Skip to main content
Versa Networks

Deploy an SSE Gateway and Onboard Tenants Using Concerto

Versa-logo-release-icon.pngFor supported software information, click here.

This article provides step-by-step procedures to deploy a new Versa SSE gateway (GW) and onboard tenants using Concerto.

Prerequisites

Before you begin, complete the following tasks:

  • Ensure that your system meets the following software and license requirements:
    • Versa Operating SystemTM (VOSTM) Release 22.1.4 or later is required for Versa Director, Versa Analytics, and the SSE gateway. 
    • The license installed on the Director node must have the deployment type Cloud-Security. Obtain the appropriate license from the Versa Managed Services team.
    • For additional features, such as SASE-for-SIM, API-DP, and UEBA using Advanced Security Cloud (ASC), request the Versa Managed Services team to include these features in the license key.
  • If more than one Director complex is deployed in a single federated network, check the global ID configuration, as shown below:
    • There must be no overlap in the global ID values for the Controller and Branch between the different Director complexes.
    • The Spoke Group, VRF, and Organization ID ranges can retain the default values.

      global-id-config.png

Deploy an SSE Gateway on Director

To deploy an SSE gateway on Director, perform the following procedures. 

Create a Template Workflow for the SSE Gateway

You must create a separate template workflow for each SSE gateway. You cannot use the same template for multiple gateways.

To create a template workflow for the SSE gateway:

  1. In Director view, select the Workflows tab in the top menu bar.
  2. Select an organization. 
  3. Select Template > Templates in the horizontal menu bar, and then click the add_icon.png Add icon.
  4. In workflow step 1, Basic, enter information for the following fields. 

    template-workflow-sse1.png
     
    Field Description
    Name (Required) Enter a name for the template.
    Device Type (Group of fields)

    Select the Cloud Security device type name, and select Hub Controller as device type.

    Organization (Required)

    Select a provider organization.

    Solution Tier (Required)

    Select Premier Elite SD-WAN.

  5. Select workflow step 3, Tunnels.
  6. To configure split tunnels for direct internet access (DIA), enter information for the following fields.

     template-workflow-tunnels1.png
     
    Field Description
    Split Tunnels (Group of Fields)  
    • VRF Names
    Select the name of the virtual routing and forwarding (VRF) instance.
    • WAN Interfaces
    Select the name of the WAN interface. If you select more than two WAN interfaces from the same LAN VR to configure DIA, the interface that is first on the list has the highest priority unless you enable load balancing by clicking Load Balance.
    • Direct Internet Access
    Click to enable DIA. Source NAT is performed before packets are sent out to the WAN interface.
    • add-icon-blue.png Add icon
    Click the add-icon-blue.png Add icon to add the split tunnel to the template.
  7. Click Save to save the configuration, or click Step 7, Review. The Step 7, Review screen displays.
  8. Click Save to add the template.
  9. Click Deploy to activate the post-staging template.

For detailed information on creating a workflow template, see Create and Manage Staging and Post-Staging Templates.

Configure a Public WAN IP Address for a Gateway Behind a NAT Device

If a gateway does not have a public IP address on its WAN interface, use a static public IP address. If you cannot use a static IP address, configure the public IP address in the device template after deploying the workflow.

To configure a public WAN IP address:

  1. In Director view:
    1. Select the Configuration tab in the top menu bar.
    2. Select Templates in the horizontal menu bar.
    3. Select an organization in the left navigation bar.
    4. Select a template from the dashboard. The view changes to Template view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Services > SD-WAN > System > Site Config in the left menu bar.

    system-site-config.png
  4. Click the edit-icon.png Edit icon.
  5. In the Edit Site Config window, click the WAN interface.
  6. In the Edit WAN Interfaces window, enter information for the following fields.

    edit-wan-interfaces.png
     
    Field Description
    Circuit Tags

    Enter the following predefined circuit tags:

    • NO_DIA—Disables DIA on the WAN interface for all tenants deployed on the gateway. Use this for private WAN circuits like MPLS or dedicated internet circuits.
    • NO_S2S—Prevents the WAN circuit from being used for site-to-site tunnels by tenants.
    • NO_RAC_RAS—Restricts the WAN interface from connecting Versa SSE clients to the gateway.
    • DIA_ON_PROVIDER—Enables source CGNAT translation for the sub-tenant’s internet traffic on the transport-VR side within the provider tenant context. Use this only in specific use cases.

    If no circuit tags are used, the WAN interface is used for site-to-site tunnels, remote Versa SASE client connections, and DIA traffic.

    IPv4 Tab Select the IPv4 tab.
    • Public IP Address
    Enter the public WAN IP address.

Update the CGNAT Rule to Perform Source NAT on the Transport VR

If Lightweight Directory Access Protocol (LDAP) is reachable over the WAN IP address of transport VR, you must add the destination zone associated with the internet circuit in the carrier-grade NAT (CGNAT) rule match criteria. This ensures that any traffic originated on the gateway is captured and translated to the WAN IP address to reach customer LDAP/AD servers on the internet.

  1. In Director view:
    1. Select the Administration tab in the top menu bar.
    2. Select Appliances in the left menu bar.
    3. Select a device name in the main panel. The view changes to Appliance view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Services > CGNAT in the left menu bar.
  4. In the main pane, select the Rules tab. The tab displays the rules that are already configured.

    cgnat-page.png
  5. Select the CGNAT rule to edit.
  6. In the Edit CGNAT Rule window, select the Match > Destination tab.
  7. In the Destination Zones section, click the add_icon.png icon, and then select the destination zone. 

    edit-cgnat-rule.png
  8. Click OK.

Create a Device Group for the SSE Gateway

You must create a separate device group for each SSE gateway. For the device group name, use the following the naming convention: <GW-name>-dg. For example, saseGW4-br4-dg.

To create a device workflow and deploy the device, see Configure Basic Features.

To create a device group:

  1. In Director view, select the Configuration tab in the top menu bar.
  2. Select Devices > Device Groups in the horizontal menu bar.
  3. Click the add_icon.png Add icon to add a device group.

    device-groups-add.png
  4. In the Add Device Group window, enter information for the following fields.

    add-device-group.png
  5. Deploy the device workflow for the gateway. 
  6. If you select a device group on which URL-based ZTP is enabled, perform the zero-touch provisioning (ZTP) process. For more information, see Activate VOS Devices.

Note: All further steps should be performed while onboarding the SASE gateway.

Certificate Requirements

The SASE client establishes connections to the SSE gateway using multiple fully qualified domain names (FQDNs), such as the portal FQDN and group FQDN. To handle these HTTPS connections, the SSE gateway requires a device certificate that includes all FQDN variants used.  

  • You must use a public certificate authority (CA) to sign the end-entity (device) certificate for SSE gateways. This ensures trusted SSL or TLS connections for client-based and clientless access without installing additional root certificates on user devices.
  • When managing FQDNs with multiple hierarchical levels, ensure that all required sub-domains are explicitly included in the certificate or covered by appropriate wildcard entries. For example, a certificate for *.example.com does not include deeper-level hierarchies such as *.sub.example.com. To avoid SSL or TLS validation failures, include all required sub-domains in the certificate's subject alternative name (SAN) section. The following table provides examples of wildcard domain matching.
     
    Wildcard Entry in Certificate Matches Does Not Match
    *.example.com

    app.example.com

    mail.example.com 

    sub.example.com 

    example.com

    a1.app.example.com

    *.sub.example.com app.sub.example.com

    sub.example.com

    a1.app.sub.example.com 

  • To ensure the SSE gateway certificate is valid for supported access methods, it must include the appropriate FQDN entries to support both client-based and clientless connectivity: 
    • For secure access: *.<sse-root-domain.com
    • For reverse proxy: *.myapps.<sse-root-domain.com
  • Ensure that you generate separate certificates for each redundant SSE gateway, with different expiration dates, to avoid both gateway certificates expiring at the same time.
  • You must obtain a wildcard certificate for root domains with extended key usage Server Authentication as shown in the following figure.

    difital-sign.png

Certificate Installation

Before onboarding sub-tenants, install the certificates that will be used by all tenants for client access communication at the system level on all gateways. The certificate files must adhere to the following naming conventions: 

  • <gw-name>.crt—Gateway certificate file.
  • vsa-default-ca-chain.crt—Use the exact filename for CA certificate chain file.
  • <gw-name>.key—Private key file for the gateway certificate.

You can copy certificate files to a gateway using the shell or CLI commands.

For example, to copy all certificate files to the /var/tmp/setup_certs directory and set the appropriate permissions, use the following shell commands:

$ mkdir /var/tmp/setup_certs
$ scp versa@10.40.N.N:~/setup_certs/* /var/tmp/setup_certs
$ cd /var/tmp/setup_certs/
$ sudo chmod 755 *

For example, to import CA chain, private key, and gateway certificate, use the following CLI commands. For the private key and gateway certificate commands, replace the <gw-name> with the hostname of your gateway.

$ cli
> request crypto pki ca-chain import name vsa-default-ca-chain.crt filepath /var/tmp/setup_certs/vsa-default-ca-chain.crt
> request crypto pki private-key import filepath /var/tmp/setup_certs/<GW-NAME>.key name <GW-NAME>.key pkey-type RSA> > 
> request crypto pki certificate import name <GW-NAME>.crt priv-key <GW-NAME>.key ca-chain vsa-default-ca-chain.crt filepath /var/tmp/setup_certs/<GW-NAME>.crt

Modify Captive Portal Settings to Allow Port 443 and Update the SASE Domain

  1. In Director view:
    1. Select the Administration tab in the top menu bar.
    2. Select Appliances in the left menu bar.
    3. Select a device name in the main panel. The view changes to Appliance view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Services > Captive Portal in the left menu bar. The dashboard displays the captive portal settings.

    captive-portal.png
  4. Click edit_icon.png Edit icon. The Edit Captive Portal Settings window displays.
  5. Click the add-icon-black-on-white-22.png Add icon to add a service endpoint.

    edit-captive-portal-settings.png
  6. In the Service Endpoint window, enter information for the following fields.

    service-endpoint1.png
    Field Description
    Routing Instance (Required) Select the routing instance (VRF) to use to access the captive portal pages. If you do not select a routing instance, captive portal pages are enabled only in the global routing instance.
    HTTPS Port

    Enter the number of the HTTPS port to use to redirect captive portal pages over HTTPS.

    Default: 443

    IP Address Click the add-icon-black-on-white-22.png Add icon to add a service endpoint IP address. Any traffic destined to these IP addresses are serviced by the captive portal. Captive portal redirection that is based on the server URL is routed to one of these IP addresses.
    Server (Group of Fields)  
    • URL
    Enter the URL of the proxy autoconfiguration (PAC) file to configure a URL proxy. A PAC file defines how web browsers can automatically choose the appropriate proxy server to fetch a given URL. You can upload PAC files to a VOS device. For more information, see Upload PAC Files.
    • Certificate
    Select the certificate to use for the PAC URL.

Update SPack and Application Engine Protocol Bundle

Configure DNS

To configure DNS at the system level:

  1. In Director view:
    1. Select the Administration tab in the top menu bar.
    2. Select Appliances in the left menu bar.
    3. Select a device name in the main panel. The view changes to Appliance view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Others > System > Domain Name Servers in the left menu bar. The main pane displays the configured DNS servers.

    domain-name-server-page.png
  4. Click the add-icon-plus.png Add icon. In the Add Name Servers popup window, enter information for the following fields.

    add-name-servers.png
     
    Field Description
    Routing Instance (Required) Select the routing instance.
    Source Interface Select the source interface to use to send DNS requests to the DNS server. You must select at least one source interface or one source network.
    Source Network Select the source network to use to send DNS requests to the DNS server. You must select at least one source interface or one source network.
    Name Servers (Required)

    Click the add-icon-plus.png Add icon to add DNS servers. You can configure a maximum of the name servers.

    Search Domain

    Click the add-icon-plus.png Add icon to add domain names to search while performing a hostname lookup. You can configure a maximum of six domain names.

  5. Click OK.

Configure Time Settings

You can configure the time settings on a VOS device or Controller node. You can configure the VOS device to use an NTP server for time synchronization, or set the time manually. You can also configure the VOS device to act as an NTP server.

Configure Time 

  1. In Director view:
    1. Select the Configuration tab in the top menu bar.
    2. Select Templates > Device Templates in the horizontal menu bar.
    3. Select an organization in the left menu bar.
    4. Select a device in the main pane. The view changes to Appliance view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Others > System > Time & Date > Time Settings in the left menu bar.

    system-time-settings-home.png
     
  4. Click the edit-icon.png Edit icon. In the Edit Time Settings popup window, enter information for the following fields.

    Edit_Time_Settings.png
     
    Field Description
    Current Time Displays the current time on the device.
    Timezone Select the timezone to use for time settings.
    Server Services (Group of Fields) (For Releases 22.1.4 (Service Release dated 2024-12-20) and later.) Enter server settings to enable the VOS device to act as an NTP server.
    • Description
    Enter a description for the time server. 
    • Source Network
    Select the source network for the time server. 
    • Source Interface
    Select the source interface for the time server.
    • Enable
    Click to enable NTP server services on the VOS device.
    NTP

    Click to use the Network Time Protocol to set the time on the device.

    Manual Click to set the time manually on the device.
    Set Date/time at If you select Manual mode, set the date and time on the device.
  5. If you select NTP, click the add-icon.png Add icon in the NTP Servers pane to add NTP servers. In the Add NTP Server popup window, enter information for the following fields.

    Add_NTP_Server.png
     
    Field Description
    Server IP Address/Host Name (Required) Enter the IP address or host name of the NTP server. For DNS resolution of host names, NTP uses global DNS settings. If there are no global DNS setting, then select a Routing Instance, below. 
    Description Enter a text description the server.
    Key ID Select the ID of the authentication key. For more information, see Configure an Authentication Key ID, below.
    Routing Instance Select the routing instance to resolve the FQDN of the NTP server.
    Source Network
    Source Interface

    Click to select either the network or interface to use to reach the NTP server. This field is required if the NTP server is inaccessible through the management network.

    Version Select the version of the NTP server. The current version is 4, which is compatible with version 3.
    Enable Click to activate NTP services.
    Iburst Click to enable iburst on the server. Using iburst improves the time required for initial synchronization. With iburst, when the NTP server is unreachable, a burst of eight packets is sent instead of the usual one packet.
  6. Click OK.

Configure an Authentication Key ID

To configure an authentication key to validate the NTP server:

  1. In Director view:
    1. Select the Configuration tab in the top menu bar.
    2. Select Templates > Device Templates in the horizontal menu bar.
    3. Select an organization in the left menu bar.
    4. Select a device in the main pane. The view changes to Appliance view.
  2. Select the Configuration tab in the top menu bar.
  3. Select Others > System Time & Date > Key ID in the left menu bar.

    system-key-id-home.png
  4. Click the add-icon.png Add icon. In the Add Key ID popup window, enter information for the following fields.

    system-add-key-id.png
     
    Field Description
    Key ID Enter an ID for the authentication key.
    Trusted Click to mark the key as trusted.
    Type

    Select the key type:

    • MD5
    • SHA1 (Releases 22.1.4 and later)
    • SHA 256 (Releases 22.1.4 and later.)
    Value Enter a key value.
  5. Click OK.

Configure QAT on a Supported Platform

To enable QAT on a supported platform, configure crypto accelerator support at the platform and service levels using the following CLI commands:

  • For platform level support: set system platform crypto-accelerator-support true
  • For service level support: set system service-options crypto-accelerator-support true

For example:

Gateway-01$ cli
Gateway-01-cli> configure
Gateway-01-cli(config)% set system platform crypto-accelerator-support true
Gateway-01-cli(config)% commit
Gateway-01$ cli
Gateway-01-cli> configure
Gateway-01-cli(config)% set system service-options crypto-accelerator-support true
Gateway-01-cli(config)% commit

To verify the QAT status on a platform, use the following command:

Gateway-01$ vsh connect vsmd
vsm-vcsn0> show ipsec qat status

Discover Gateways on Concerto

You must add the Director node to the Concerto portal, and discover the Director node and gateways that you created in Versa Director on the Concerto portal. For more information, see Install Concerto.

To add a Director node in the Concerto portal:

  1. Log in to Concerto as an administrator. The Tenants home screen displays.
  2. In the left menu bar, select Infrastructure > Director.

    infra-director.png
  3. In the Infrastructure > Director screen, click add_icon.png Add.

    infra-director-add.png
  4. In the Add Director window, enter information for the following fields.

    infra-director-add-screen.png
     
    Field Description
    Name (Required) Enter a name for the Director.
    Is Default Click the toggle to the enabled position toggle-button.png to have the new Director node be the default Director node. The default Director node authenticates all Administrator users, whether the users are local or internal to the Director node.
    Username Enter a username.
    Password Enter a password that the Concerto orchestrator uses to enable server-to-server communication with the Director node using REST API calls. You can configure a separate password for each Director cluster. The password should have at least one uppercase character, one digit, and one special character.
    Services Provided by Director

    Select the services that the Director provides:

    • Secure SD-WAN—Director supports only Secure SD-WAN gateways.
    • Security Service Edge (SSE)—Director supports only Security Service Edge gateways.

    When you later create a tenant and select the services for that tenant, you can select only the Directors that support that service. For example, if you select only the Secure SD-WAN service for a tenant and then select the Director or Directors for that tenant, only the Directors that support Secure SD-WAN are displayed.

    Primary Director IP Address (Required) Enter the IP addresses of the primary Director node. 
    Secondary Director IP Address Enter the IP addresses of the secondary Director node (if a secondary Director node exists). For a HA deployment, enter the IP addresses of both Director nodes.
  5. Click Submit.
  6. To discover the Director node on the Concerto portal:
    1. In the Infrastructure > Director screen, click the More Actions drop-down list.
    2. Select Discover Tenants.

      infra-director-discover.png
  7. In the Discover Tenants on Director window, enter the username and password for the ProviderDataCenterSystemAdmin. The screen displays the discovered Controller nodes and the solution tiers for the new Director node.

    discover-tenant-director.png
  8. To discover devices in the provider tenant to add gateways to Concerto portal, select Tenants in the left navigation bar. The list of tenants displays. 
  9. Click the three-dot-icon.png eclipse to the right of the tenant name, and then select Appliance Discovery.

    appiance-discovery.png
  10. Verify that all gateways appear in the Deploy Lifecycle of the provider tenant.

All discovered gateways are initially added to the Default region in Concerto. You can create and move gateway sites to the appropriate geographical regions. When you create subtenants, provider tenant-level regions for associated gateways are automatically cloned to the subtenants.

To create and move gateway sites to specific regions, select Deploy in the left menu bar, and then select the Regions tab in the horizontal menu bar. For more information, see Configure Regions.

deploy-region.png

Configure the Root Domain for an SSE Deployment

You can use the SSE setting to specify the root domain for your SSE deployment. Gateway FQDNs are automatically generated based on the root domain value.

To configure the root domain for an SSE deployment:

  1. In the service provider home screen, select Settings > SSE.

    sse-page.png
  2. In the SSE Infrastructure Settings screen, select the General tab, and enter information for the following fields.

    sse-infra-settings.png
     
    Field Description
    Use Tenant Name in GW FQDNs Click the toggle-button.png toggle to use the tenant name in the SSE gateway FQDNs.
  3. Click Save.

Onboard Tenants on SSE Gateway

To onboard tenants on an SSE gateway, see Configure SASE Tenants

Supported Software Information  

Releases 22.1.4 and later support all content described in this article.

  • Was this article helpful?