Skip to main content

Connection with SASE (Connection Method: Select)

For the target services, please refer to the Overview of XaaS Connection.​

Problem to Solve​

Accessing SASE / security services through the OCX private network.

Solution with OCX​

By using XaaS Connection, you can connect to SASE / security services without creating an IPsec Parameter.
If an IPsec tunnel or agent is required to connect to the SASE / security service, please configure it in your environment (CPE or client device) based on the configuration information provided by the service provider.

OCX Resources​

ResourceRequired QuantityRequired Quantity (East-West Redundant)
Physical Port22
VCI22
XaaS Connection12
Virtual Circuit (VC)5 ※16 ※1
OCX-Router (v1)1 (Consisting of 2 instances)1 (Consisting of 2 instances)
Interface (Router Connection)8 ※18 ※1
Internet Gateway1 ※11 ※1

※1 If your environment already has internet connectivity, the required quantity is reduced.

Structure​

Configuration Diagram (Via Application)​

XaaS Connection Configuration Diagram (Via App)

Configuration Diagram (Via Application, East-West Redundant)​

XaaS Connection Configuration Diagram (Via App, East-West Redundant)

Configuration Diagram (Via IPsec)​

XaaS Connection Configuration Diagram (Via IPsec)

Configuration Diagram (Via IPsec, East-West Redundant)​

XaaS Connection Configuration Diagram (Via IPsec)

Benefits​

  • Provides stable connectivity to SASE / security services and optimizes network traffic.
  • Simplifies configuration by centralizing BGP settings on the OCX-Router (v1).
  • Enhances communication redundancy to SASE / security services by implementing an East-West (Tokyo-Osaka) redundant configuration.
  • When the service provider offers a dedicated application (agent), you can use it to connect.

Notes​

  • Ensure that AS numbers and network segments do not overlap in your design.
  • When connecting via IPsec, IPsec tunnel termination must be configured on the customer's equipment.
  • For terms and conditions regarding the use of each service, please contact the respective service provider.
  • For details about the connection destination service, please refer to the creation page for each service.
  • An East-West redundant configuration is required to meet the SLA standards for XaaS Connection. For SLA applicability of each service, please refer to the Overview of XaaS Connection.
  • Some services may be out of SLA scope or may not support East-West redundant configurations.