for access to Remote Connect for the Secure Connect site router.
Note
The automatically generated resources are accessed only by auto-FQDN and overlay IP addresses through configured access policies and are not applicable for sites created under a site group or a single arm Virtual Edge.
Select .
Completing this task associates the site and routers within the NetCloud Exchange Service Gateway and creates the Secure Connect tunnel between them.
The sites appear in the table on the Sites page.
Note
Warning appears in the Status column if a configured site does not have an associated Ericsson Cradlepoint router. For example, the router was unregistered after the site was created. The status does not apply to the site's tunnels.
All Ericsson Cradlepoint routers are automatically configured with Primary LAN and Guest LAN local IP networks. Adding an Ericsson Cradlepoint router to a network site automatically creates the DNS LAN local IP network, which ensures that DNS traffic continues to flow if a LAN is deleted or added. The source IP address of DNS queries is set to the DNS LAN IP address.
Note
Secure Connect tunnels follow the priority of the interfaces shown in Connection Manager.
Repeat this procedure for any additional sites.
Note
When using SD-WAN, it is required that site routers are left at the default settings and that traffic steering is only configured through SD-WAN policies due to conflicts between NetCloud OS and NetCloud Exchange Service Gateway configuration options. See Configuration Conflicts Between NetCloud OS and NetCloud Exchange for more information.