Configure Third-Party Sites - Configuring-NetCloud-SASE/Configure-Third-Party-Sites

NetCloud SASE Configuration Guide

ft:locale
en-US
ft:sourceName
Paligo_Prod
Document Type
Configuration Guide

With the release of NetCloud OS 7.26.40, NetCloud SASE supports integration with on-premises data centers and network sites using legacy Ericsson Cradlepoint or third-party routers. A maximum of two third-party sites with up to four tunnels across the sites, may be added to an existing SASE Secure Connect network.

Following is an example single third-party site network diagram:

Example network diagram for a single third-party site.

Complete the following steps to configure a third-party site:

  1. Log into NetCloud Manager.

  2. Select Networks in the left-side navigation panel.

  3. Select the Secure Connect network's tile.

  4. Select Network Configuration in the top-right corner of the page.

    Network Configuration button on the NetCloud Manager Networks page.
  5. Select the Sites tab.

  6. Select the Third-Party tab.

  7. Select Add.

  8. Enter a descriptive name for the site.

  9. Optional: Enter a descriptive name for a tag to apply to this new site and then select Add. An existing tag may be applied, if needed.

    Note

    All tag names default to lowercase and cannot contain spaces or special characters.

    Tagging allows the grouping of sites or resources with a common purpose, for example ATMs that all have the same access policy. Once tagged, a single access policy can be created that impacts all the tagged site groups and routers within those groups. Minimum software version required for tags is 7.24.80.

  10. Optional: Select the Advanced DNS Options box to configure a domain name system (DNS) server, instead of using the automatically generated fully qualified domain name (FQDN) for the new site.

    1. Optional: Enter the Primary DNS server IP address.

      If a DNS server exists on the new site’s local area network that resolves DNS requests from other network sites, enter the IP address for the site's DNS server.

      Note

      If a primary or secondary DNS server is not specified, the Secure Connect network defaults to the DNS server of its host environment, if available. Otherwise, the NCX Service Gateway uses dns.google.com to resolve DNS requests through the UDP port 53 to IP address 8.8.8.8. The network's primary and secondary DNS settings configure the Secure Connect network-level DNS, which resolves DNS requests for anything that does not have a fully qualified domain name (FQDN) explicitly defined.

    2. Optional: Enter the Secondary DNS server IP address if a primary DNS server was added.

      Note

      Secondary DNS is not enabled if Use Router as DNS is selected.

  11. Select Add in the Tunnel section to configure a tunnel for the new site.

  12. Enter a descriptive name for the tunnel.

  13. Optional: Enter a description for the new tunnel.

  14. Enter the local tunnel IP address.

    This is the IP address for the third-party end of the tunnel that the generated VPN configuration will specify.

  15. Enter the remote tunnel IP address for the NCX Service Gateway end of the tunnel.

    Note

    The local tunnel IP address and the remote tunnel IP address must be in the same subnet. They must also be unique addresses that do not conflict with any other subnet resources or NCX Service Gateway local IP addresses for wan0, mgmt0, or lan0.

  16. Select Add to save the new tunnel.

  17. Select Create.

  18. Optional: Select Preview Configuration to view the configuration of the new tunnel on the third-party site.

Note

Third-party sites require configuration for Border Gateway Protocol. See Configure the Border Gateway Protocol for detailed steps.