打印

Edge Management

Edge Management feature allows users to configure general settings, authentication, and encryption for an Edge. It allows activation and deactivation of configuration updates for an Edge. Users can also select a default Software & Firmware Image.
  1. In the Operator portal, on the Monitor Customers screen, select on a Customer name.
  2. From the top menu, select Service Settings, and then from the left menu, select Edge Management.
  3. Configure the following options, and then select Save Changes.
    Figure 1. Edge Management

     

    Table 1. Edge Management - Options and Descriptions
    Option Description
    General Edge Settings
    Edge Link Down Limit Set this value for each Edge by selecting the Customize checkbox. This overrides the value set through the system property edge.link.show.limit.sec.
    Number of days Enter a value in the range 1 to 365. The default value is 1.
    Edge Authentication
    Default Certificate Choose the default option to authenticate the Edges associated to the Customer.
    • Certificate Acquire: This option instructs the Edge to acquire a certificate from the certificate authority of the Orchestrator, by generating a key pair and sending a certificate signing request to the Orchestrator. Once acquired, the Edge uses the certificate for authentication to the Orchestrator and for the establishment of VCMP tunnels.
      Note: The Orchestrator allows updates to Certificate Required only after the certificate is acquired.
    • Certificate Deactivated: This option instructs the Edge to use a pre-shared key mode of authentication.
    • Certificate Required: This is the default option, and it instructs the Edge to use the PKI certificate. Operators can change the certificate renewal time window for Edges using system properties. For additional information, contact your Operator.
    Note: When selecting Save Changes, the Orchestrator prompts the users to confirm whether the selected Edge authentication setting applies to all impacted Edges or only the new Edges. By default, the Orchestrator selects the Apply to all Edges checkbox.
    Edge Authentication Select the Activate Secure Edge Access button to allow the user to access Edges using Password-based or Key-based authentication. Activate this option only once. The Orchestrator supports switching between Password-based and Key-based authentication an unlimited number of times. For additional details, see Configure User Account Details.
    Device Secret Encryption
    Enable Encrypt Device Secrets Select the Enable For All Edges button to activate device secret encryption for all the Edges in the current Enterprise. This action causes restart of all the Edges. However, activated Edges maintain their current status without disruption.
    Note: Activate this option for individual Edges at the time of creating a new Edge. For additional information, see the topic Provision a New Edge in the Arista VeloCloud SD-WAN Administration Guide.
    Configuration Updates
    Disable Edge Configuration Updates By default, the Orchestrator activates this option. This option enables active pushing of configuration updates to Edges. Slide the toggle button to turn it off.
    Enable Configuration Updates Post-Upgrade By default, the Orchestrator deactivates this option. This option allows users to control the timing of post-Orchestrator upgrade configuration changes for their Edges. Slide the toggle button to turn it on.

Software & Firmware Images

To view this section, an Operator user must follow the below steps:
  1. Navigate to the Global Settings service of the Enterprise portal.
  2. Go to Customer Configuration > SD-WAN Configuration .
  3. Select the Allow Customer to manage software checkbox.
    Note: Only an Operator user can add, delete, or edit an image.
For additional information, see the topics Platform and Modem Firmware and Factory Images and Software Images.
..