The NetCloud Exchange Service Gateway is deployed as a virtual machine (VM) and acts as the heart of a network, facilitating connections between remote sites and resources, aggregating tunnels, and enforcing routing and policy decisions. Although it is not a physical endpoint, it can be managed just like any Ericsson Cradlepoint router in NetCloud Manager after deployment. The NCX Service Gateway provides deep visibility into each flow and recognizes corporate applications.
NCX Service Gateway provides the foundation for the services: Secure Connect, SD-WAN and Zero Trust. As the customer-hosted service delivery platform for NetCloud Exchange, the NCX Service Gateway works in conjunction with Secure Connect to orchestrate secure connectivity from Ericsson Cradlepoint routers in fixed locations, vehicles and IoT to digital resources in the cloud, data center and external sites. Delivered in virtual form factors for deployment on-or-off premises, the NCX Service Gateway is easily provisioned using Ericsson NetCloud and managed like other Ericsson solutions.
Depending upon internal resource needs, the NCX Service Gateway can be deployed with two (mgmt0 and wan0) or three interfaces (mgmt0, lan0, and wan0):
The mgmt0 interface provides the Secure Shell Access (SSH Access) protocol and the NetCloud OS user interface access to the NCX Service Gateway and is used for link state synchronization with a standby NCX Service Gateway, if needed.
The local area network interface (lan0) at the NCX Service Gateway is used to reach internal resources, applications, and Domain Name System (DNS) servers. If internal resources on the lan0 interface need to be reached by sites and site resources, all three interfaces should be configured (mgmt0, lan0 and wan0).
The wan0 interface is where the tunnels come into the network and are terminated at the NCX Service Gateway. Only one publicly routable static IP address is needed for the network on the wan0 interface.
The NCX Service Gateway implements the Data Plane Development Kit (DPDK) standard to provide high-performance packet forwarding capabilities. The processors (CPUs) and NICs in the servers must support DPDK for the NCX Service Gateway to function correctly. High CPU usage is part of DPDK normal function, as DPDK reserves CPU cores to constantly poll the network interface card (NIC) for packets. No less than four of the eight CPUs are dedicated to constant data plane polling. CPU usage at 100% is expected on all NCX Service Gateway host virtual machines (VMs) regardless of load. NCX Service Gateway host VMs that are operating properly will have high CPU usage. Internal CPU usage reporting may need to be adjusted accordingly.
Secure Connect is a foundational service of the NetCloud Exchange and NetCloud SASE platforms that provides highly secure, encrypted communications. It is a zero-trust network that replaces outdated multiprotocol label switching (MPLS), software defined networks (SDNs), and difficult to manage VPNs, providing far better security and operational simplicity. Secure Connect enables large scale deployments of Ericsson Cradlepoint routers simply and with minimal technical acumen. The NetCloud Exchange Service Gateway, which acts as an aggregation point for spoke routes, is required to enable and orchestrate connectivity from spoke locations to Secure Connect. Secure Connect allows for programmatic configuration of an NCX Service Gateway.
Some protocols and ports must be open through the firewall for Secure Connect to properly function. See Firewall Ports and Protocols for Cloud Connectivity for the detailed list.
Note
UDP ports 500 and 4500 must be open at the firewall and ensure that neither conflict with other firewall configurations since dedicating the same IP address and ports to different assets can be problematic.
Activation and use of NetCloud Exchange Service Gateway requires a license to a NetCloud Service plan.
The settings depicted in this guide are only a reference and do not represent the best or the only way of deploying the NCX Service Gateway as a virtual machine. You may have to modify the deployment depending on your hardware and software versions or other factors.