Deploy an SSE Gateway and Onboard Tenants Using Concerto
For supported software information, click here.
This article provides step-by-step procedures to deploy a new Versa SSE gateway (GW) and onboard tenants using Concerto.
Prerequisites
Before you begin, complete the following tasks:
- Ensure that your system meets the following software and license requirements:
- Versa Operating SystemTM (VOSTM) Release 22.1.4 or later is required for Versa Director, Versa Analytics, and the SSE gateway.
- The license installed on the Director node must have the deployment type Cloud-Security. Obtain the appropriate license from the Versa Managed Services team.
- For additional features, such as SASE-for-SIM, API-DP, and UEBA using Advanced Security Cloud (ASC), request the Versa Managed Services team to include these features in the license key.
- If more than one Director complex is deployed in a single federated network, check the global ID configuration, as shown below:
- There must be no overlap in the global ID values for the Controller and Branch between the different Director complexes.
- The Spoke Group, VRF, and Organization ID ranges can retain the default values.

Deploy an SSE Gateway on Director
To deploy an SSE gateway on Director, perform the following procedures.
Create a Template Workflow for the SSE Gateway
You must create a separate template workflow for each SSE gateway. You cannot use the same template for multiple gateways.
To create a template workflow for the SSE gateway:
- In Director view, select the Workflows tab in the top menu bar.
- Select an organization.
- Select Template > Templates in the horizontal menu bar, and then click the
Add icon. - In workflow step 1, Basic, enter information for the following fields.

Field Description Name (Required) Enter a name for the template. Device Type (Group of fields) Select the Cloud Security device type name, and select Hub Controller as device type.
Organization (Required) Select a provider organization.
Solution Tier (Required)
Select Premier Elite SD-WAN.
- Select workflow step 3, Tunnels.
- To configure split tunnels for direct internet access (DIA), enter information for the following fields.

Field Description Split Tunnels (Group of Fields) - VRF Names
Select the name of the virtual routing and forwarding (VRF) instance. - WAN Interfaces
Select the name of the WAN interface. If you select more than two WAN interfaces from the same LAN VR to configure DIA, the interface that is first on the list has the highest priority unless you enable load balancing by clicking Load Balance. - Direct Internet Access
Click to enable DIA. Source NAT is performed before packets are sent out to the WAN interface.
Add icon
Click the
Add icon to add the split tunnel to the template. - Click Save to save the configuration, or click Step 7, Review. The Step 7, Review screen displays.
- Click Save to add the template.
- Click Deploy to activate the post-staging template.
For detailed information on creating a workflow template, see Create and Manage Staging and Post-Staging Templates.
Configure a Public WAN IP Address for a Gateway Behind a NAT Device
If a gateway does not have a public IP address on its WAN interface, use a static public IP address. If you cannot use a static IP address, configure the public IP address in the device template after deploying the workflow.
To configure a public WAN IP address:
- In Director view:
- Select the Configuration tab in the top menu bar.
- Select Templates in the horizontal menu bar.
- Select an organization in the left navigation bar.
- Select a template from the dashboard. The view changes to Template view.
- Select the Configuration tab in the top menu bar.
- Select Services > SD-WAN > System > Site Config in the left menu bar.

- Click the
Edit icon. - In the Edit Site Config window, click the WAN interface.
- In the Edit WAN Interfaces window, enter information for the following fields.

Field Description Circuit Tags Enter the following predefined circuit tags:
- NO_DIA—Disables DIA on the WAN interface for all tenants deployed on the gateway. Use this for private WAN circuits like MPLS or dedicated internet circuits.
- NO_S2S—Prevents the WAN circuit from being used for site-to-site tunnels by tenants.
- NO_RAC_RAS—Restricts the WAN interface from connecting Versa SSE clients to the gateway.
- DIA_ON_PROVIDER—Enables source CGNAT translation for the sub-tenant’s internet traffic on the transport-VR side within the provider tenant context. Use this only in specific use cases.
If no circuit tags are used, the WAN interface is used for site-to-site tunnels, remote Versa SASE client connections, and DIA traffic.
IPv4 Tab Select the IPv4 tab. - Public IP Address
Enter the public WAN IP address.
Update the CGNAT Rule to Perform Source NAT on the Transport VR
If Lightweight Directory Access Protocol (LDAP) is reachable over the WAN IP address of transport VR, you must add the destination zone associated with the internet circuit in the carrier-grade NAT (CGNAT) rule match criteria. This ensures that any traffic originated on the gateway is captured and translated to the WAN IP address to reach customer LDAP/AD servers on the internet.
- In Director view:
- Select the Administration tab in the top menu bar.
- Select Appliances in the left menu bar.
- Select a device name in the main panel. The view changes to Appliance view.
- Select the Configuration tab in the top menu bar.
- Select Services > CGNAT in the left menu bar.
- In the main pane, select the Rules tab. The tab displays the rules that are already configured.

- Select the CGNAT rule to edit.
- In the Edit CGNAT Rule window, select the Match > Destination tab.
- In the Destination Zones section, click the
icon, and then select the destination zone.

- Click OK.
Create a Device Group for the SSE Gateway
You must create a separate device group for each SSE gateway. For the device group name, use the following the naming convention: <GW-name>-dg. For example, saseGW4-br4-dg.
To create a device workflow and deploy the device, see Configure Basic Features.
To create a device group:
- In Director view, select the Configuration tab in the top menu bar.
- Select Devices > Device Groups in the horizontal menu bar.
- Click the
Add icon to add a device group.

- In the Add Device Group window, enter information for the following fields.

- Deploy the device workflow for the gateway.
- If you select a device group on which URL-based ZTP is enabled, perform the zero-touch provisioning (ZTP) process. For more information, see Activate VOS Devices.
Note: All further steps should be performed while onboarding the SASE gateway.
Certificate Requirements
The SASE client establishes connections to the SSE gateway using multiple fully qualified domain names (FQDNs), such as the portal FQDN and group FQDN. To handle these HTTPS connections, the SSE gateway requires a device certificate that includes all FQDN variants used.
- You must use a public certificate authority (CA) to sign the end-entity (device) certificate for SSE gateways. This ensures trusted SSL or TLS connections for client-based and clientless access without installing additional root certificates on user devices.
- When managing FQDNs with multiple hierarchical levels, ensure that all required sub-domains are explicitly included in the certificate or covered by appropriate wildcard entries. For example, a certificate for *.example.com does not include deeper-level hierarchies such as *.sub.example.com. To avoid SSL or TLS validation failures, include all required sub-domains in the certificate's subject alternative name (SAN) section. The following table provides examples of wildcard domain matching.
Wildcard Entry in Certificate Matches Does Not Match *.example.com app.example.com
mail.example.com
sub.example.com
example.com
a1.app.example.com
*.sub.example.com app.sub.example.com sub.example.com
a1.app.sub.example.com
- To ensure the SSE gateway certificate is valid for supported access methods, it must include the appropriate FQDN entries to support both client-based and clientless connectivity:
- For secure access: *.<sse-root-domain.com>
- For reverse proxy: *.myapps.<sse-root-domain.com>
- Ensure that you generate separate certificates for each redundant SSE gateway, with different expiration dates, to avoid both gateway certificates expiring at the same time.
- You must obtain a wildcard certificate for root domains with extended key usage Server Authentication as shown in the following figure.

Certificate Installation
Before onboarding sub-tenants, install the certificates that will be used by all tenants for client access communication at the system level on all gateways. The certificate files must adhere to the following naming conventions:
- <gw-name>.crt—Gateway certificate file.
- vsa-default-ca-chain.crt—Use the exact filename for CA certificate chain file.
- <gw-name>.key—Private key file for the gateway certificate.
You can copy certificate files to a gateway using the shell or CLI commands.
For example, to copy all certificate files to the /var/tmp/setup_certs directory and set the appropriate permissions, use the following shell commands:
$ mkdir /var/tmp/setup_certs
$ scp versa@10.40.N.N:~/setup_certs/* /var/tmp/setup_certs
$ cd /var/tmp/setup_certs/
$ sudo chmod 755 *
For example, to import CA chain, private key, and gateway certificate, use the following CLI commands. For the private key and gateway certificate commands, replace the <gw-name> with the hostname of your gateway.
$ cli > request crypto pki ca-chain import name vsa-default-ca-chain.crt filepath /var/tmp/setup_certs/vsa-default-ca-chain.crt
> request crypto pki private-key import filepath /var/tmp/setup_certs/<GW-NAME>.key name <GW-NAME>.key pkey-type RSA> >
> request crypto pki certificate import name <GW-NAME>.crt priv-key <GW-NAME>.key ca-chain vsa-default-ca-chain.crt filepath /var/tmp/setup_certs/<GW-NAME>.crt
Modify Captive Portal Settings to Allow Port 443 and Update the SASE Domain
- In Director view:
- Select the Administration tab in the top menu bar.
- Select Appliances in the left menu bar.
- Select a device name in the main panel. The view changes to Appliance view.
- Select the Configuration tab in the top menu bar.
- Select Services > Captive Portal in the left menu bar. The dashboard displays the captive portal settings.

- Click
Edit icon. The Edit Captive Portal Settings window displays. - Click the
Add icon to add a service endpoint.

- In the Service Endpoint window, enter information for the following fields.
Field Description Routing Instance (Required) Select the routing instance (VRF) to use to access the captive portal pages. If you do not select a routing instance, captive portal pages are enabled only in the global routing instance. HTTPS Port Enter the number of the HTTPS port to use to redirect captive portal pages over HTTPS.
Default: 443
IP Address Click the
Add icon to add a service endpoint IP address. Any traffic destined to these IP addresses are serviced by the captive portal. Captive portal redirection that is based on the server URL is routed to one of these IP addresses.Server (Group of Fields) - URL
Enter the URL of the proxy autoconfiguration (PAC) file to configure a URL proxy. A PAC file defines how web browsers can automatically choose the appropriate proxy server to fetch a given URL. You can upload PAC files to a VOS device. For more information, see Upload PAC Files. - Certificate
Select the certificate to use for the PAC URL.
Update SPack and Application Engine Protocol Bundle
- To update security package (SPack) to the premium version on the SSE gateway from Versa Director, see Use Security Packages (SPacks).
- To upgrade the application engine protocol bundle on the SSE gateway, see Use Security Packages (SPacks).
Configure DNS
To configure DNS at the system level:
- In Director view:
- Select the Administration tab in the top menu bar.
- Select Appliances in the left menu bar.
- Select a device name in the main panel. The view changes to Appliance view.
- Select the Configuration tab in the top menu bar.
- Select Others > System > Domain Name Servers in the left menu bar. The main pane displays the configured DNS servers.

- Click the
Add icon. In the Add Name Servers popup window, enter information for the following fields.

Field Description Routing Instance (Required) Select the routing instance. Source Interface Select the source interface to use to send DNS requests to the DNS server. You must select at least one source interface or one source network. Source Network Select the source network to use to send DNS requests to the DNS server. You must select at least one source interface or one source network. Name Servers (Required) Click the
Add icon to add DNS servers. You can configure a maximum of the name servers.Search Domain Click the
Add icon to add domain names to search while performing a hostname lookup. You can configure a maximum of six domain names. - Click OK.
Configure Time Settings
You can configure the time settings on a VOS device or Controller node. You can configure the VOS device to use an NTP server for time synchronization, or set the time manually. You can also configure the VOS device to act as an NTP server.
Configure Time
Configure an Authentication Key ID
Configure QAT on a Supported Platform
To enable QAT on a supported platform, configure crypto accelerator support at the platform and service levels using the following CLI commands:
- For platform level support: set system platform crypto-accelerator-support true
- For service level support: set system service-options crypto-accelerator-support true
For example:
Gateway-01$ cli Gateway-01-cli> configure Gateway-01-cli(config)% set system platform crypto-accelerator-support true Gateway-01-cli(config)% commit
Gateway-01$ cli Gateway-01-cli> configure Gateway-01-cli(config)% set system service-options crypto-accelerator-support true Gateway-01-cli(config)% commit
To verify the QAT status on a platform, use the following command:
Gateway-01$ vsh connect vsmd vsm-vcsn0> show ipsec qat status
Discover Gateways on Concerto
You must add the Director node to the Concerto portal, and discover the Director node and gateways that you created in Versa Director on the Concerto portal. For more information, see Install Concerto.
To add a Director node in the Concerto portal:
- Log in to Concerto as an administrator. The Tenants home screen displays.
- In the left menu bar, select Infrastructure > Director.

- In the Infrastructure > Director screen, click
Add.

- In the Add Director window, enter information for the following fields.

Field Description Name (Required) Enter a name for the Director. Is Default Click the toggle to the enabled position
to have the new Director node be the default Director node. The default Director node authenticates all Administrator users, whether the users are local or internal to the Director node.Username Enter a username. Password Enter a password that the Concerto orchestrator uses to enable server-to-server communication with the Director node using REST API calls. You can configure a separate password for each Director cluster. The password should have at least one uppercase character, one digit, and one special character. Services Provided by Director Select the services that the Director provides:
- Secure SD-WAN—Director supports only Secure SD-WAN gateways.
- Security Service Edge (SSE)—Director supports only Security Service Edge gateways.
When you later create a tenant and select the services for that tenant, you can select only the Directors that support that service. For example, if you select only the Secure SD-WAN service for a tenant and then select the Director or Directors for that tenant, only the Directors that support Secure SD-WAN are displayed.
Primary Director IP Address (Required) Enter the IP addresses of the primary Director node. Secondary Director IP Address Enter the IP addresses of the secondary Director node (if a secondary Director node exists). For a HA deployment, enter the IP addresses of both Director nodes. - Click Submit.
- To discover the Director node on the Concerto portal:
- In the Infrastructure > Director screen, click the More Actions drop-down list.
- Select Discover Tenants.

- In the Discover Tenants on Director window, enter the username and password for the ProviderDataCenterSystemAdmin. The screen displays the discovered Controller nodes and the solution tiers for the new Director node.

- To discover devices in the provider tenant to add gateways to Concerto portal, select Tenants in the left navigation bar. The list of tenants displays.
- Click the
eclipse to the right of the tenant name, and then select Appliance Discovery.

- Verify that all gateways appear in the Deploy Lifecycle of the provider tenant.
All discovered gateways are initially added to the Default region in Concerto. You can create and move gateway sites to the appropriate geographical regions. When you create subtenants, provider tenant-level regions for associated gateways are automatically cloned to the subtenants.
To create and move gateway sites to specific regions, select Deploy in the left menu bar, and then select the Regions tab in the horizontal menu bar. For more information, see Configure Regions.

Configure the Root Domain for an SSE Deployment
You can use the SSE setting to specify the root domain for your SSE deployment. Gateway FQDNs are automatically generated based on the root domain value.
To configure the root domain for an SSE deployment:
- In the service provider home screen, select Settings > SSE.

- In the SSE Infrastructure Settings screen, select the General tab, and enter information for the following fields.

Field Description Use Tenant Name in GW FQDNs Click the
toggle to use the tenant name in the SSE gateway FQDNs. - Click Save.
Onboard Tenants on SSE Gateway
To onboard tenants on an SSE gateway, see Configure SASE Tenants.
Supported Software Information
Releases 22.1.4 and later support all content described in this article.
Additional Information
Create and Manage Staging and Post-Staging Templates
Configure Interfaces
Configure CGNAT
Install Concerto





