Connection with SASE (Connection Method: Select)
For the target services, please refer to the Overview of XaaS Connection.
Problem to Solve
Accessing SASE / security services through the OCX private network.
Solution with OCX
By using XaaS Connection, you can connect to SASE / security services without creating an IPsec Parameter.
If an IPsec tunnel or agent is required to connect to the SASE / security service, please configure it in your environment (CPE or client device) based on the configuration information provided by the service provider.
OCX Resources
| Resource | Required Quantity | Required Quantity (East-West Redundant) |
|---|---|---|
| Physical Port | 2 | 2 |
| VCI | 2 | 2 |
| XaaS Connection | 1 | 2 |
| Virtual Circuit (VC) | 5 ※1 | 6 ※1 |
| OCX-Router (v1) | 1 (Consisting of 2 instances) | 1 (Consisting of 2 instances) |
| Interface (Router Connection) | 8 ※1 | 8 ※1 |
| Internet Gateway | 1 ※1 | 1 ※1 |
※1 If your environment already has internet connectivity, the required quantity is reduced.
Structure
Configuration Diagram (Via Application)

Configuration Diagram (Via Application, East-West Redundant)

Configuration Diagram (Via IPsec)

Configuration Diagram (Via IPsec, East-West Redundant)

Benefits
- Provides stable connectivity to SASE / security services and optimizes network traffic.
- Simplifies configuration by centralizing BGP settings on the OCX-Router (v1).
- Enhances communication redundancy to SASE / security services by implementing an East-West (Tokyo-Osaka) redundant configuration.
- When the service provider offers a dedicated application (agent), you can use it to connect.
Notes
- Ensure that AS numbers and network segments do not overlap in your design.
- When connecting via IPsec, IPsec tunnel termination must be configured on the customer's equipment.
- For terms and conditions regarding the use of each service, please contact the respective service provider.
- For details about the connection destination service, please refer to the creation page for each service.
- An East-West redundant configuration is required to meet the SLA standards for XaaS Connection. For SLA applicability of each service, please refer to the Overview of XaaS Connection.
- Some services may be out of SLA scope or may not support East-West redundant configurations.