Edge Management

Edge Management feature allows users to configure general settings, authentication, and encryption for an Edge. It allows users to activate or deactivate configuration updates for an Edge. Users can also select a default Software & Firmware Image.
  1. Log into the Orchestrator as a Partner.
  2. On the Partner portal, select Service Settings, and then select Edge Management.
  3. You can configure the following options and select Save Changes.
    Figure 1. Edge Management - Partner

     

    Table 1. Edge Management - Options and Descriptions
    Option Description
    General Edge Settings
    Edge Link Down Limit You can set this value for each Edge by selecting Customize. This overrides the value set through the system property edge.link.show.limit.sec.
    Number of days Enter a value in the range 1 to 365 with a default value of 1.
    Edge Authentication
    Default Certificate Select the default option to authenticate the Edges associated to the Customer.
    • Certificate Acquire - This option instructs the Edge to acquire a certificate from the certificate authority of the Orchestrator, by generating a key pair and sending a certificate signing request to the Orchestrator. Once acquired, the Edge uses the certificate for authentication to the Orchestrator and for the establishment of VCMP tunnels.
      Note: Only after acquiring the certificate, the option can be updated to Certificate Required.
    • Certificate Deactivated - This option instructs the Edge to use a pre-shared key mode of authentication.
    • Certificate Required - Selected by default, and it instructs the Edge to use the PKI certificate. Operators can change the certificate renewal time window for Edges using system properties. For additional information, contact your Operator.
    Note: After selecting Save Changes,confirm if the selected Edge authentication setting applies to all the impacted Edges or only the new Edges. By default, Apply to all Edges is selected.
    Edge Authentication Select Activate Secure Edge Accessto allow the user to access Edges using Password-based or Key-based authentication. You can activate this option only once. But you can switch to either Password-based or Key-based authentication any number of times.
    Device Secret Encryption
    Enable Encrypt Device Secrets Select Enable For All Edges to activate device secret encryption for all the Edges in the current Enterprise. This action causes restart of all the Edges. However, it does not affect Edges with this feature activated.
    Note: You can activate this option for individual Edges at the time of creating a new Edge. For additional information, see the topic Provision a New Edge in the Arista VeloCloud SD-WAN Administration Guide.
    Configuration Updates
    Disable Edge Configuration Updates Activated by default. This option allows you to actively push the configuration updates to Edges.
    Enable Configuration Updates Post-Upgrade Deactivated by default. This option allows you to control when post-Orchestrator upgrade configuration changes apply to their Edges. Enable it by selecting On.

     

  4. Software & Firmware Images: You can view the details of the listed images and select the default image.
    Note: To view this section:
    • An Operator must navigate to the Global Settings service of the Enterprise portal, then select Customer Configuration > SD-WAN Configuration . Select Allow Customer to manage software. Only an Operator can add, delete, or edit an image. For additional information, see the topic Platform Firmware and Factory Images, in the Arista VeloCloud SD-WAN Operator Guide.
    • A Partner user must navigate to Manage Partner Customers. Select More and perform the following options:
      • Select Update Edge Image Management. Turn on the toggle button, then select Save.
      • Select Assign Software/Firmware Image, then select a Software/Firmware image from the menu. Select Save.