With the release of NetCloud OS 7.26.40, NetCloud SASE supports integration with on-premises data centers and network sites using legacy Ericsson Cradlepoint or third-party routers. A maximum of two third-party sites with up to four tunnels across the sites, may be added to an existing SASE Secure Connect network.
Following is an example single third-party site network diagram:
Complete the following steps to configure a third-party site:
Log into NetCloud Manager.
Select in the left-side navigation panel.
Select the Secure Connect network's tile.
Select in the top-right corner of the page.
Select the Sites tab.
Select the Third-Party tab.
Select .
Enter a descriptive name for the site.
Optional: Enter a descriptive name for a tag to apply to this new site and then select . An existing tag may be applied, if needed.
Note
All tag names default to lowercase and cannot contain spaces or special characters.
Tagging allows the grouping of sites or resources with a common purpose, for example ATMs that all have the same access policy. Once tagged, a single access policy can be created that impacts all the tagged site groups and routers within those groups. Minimum software version required for tags is 7.24.80.
Optional: Select the Advanced DNS Options box to configure a domain name system (DNS) server, instead of using the automatically generated fully qualified domain name (FQDN) for the new site.
Optional: Enter the Primary DNS server IP address.
If a DNS server exists on the new site’s local area network that resolves DNS requests from other network sites, enter the IP address for the site's DNS server.
Note
If a primary or secondary DNS server is not specified, the Secure Connect network defaults to the DNS server of its host environment, if available. Otherwise, the NCX Service Gateway uses dns.google.com to resolve DNS requests through the UDP port 53 to IP address 8.8.8.8. The network's primary and secondary DNS settings configure the Secure Connect network-level DNS, which resolves DNS requests for anything that does not have a fully qualified domain name (FQDN) explicitly defined.
Optional: Enter the Secondary DNS server IP address if a primary DNS server was added.
Note
Secondary DNS is not enabled if Use Router as DNS is selected.
Select Add in the Tunnel section to configure a tunnel for the new site.
Enter a descriptive name for the tunnel.
Optional: Enter a description for the new tunnel.
Enter the local tunnel IP address.
This is the IP address for the third-party end of the tunnel that the generated VPN configuration will specify.
Enter the remote tunnel IP address for the NCX Service Gateway end of the tunnel.
Note
The local tunnel IP address and the remote tunnel IP address must be in the same subnet. They must also be unique addresses that do not conflict with any other subnet resources or NCX Service Gateway local IP addresses for wan0, mgmt0, or lan0.
Select to save the new tunnel.
Select .
Optional: Select to view the configuration of the new tunnel on the third-party site.
Note
Third-party sites require configuration for Border Gateway Protocol. See Configure the Border Gateway Protocol for detailed steps.