Provision a New Edge
To create a new Edge, perform the following steps:
- In the SD-WAN service of the Enterprise portal, go to Configure > Edges .
- On the Edges screen, click Add Edge. The Provision an Edge screen appears.
Figure 1. Provision an Edge 
- Users can configure the following options:
Table 1. Provision an Edge - Options and Descriptions Option Description Mode By default, SD-WAN Edge mode is selected. Name Enter a unique name for the Edge. Model Select an Edge model from the drop-down menu. Profile Select a Profile to assign to the Edge from the drop-down menu. For information on creating a new Profile, see Create a Profile. If the system displays an Edge Staging Profile due to Edge Auto-activation, it indicates that a newly assigned Edge is currently using this profile and that the user has not yet configured it with a Production Profile. Edge License Select an Edge license from the drop-down menu. The list displays the licenses assigned to the Enterprise by the Operator. Authentication Choose the mode of authentication from the drop-down menu: - Certificate Deactivated: The system selects this mode by default. In this state, the Edge uses Pre-Shared Key (PSK) authentication to establish secure communication. If users change the mode from Certificate Deactivated to:
- Certificate Acquire: All tunnels are disconnected and reconnected based on the RSA mode.
- Certificate Required: The Orchestrator does not allow this change to be made directly. Users must first change the mode to Certificate Acquire, and then change it to Certificate Required. This helps avoid heartbeat loss to the Orchestrator when Edge is assigned a certificate.
Warning: VeloCloud SD-WAN do not recommend this mode for any customer deployments. - Certificate Acquire: In this mode, certificates are issued at Edge activation and renewed automatically. The Orchestrator instructs the Edge to acquire a certificate from the Orchestrator's certificate authority by generating a key pair and sending a certificate signing request to the Orchestrator. After acquisition, the Edge uses the certificate for authentication with the Edge Cloud Orchestrator and for establishing VCMP tunnels. If users change the mode from Certificate Acquire to:
- Certificate Deactivated: All tunnels are disconnected and reconnected based on PSK mode.
- Certificate Required: All tunnels continue to stay active, and no disruption is seen in the traffic.
Note: After acquiring the certificate, the option can be updated to Certificate Required, if needed. - Certificate Required: This mode is only appropriate for customer enterprises that are "static". The system defines a static enterprise as one where users likely deploy only a few new Edges and do not anticipate any new PKI-oriented changes. This mode does not allow peers with a pre-shared key to connect.
Important: Certificate Required has no security advantages over Certificate Acquire. Both modes are equally secure, and a customer using Certificate Required should do so only for the reasons outlined in this section.
- Certificate Required mode means that no Edge heartbeats are accepted without a valid certificate.
CAUTION: Using this mode can cause Edge failures when a customer is unaware of this strict enforcement.With this mode, the Edge uses the PKI certificate. Operators can change the certificate renewal time window for Edges by editing the Orchestrator's System Properties. For more information, contact the Operator.
Note:- When a user enables the Bastion Orchestrator feature, they must set the Authentication Mode to either Certificate Acquire or Certificate Required for any Edges they plan to stage.
- When the user revokes an Edge certificate, the system deactivates the Edge and requires it to undergo reactivation. The current QuickSec design checks the time validity of the certificate revocation list (CRL). The CRL time validity must match the current time at Edges for the CRL to affect a newly established connection. To implement this, ensure the Orchestrator time is properly updated to match the Edges' date and time.
Encrypt Device Secrets Select the Enable checkbox to activate Edge encryption across all platforms. This option is also available on the Edge Overview page. For additional information, see View Edge Information. Note: For Edge versions 5.2.0 and later, before users deactivate this option, users must first deactivate the Edge using remote actions. This causes Edge to restart.High Availability Select the Enable checkbox to apply High Availability (HA). Edges can be installed as a single standalone device or paired with another Edge to support HA. For additional information about HA, see the High Availability Deployment Models section. Local Contact Name Enter the name of the site contact for the Edge. Local Contact Email Enter the email address of the site contact for the Edge. - Certificate Deactivated: The system selects this mode by default. In this state, the Edge uses Pre-Shared Key (PSK) authentication to establish secure communication. If users change the mode from Certificate Deactivated to:
- Enter all the required details and click Next to configure the following additional options:
Note: The Next button is activated only when users enter all the required details.
Table 2. Additional Options and Descriptions Option Description Serial Number Enter the serial number of the Edge. If specified, the Edge must display this serial number on activation. When deploying virtual VeloCloud SD-WAN Edges on AWS Edges, ensure users use the instance ID as the Edge's serial number. Description Enter an appropriate description. Location Click the Set Location link to set the Edge's location. If not specified, the location is auto-detected from the IP address when the Edge is activated. - Select Add Edge. The Edge gets provisioned with an activation key.
Note: If the user does not activate the Edge using the provided Activation Key, it will expire after one month. For information on how to activate an Edge, see the Configure Edge Activation section in the Edge Activation Quick Start Guide.After users have provisioned an Edge, the Edge appears on the Edges screen.
- If users have configured the Edge 510-LTE device or the 610-LTE device (version 4.2.0 release), users can run the LTE Modem Information diagnostic test. This test will retrieve diagnostic information, such as signal strength, connection information, and so on. For information on running a diagnostic test, see Testing and Troubleshooting.
- To manage the provisioned Edges, see Manage Edges.
- To view Edge details or to make any changes to the Edge, see View Edge Information.
- To configure an Edge, see Configure Device Settings for Edges.
