Microtunnel is an encryption and tunneling technology between an Ericsson Cradlepoint router and NetCloud Exchange. Similar to IPsec, Microtunnel provides higher throughput than a standard IPsec tunnel. Minimum software version required is 7.26.40.
The following Ericsson Cradlepoint routers with Secure Connect licenses support Micotunnel:
E100
E300
E400
E3000
R1900
A microtunnel can be operated in one of three modes:
Level 0 (Null Encryption) – No user traffic is encrypted. Ericsson Enterprise Wireless Solution recommends using this mode only when all user traffic is already encrypted. This mode provides maximum performance.
Level 1 (Selective Encryption) – This is the default mode for Microtunnel. Ports and protocols that already receive encrypted traffic can be specified, thus excluding Microtunnel encryption and avoiding another level of encryption. If no ports or protocols are specified all traffic is encrypted, which might lead to performance degradation.
Level 3 (All Encryption) – In this mode, all user traffic is encrypted. This mode enables the network's FIPS compliance.
Complete the following steps to configure a Secure Connect network with Microtunnel:
Log into NetCloud Manager.
Select in the left-side navigation panel.
Select .
Optional: Select Current Account to open the Select an Account panel and then select a subaccount in which to configure the Secure Connect network, if needed.
Select from the Hosting Mode drop-down menu.
Note
NetCloud Manager supports different Secure Connect network types within a single account. The Cradlepoint-Hosted (Legacy) option is active only for particular accounts.
Enter a descriptive name for the network.
Input the Primary DNS server IP address.
The network's primary and secondary domain name system (DNS) settings configure the network-level DNS, which resolves DNS requests for named resources. The DNS server must be reachable from the NetCloud SASE point of presence (PoP).
Note
With NetCloud OS 7.25.100, private DNS server IP addresses may be entered in the primary and secondary fields, if the DNS server is configured as a subnet resource for a Secure Connect site.
Optional: Input the Secondary DNS server IP address.
Optional: Check the Enable Fast Link Monitoring box to initiate sending Secure Connect network-specific metering packets every 300 msec that include a new time-to-live timer and unique identifier on a specific User Datagram Protocol (UDP) port from the Ericsson Cradlepoint router to the service gateway. If the timer expires and a traffic steering rule is configured for failover, traffic is switched to a better WAN interface. This functionality uses approximately 66 MB per day.
Note
Fast Link Monitoring is supported for bonded interfaces with minimum software version 7.24.60.
Loss measurement is supported only for Transmission Control Protocol (TCP) traffic flows and applies to individual WAN interfaces. This feature only measures loss and does not measure other parameters such as latency or signal strength.
Optional: Select Advanced DNS Options to override the default 8.8.8.8 DNS setting with static entries for the network, if needed in a network configured for split routing.
Enter the Split DNS Server 1 IP address.
Enter the Split DNS Server 2 IP address.
Select the region (PoP) that is closest to the majority of network users.
Note
Once a region is configured for the network, it cannot be changed since doing so requires deleting the NetCloud Exchange Service Gateway and creating a network in the new region.
See NetCloud SASE Points of Presence and Egress IP Addresses for currently supported regions.
Note
The displayed regions are dependent upon the region in which the NetCloud Manager account resides.
Optional: Select the Cipher Profile level from the drop-down menu to increase the complexity of the encryption used for communication.
Null Encryption – No encryption
Level 1 – AES 128, SHA2 256, Group 14 (ECP 256)
Level 2 – AES 128, SHA2 256, Group 19 (ECP 256)
Level 3 – AES 256, SHA2 384, Group 20 (ECP 256)
Select the Microtunnel checkbox.
If LEVEL1 was selected in the previous step, select the desired protocol checkboxes and enter the corresponding ports that are excluded from receiving encrypted traffic.
Note
Ports for TCP and UDP are pre-populated and can be modified or deleted, if needed.
Reset to default may be used to restore the default settings, if needed.
Select .
Select Full Tunnel or Split Routing.
If Full Tunnel is selected, check Update DNS on Tunnel Failure so the router associated with the network site can monitor connectivity to the service gateway. If a connection failure is detected, a 30-second timer starts. If the timer meets its threshold, the router updates its local DNS server to use its local DNS settings for internet-bound traffic.
Note
Minimum software version required for DNS on Tunnel Failure is 7.23.60.
If Split Routing is selected, add the routes:
Select .
Hover over the row and select the edit pencil (
) icon.
Enter a destination IP address/network in CIDR format (for example, 192.168.0.0/16) and then press Enter.
Note
These routes go toward the NCX Service Gateway. Anything not specified in this table is directed out to the internet.
Repeat as needed to add other routes.
Optional: Select an unused overlay range from the Overlay Network Range drop-down menu and select .
Overlay Range – The overlay IP address range from which the various IP addresses are drawn.
DNS IP Used – The last useable IP address in the network range.
Site Groups Static Range – The overlay IP address range from which the static IP address for a site group is drawn.
API Static Range – The overlay IP address range from which the static IP address is drawn when using an Application Programming Interface (API).
Select to view a summary of the network configuration.
Select .
The new network appears on the Networks page with the status of provisioning. After a few minutes, the status changes to provisioned.