Provision an Edge
Ensure you have the Orchestrator host name and admin account to login.
To provision an Edge, perform the following steps:
- Log into the Orchestrator application as Admin user, with your login credentials.
- Go to Configure > Edges .
- In the Edges screen, select Add Edge.
The Provision an Edge screen displays.
Figure 1. Provision an Edge 
- You can configure the following options:
Table 1. Option Descriptions Option Description Mode SD-WAN Edge mode selected by default. Name Enter a unique name for the Edge. Model Select Virtual Edge from the menu. Profile Select Quick Start Profile from the menu. Note: If an Edge Staging Profile is displayed as an option due to Edge Auto-activation, it indicates that this Profile is used by a newly assigned Edge, but has not been configured with a production Profile.Edge License Select an Edge license from the menu. The list displays the licenses assigned to the Enterprise, by the Operator. Authentication Choose the mode of authentication from the drop-down menu: - Certificate Deactivated: In this mode, the Edge uses Pre-Shared Key (PSK) authentication to establish secure communication to the Hub/Gateways/Orchestrator.
Warning: VeloCloud SD-WAN does not recommend this mode for any customer deployments.If users change the mode from Certificate Deactivated to:
- Certificate Acquire: All tunnels are disconnected and reconnected based on the RSA mode.
- Certificate Required: The Orchestrator does not directly allow this change. Users must first change the mode to Certificate Acquire and then to Certificate Required. This helps avoid heartbeat loss to the Orchestrator when Edge is assigned a certificate.
- Certificate Acquire: In this mode, certificates are issued at Edge activation and automatically renewed. The Orchestrator instructs the Edge to acquire a certificate from the Orchestrator's certificate authority by generating a key pair and sending a certificate signing request to the Orchestrator. After acquisition, the Edge uses the certificate for authentication with the Orchestrator and for establishing VCMP tunnels.
If users change the mode from Certificate Acquire to:
- Certificate Deactivated All tunnels are disconnected and reconnected based on PSK mode.
- Certificate Required For Edges/Gateways running versions older than 6.1.x, switching from Certificate Acquire to Certificate Required causes a tunnel flap. Edges/Gateways running version 6.1.x or newer will not experience a tunnel flap.
When a Hub enters Certificate Acquire mode, it reestablishes certificate-based tunnels using a new certificate while leaving PSK-based tunnels unaffected.
Note: After acquiring the certificate, VeloCloud SD-WAN recommends updating this option to Certificate Required. This is to prevent Hubs/Gateways from accepting tunnel requests using PSK. - Certificate Required: This is the recommended mode. This mode does not allow peers with a PSK to connect. This mode does not accept Edge heartbeats without a valid certificate.
If users change the mode from Certificate Required to:
- Certificate Deactivated: VeloCloud SD-WAN does not recommend transitioning the Edge’s authentication mode to Certificate Deactivated.
- Certificate Acquire: An Edge that has been offline for an extended period after activation may be unable to connect to the Orchestrator when it tries to bring itself online if its certificate has expired or it never acquired one. In Certificate Required mode, the Orchestrator rejects connections from Edges without a valid certificate. Reactivation is not required for such cases. The Edge can be brought back online by temporarily switching it to Certificate Acquire mode to obtain a new certificate.
Recovery Procedure:
- Verify with the Enterprise administrator that they expect the Edge to come back online.
- Move the Edge to Certificate Acquire mode in the Orchestrator.
- Turn on or reconnect the Edge. This will connect to the Orchestrator and acquire a new certificate.
- Confirm in the Orchestrator that the Edge has a valid certificate and is establishing tunnels.
- Switch the Edge back to Certificate Required mode.
Encrypt Device Secrets Select Enable to allow the Edge to encrypt the sensitive data across all platforms. This option is also available on the Edge Overview page. Note: For Edge versions 5.2.0 and above, before you deactivate this option, you must first deactivate the Edge using remote actions. This causes restart of the Edge.High Availability Select Enable to apply High Availability (HA). Edges can be installed as a single standalone device or paired with another Edge to provide High Availability (HA) support. Local Contact Name Enter the name of the site contact for the Edge. Local Contact Email Enter the email address of the site contact for the Edge. - Certificate Deactivated: In this mode, the Edge uses Pre-Shared Key (PSK) authentication to establish secure communication to the Hub/Gateways/Orchestrator.
- Enter all the required details and select Next to configure the following additional options:
Note: The Next button is activated only when you enter all the required details.
Table 2. Additional Option Descriptions Option Description Serial Number Enter the serial number of the Edge. If specified, the Edge must display this serial number on activation. Note: When deploying virtual VeloCloud SD-WAN Edges on AWS Edges, make sure to use the instance ID as the serial number for the Edge.Description Enter an appropriate description. Location select the Set Location link to set the location of the Edge. If not specified, the location is auto-detected from the IP address when the Edge is activated. - Select Add Edge. The Edge is provisioned, and the activation key is displayed on the top of the page. Make a note of the activation key to use it for launching the Edge from the AliCloud Console.
Note: The activation key expires in one month if the Edge device is not activated against it.
- Configure Virtual Edge interfaces. The following steps are explained considering Topology A.
- Go to Configure > Edges . The Edges page displays the existing Edges.
- Select the link to an Edge or select the View link in the Device column of the Edge. The configuration options for the selected Edge are displayed in the Device tab.
- Go to the Interface Settings area.
- In the Connectivity category, expand Interfaces. Different types of Interfaces available for the selected Edge are displayed.
- Select the Override Interface check box, and then update configurations of Virtual Edge interfaces GE1 Interface, GE2 Interface, and GE3 Interface as follows:
- Change GE1 interface capability to Routed, and deactivate WAN Overlay and NAT Direct Traffic.
- Change GE2 interface capability to Routed and ensure WAN Overlay and NAT Direct Traffic are activated.
- For GE3 interface, deactivate WAN Overlay and NAT Direct Traffic, which will be the next hop for devices connected to Private VPC subnets (LAN devices).
Figure 2. Virtual Edge 
For additional information, see the topic Configure Interface Settings for Edges in the Arista VeloCloud SD-WAN Administration Guide.
- Select Save.
A Virtual Edge is provisioned on the Orchestrator.
Deploy the Virtual Edge on GCP. You can deploy the Virtual Edge by using one of the following methods:
