Configure a NetCloud SASE Secure Connect Network - Configuring-NetCloud-SASE/Configure-a-NetCloud-SASE-Secure-Connect-Network

NetCloud SASE Configuration Guide

ft:locale
en-US
ft:sourceName
Paligo_Prod
Document Type
Configuration Guide

Secure Connect may be used with NetCloud Exchange or NetCloud SASE. The following procedure applies only to NetCloud SASE. See Configuring a NetCloud Exchange Secure Connect Network for instructions to configure a network for NetCloud Exchange.

Complete the following steps to configure a Secure Connect network:

  1. Log into NetCloud Manager.

  2. Select Networks in the left-side navigation panel.

  3. Select Add.

    NetCloud Manager Networks screen highlighting the Add button.
  4. Optional: Select Current Account to open the Select an Account panel and then select a subaccount in which to configure the Secure Connect network, if needed.

  5. Select Cradlepoint-Hosted (SASE) from the Hosting Mode drop-down menu.

    NetCloud Manager Network page highlighting the Hosting Mode selection.

    Note

    NetCloud Manager supports different Secure Connect network types within a single account. The Cradlepoint-Hosted (Legacy) option is active only for particular accounts.

  6. Enter a descriptive name for the network.

  7. Input the Primary DNS server IP address.

    The network's primary and secondary domain name system (DNS) settings configure the network-level DNS, which resolves DNS requests for named resources. The DNS server must be reachable from the NetCloud SASE point of presence (PoP).

    Note

    With NetCloud OS 7.25.100, private DNS server IP addresses may be entered in the primary and secondary fields, if the DNS server is configured as a subnet resource for a Secure Connect site.

  8. Optional: Input the Secondary DNS server IP address.

  9. Optional: Check the Enable Fast Link Monitoring box to initiate sending Secure Connect network-specific metering packets every 300 msec that include a new time-to-live timer and unique identifier on a specific User Datagram Protocol (UDP) port from the Ericsson Cradlepoint router to the service gateway. If the timer expires and a traffic steering rule is configured for failover, traffic is switched to a better WAN interface. This functionality uses approximately 66 MB per day.

    Note

    Fast Link Monitoring is supported for bonded interfaces with minimum software version 7.24.60.

    Loss measurement is supported only for Transmission Control Protocol (TCP) traffic flows and applies to individual WAN interfaces. This feature only measures loss and does not measure other parameters such as latency or signal strength.

  10. Optional: Select Advanced DNS Options to override the default 8.8.8.8 DNS setting with static entries for the network, if needed in a network configured for split routing.

    1. Enter the Split DNS Server 1 IP address.

    2. Enter the Split DNS Server 2 IP address.

  11. Select the region (PoP) that is closest to the majority of network users.

    NetCloud Manager Configure Network page highlighting the Region drop-down menu.

    Note

    Once a region is configured for the network, it cannot be changed since doing so requires deleting the NetCloud Exchange Service Gateway and creating a network in the new region.

    See NetCloud SASE Points of Presence and Egress IP Addresses for currently supported regions.NetCloud SASE Points of Presence and Egress IP Addresses

    Note

    The displayed regions are dependent upon the region in which the NetCloud Manager account resides.

  12. Optional: Select the Cipher Profile level from the drop-down menu to increase the complexity of the encryption used for communication.

    • Level 1 – AES 128, SHA2 256, Group 14 (ECP 256)

    • Level 2 – AES 128, SHA2 256, Group 19 (ECP 256)

    • Level 3 – AES 256, SHA2 384, Group 20 (ECP 256)

  13. Select Next.

  14. Select Full Tunnel or Split Routing.

    1. If Full Tunnel is selected, check Update DNS on Tunnel Failure so the router associated with the network site can monitor connectivity to the service gateway. If a connection failure is detected, a 30-second timer starts. If the timer meets its threshold, the router updates its local DNS server to use its local DNS settings for internet-bound traffic.

      Configure Network Routing page highlighting the Update DNS on Tunnel Failure option.

      Note

      Minimum software version required for DNS on Tunnel Failure is 7.23.60.

    2. If Split Routing is selected, add the routes:

      1. Select Add.

      2. Hover over the row and select the edit pencil (Edit pencil icon.) icon.

        Configure Network Tunnel Mode section highlighting the edit (pencil) icon.
      3. Enter a destination IP address/network in CIDR format (for example, 192.168.0.0/16) and then press Enter.

        Note

        These routes go toward the NCX Service Gateway. Anything not specified in this table is directed out to the internet.

      4. Repeat as needed to add other routes.

  15. Optional: Select an unused overlay range from the Overlay Network Range drop-down menu and select Save.

    • Overlay Range – The overlay IP address range from which the various IP addresses are drawn.

      NetCloud Manager Routing page showing the Overlay Network Range options.
    • DNS IP Used – The last useable IP address in the network range.

    • Site Groups Static Range – The overlay IP address range from which the static IP address for a site group is drawn.

    • API Static Range – The overlay IP address range from which the static IP address is drawn when using an Application Programming Interface (API).

  16. Select Next to view a summary of the network configuration.

    NetCloud Manager Configure Network Summary page.
  17. Select Finish.

    Notification message for successful network creation.

The new network appears on the Networks page with the status of provisioning. After a few minutes, the status changes to provisioned.

Provisioning status for the NetCloud SASE network.

Sites and resources may now be configured for the new network.

Note

If a network creation failed message appears, contact Ericsson Enterprise Wireless Solutions Global Service & Support for technical assistance.

Notification message for failed network creation.