Configure a Secure Connect Network with Microtunnel - Configuring-NetCloud-SASE/Configure-a-Secure-Connect-Network-with-Microtunnel

NetCloud SASE Configuration Guide

ft:locale
en-US
ft:sourceName
Paligo_Prod
Document Type
Configuration Guide

Microtunnel is an encryption and tunneling technology between an Ericsson Cradlepoint router and NetCloud Exchange. Similar to IPsec, Microtunnel provides higher throughput than a standard IPsec tunnel. Minimum software version required is 7.26.40.

The following Ericsson Cradlepoint routers with Secure Connect licenses support Micotunnel:

  • E100

  • E300

  • E400

  • E3000

  • R1900

A microtunnel can be operated in one of three modes:

  1. Level 0 (Null Encryption) – No user traffic is encrypted. Ericsson Enterprise Wireless Solution recommends using this mode only when all user traffic is already encrypted. This mode provides maximum performance.

  2. Level 1 (Selective Encryption) – This is the default mode for Microtunnel. Ports and protocols that already receive encrypted traffic can be specified, thus excluding Microtunnel encryption and avoiding another level of encryption. If no ports or protocols are specified all traffic is encrypted, which might lead to performance degradation.

  3. Level 3 (All Encryption) – In this mode, all user traffic is encrypted. This mode enables the network's FIPS compliance.

Complete the following steps to configure a Secure Connect network with Microtunnel:

  1. Log into NetCloud Manager.

  2. Select Networks in the left-side navigation panel.

  3. Select Add.

    NetCloud Manager Networks screen highlighting the Add button.
  4. Optional: Select Current Account to open the Select an Account panel and then select a subaccount in which to configure the Secure Connect network, if needed.

  5. Select Cradlepoint-Hosted (SASE) from the Hosting Mode drop-down menu.

    NetCloud Manager Network page highlighting the Hosting Mode selection.

    Note

    NetCloud Manager supports different Secure Connect network types within a single account. The Cradlepoint-Hosted (Legacy) option is active only for particular accounts.

  6. Enter a descriptive name for the network.

  7. Input the Primary DNS server IP address.

    The network's primary and secondary domain name system (DNS) settings configure the network-level DNS, which resolves DNS requests for named resources. The DNS server must be reachable from the NetCloud SASE point of presence (PoP).

    Note

    With NetCloud OS 7.25.100, private DNS server IP addresses may be entered in the primary and secondary fields, if the DNS server is configured as a subnet resource for a Secure Connect site.

  8. Optional: Input the Secondary DNS server IP address.

  9. Optional: Check the Enable Fast Link Monitoring box to initiate sending Secure Connect network-specific metering packets every 300 msec that include a new time-to-live timer and unique identifier on a specific User Datagram Protocol (UDP) port from the Ericsson Cradlepoint router to the service gateway. If the timer expires and a traffic steering rule is configured for failover, traffic is switched to a better WAN interface. This functionality uses approximately 66 MB per day.

    Note

    Fast Link Monitoring is supported for bonded interfaces with minimum software version 7.24.60.

    Loss measurement is supported only for Transmission Control Protocol (TCP) traffic flows and applies to individual WAN interfaces. This feature only measures loss and does not measure other parameters such as latency or signal strength.

  10. Optional: Select Advanced DNS Options to override the default 8.8.8.8 DNS setting with static entries for the network, if needed in a network configured for split routing.

    1. Enter the Split DNS Server 1 IP address.

    2. Enter the Split DNS Server 2 IP address.

  11. Select the region (PoP) that is closest to the majority of network users.

    NetCloud Manager Configure Network page highlighting the Region drop-down menu.

    Note

    Once a region is configured for the network, it cannot be changed since doing so requires deleting the NetCloud Exchange Service Gateway and creating a network in the new region.

    See NetCloud SASE Points of Presence and Egress IP Addresses for currently supported regions.NetCloud SASE Points of Presence and Egress IP Addresses

    Note

    The displayed regions are dependent upon the region in which the NetCloud Manager account resides.

  12. Optional: Select the Cipher Profile level from the drop-down menu to increase the complexity of the encryption used for communication.

    • Null Encryption – No encryption

    • Level 1 – AES 128, SHA2 256, Group 14 (ECP 256)

    • Level 2 – AES 128, SHA2 256, Group 19 (ECP 256)

    • Level 3 – AES 256, SHA2 384, Group 20 (ECP 256)

  13. Select the Microtunnel checkbox.

    If LEVEL1 was selected in the previous step, select the desired protocol checkboxes and enter the corresponding ports that are excluded from receiving encrypted traffic.

    Note

    Ports for TCP and UDP are pre-populated and can be modified or deleted, if needed.

    Reset to default may be used to restore the default settings, if needed.

  14. Select Next.

  15. Select Full Tunnel or Split Routing.

    1. If Full Tunnel is selected, check Update DNS on Tunnel Failure so the router associated with the network site can monitor connectivity to the service gateway. If a connection failure is detected, a 30-second timer starts. If the timer meets its threshold, the router updates its local DNS server to use its local DNS settings for internet-bound traffic.

      Configure Network Routing page highlighting the Update DNS on Tunnel Failure option.

      Note

      Minimum software version required for DNS on Tunnel Failure is 7.23.60.

    2. If Split Routing is selected, add the routes:

      1. Select Add.

      2. Hover over the row and select the edit pencil (Edit pencil icon.) icon.

        Configure Network Tunnel Mode section highlighting the edit (pencil) icon.
      3. Enter a destination IP address/network in CIDR format (for example, 192.168.0.0/16) and then press Enter.

        Note

        These routes go toward the NCX Service Gateway. Anything not specified in this table is directed out to the internet.

      4. Repeat as needed to add other routes.

  16. Optional: Select an unused overlay range from the Overlay Network Range drop-down menu and select Save.

    • Overlay Range – The overlay IP address range from which the various IP addresses are drawn.

      NetCloud Manager Routing page showing the Overlay Network Range options.
    • DNS IP Used – The last useable IP address in the network range.

    • Site Groups Static Range – The overlay IP address range from which the static IP address for a site group is drawn.

    • API Static Range – The overlay IP address range from which the static IP address is drawn when using an Application Programming Interface (API).

  17. Select Next to view a summary of the network configuration.

    NetCloud Manager Configure Network Summary page.
  18. Select Finish.

    Notification message for successful network creation.

The new network appears on the Networks page with the status of provisioning. After a few minutes, the status changes to provisioned.

Provisioning status for the NetCloud SASE network.