Manage Templates
This article describes how to configure and manage device templates, service templates, and Versa secure access template. Note that the secure access template configuration is common for across an organization and all devices in the organization. You cannot configure it for individual devices.
You can use configuration templates to deploy configurations across an organization or across devices in an organization. Versa Portal supports three types of templates:
- Device template—A device template lets you configure, store, use, and reuse the configuration on a device, and perform mass publishing. A default template is available and you can clone, rename, and make changes to the default template based on your requirements.
- Service template—Service templates are service-specific configurations that can be used to configure certain services. They can then be applied to device configurations to enable the services. You can make mass configuration changes using a service template. The changes are not stored in the service template after publishing. Initially, the device list will be empty; devices will appear after you have published. Reload the device list or refresh the page to see the updated device list.
- Versa Secure Access Template—When you use a secure access template, you can attach a VRF to terminate an IPsec tunnel. If you have SASE gateway and remote access VPN services in the same organization, when you publish the VRF configuration, it publishes only to the remote access VPN,
Device Templates
An enterprise admin can clone the default template and save the configuration in a new template. You can add and publish the device template configuration to multiple devices that are associated with the template, an operation sometimes referred to as a mass publish. When you do this, the device Miscellaneous tab configuration is replaced with the template Miscellaneous tab configuration. You can perform a mass publish operation only for devices; you cannot use it to publish a configuration to SASE or to a multitenant gateway.
Default Configuration Templates
Versa Portal provides a default configuration. When you create a new site, Versa Portal populates the site's device configuration with the values from the default configuration. You can edit or clone the default template using the organization settings menu in the left menu bar in the Versa Portal dashboard. All sites created after you save the changes use the new values. You can select the new configuration template when you configure a new site.
You can edit defaults for networking and security. For more information, see Configure Security. Versa Portal uses only the settings that apply to a device.
Manage Device Templates
To clone a device template, you can use the clone template with devices option, and then you choose the topology. When you select a topology, all the devices associated with that topology are listed.
It is highly recommended that you do not delete or make changes to the WAN and LAN configuration from a device template, to avoid outages. Instead, perform these operations on the individual devices.
To edit or clone the default configuration template:
- Click Templates in the left menu bar to open the template settings dashboard, and select Device Template. The Device Templates section displays the following information.
Field Description Template Name Displays the name of the configuration template. # Devices Displays the number of devices using the template. Template Type Displays the default template's topology. Clone Click the Clone icon to clone the configuration to another template so that you can customize it. Delete Click the Delete icon to delete a custom template. You cannot delete a default template or a custom template that is associated with a device. Device List Click the Device List icon to view the devices that use the template. -
Click the Clone icon, and then enter information for the following fields.
Field Description Clone Option Select a clone option:
- Clone Template—Click to clone the configuration to another template without devices.
- Clone Template with Devices—Click to clone the configuration to another template with devices.
Template Name Enter a name for the template. Template Type Select a template type. A full-mesh template device can be cloned into any topology. If you clone any other topology, such as spoke, it is cloned as a spoke. - Full Mesh
- HA (HA with Full Mesh)
- HA with Hub
- HA with Spoke
- Hub
- Hub Controller
- Spoke
- Cross Connect Port
For HA, HA with Hub, and HA with Spoke topologies, select the HA cross-connect port. You must select the same HA cross-connect port that is used in the HA site configuration. Devices For Clone Template with Devices option, select the devices to copy with the template, and then click Continue. The devices are listed based on the template type (topology) selected, and a template with the device list selected is created.
- Click the Device List icon to view the devices that use the template. Use the search option to search by device name. In the device list, the device names shown in black are deployed devices and the device shown in blue are activated devices.
Click the Show Failed/Republish toggle to display the devices if a publish operation failed for any device. For failed devices, click the device checkbox and then click the Republish button to publish the configuration again.
Publish Device Template Configuration to Multiple Devices
To publish a device template configuration to multiple devices:
- In the Templates tab, select the device template.
- In the Configuration > Network screen, click the down arrow next to Save to display the Publish option, and then click Publish.
- In the Device List popup window, select the devices, or click Select All to select all the devices associated with the template, and then click Validate.
- In the Configuration Validation popup window, check that all devices are listed, and then click Continue.
- Click the icon to download the CSV file and check the validation message for all devices.
- Click Preview to view the configuration in each device.
- If the Validation Status column shows any conflict found message, the publish task is skipped for the device.
- Click Yes to save the configuration changes in the template.
- Check the blue dot next to the device icon to display the publish status. The blue dot disappears after the task is completed. Use the Refresh icon next to the Device List column to check the publish status. If the publish failed on a devices, the blue dot changes to a red dot. To view the failed devices, click the Device icon, and then click the Show Failed/Republish toggle. For failed devices, click the device checkbox and then click the Republish button to publish the configuration again.
- Click the Tasks icon to track the publish status for each device.
Service Templates
Service templates allow you to configure application-steering, NGFW, and secure access properties for Versa Portal instances. After you create a service template, you associate it with a device template.
You can use the service template to make mass configuration changes. The changes are not stored in the service template after publishing. The device list is initially empty, and devices appear once you have published. To see the updated device list, reload the device list or refresh the page.
Customers can configure any number of devices in their environment with a one-time service template configuration and publish the configuration to multiple devices. To track the publish status for each device, click the Tasks icon at the top of Versa Portal dashboard.
Create a Service Template
- Click Templates in the left menu bar to open the template settings dashboard, and then select Service Template. The Service Template screen displays.
- Click the service template name, and then make required changes to the default service template configuration.
- Click Publish.
- Click the Device List icon to view the devices that use the template. Use the search option to search by device name. The device names shown in black are deployed devices and the device shown in blue are activated devices.
Configure WAN Interfaces
Initially, the service template has one WAN interface in the zone list. If you have more than one WAN interface, the WAN interfaces are listed in the Objects: WAN Networks section.
- To edit a WAN interface, click the Edit icon to update the WAN interface, and then click Update to save the changes.
- To delete a WAN interface, click the icon.
To add a WAN interface:
- Click the icon and enter information for the following fields.
Field Description WAN Name (Required) Enter a name for the WAN interface. This WAN interface will list in the zone selection for all rules. HA Select HA to add the WAN interface to an HA device. PPPoE Select PPPoE to add the WAN interface to a PPPoE device. Description Enter a text description for the WAN interface.
When you add a WAN port, if the device is not an HA or a PPPoE device, enter the WAN name and click Add. If you add a WAN port for HA or for PPPoE, you must select the type of device. - Click Add.
Versa Secure Access Templates
For a Versa Secure Access (VSA) or remote access VPN template, you can view the template name, number of devices, and the devices that use the template. Click the VSA or remote access VPN template name to configure the VSA service for the organization. To configure VSA service, see Configure a Secure Access Service (Remote Access VPN) Template.
The VSA template screen also provides the link to download Versa secure access client application for Windows, MAC, and Linux operating systems and validate the secure access connection. To copy the Portal FQDN and enterprise name of the secure access client, click the Copy icon parallel to each field.
You can retrieve the following information and perform the following tasks:
- Template Name—Displays the name of the default configuration template.
- # Devices—Displays the number of devices using the template.
- Device List—Click the Device List icon to list the devices that use the template. Use the search option to search with the device name. Click Continue.
The red Caution icon indicates that the device has failed to publish any updates. You can click the device checkbox only if the publish has failed for any of the devices. You can click the checkbox and then click the Republish button to publish the configuration again.