打印

Access SD-WAN Edges Using Key-Based Authentication

This section provides details about enabling key-based authentication, adding SSH keys, and securely accessing Edges.
The Secure Shell (SSH) key-based authentication provides a secure and robust authentication method for accessing VeloCloud Edges. It provides a strong, encrypted verification and communication process between users and Edges. Using SSH keys eliminates the need to enter login credentials manually and automates secure access to Edges.
Note:
  • Both the Edge and the Orchestrator must be using Release 5.0.0 or later.
  • Users with Operator Business or Business Specialist account roles cannot access Edges using key-based authentication.

Perform the following tasks to access Edges using key-based authentication:

  1. Configure user privileges to securely access Edges. You must set the user access level to Basic. Configure the access level when you create a new user and modify it later. Ensure that you have the Superuser role to modify the user access level.
  2. Generate a new SSH key pair or import an existing SSH key. See Add an SSH Key.
  3. Enable key-based authentication to access Edges. See Enable Secure Edge Access for an Enterprise.
See the following topics:

Add an SSH Key

Using key-based authentication to access Edges generates a pair of SSH keys - Public and Private.

Orchestrator stores the public key in the database and shares the key with Edges. Download the private key to your computer, and use it along with the SSH username to access Edges. You can generate only one pair of SSH keys at a time. If you need to add a new SSH key pair, you must delete the existing one and then generate a new one. If you lose a previously generated private key, you cannot recover it from the Orchestrator. You must delete the key and then add a new key to gain access. For details about how to delete SSH keys, see Revoke SSH Keys.

Based on their roles, users can perform the following actions:
  • All users, except users with Operator Business or Business Specialist account roles, can create and revoke SSH keys for themselves.
  • Operator Superusers can manage SSH keys for other Operator users, Partner users, and Enterprise users, if the Partner user and Enterprise user have delegated user permissions to the Operator.
  • Partner Super users can manage SSH keys of other Partner users and Enterprise users, if the Enterprise user has delegated user permissions to the Partner.
  • Enterprise Super users can manage SSH keys of all the users within that Enterprise.
  • Superusers can only view and revoke the SSH keys for other users.
    Note: Enterprise and Partner customers without SD-WAN service access cannot configure or view SSH key-related details.

To add a SSH key:

  1. In the Orchestrator, select User to display the User Information panel.
  2. Select Add SSH Key. Add SSH Key appears.
  3. Select one of the following options to add the SSH key:
    Generate Key: Use this option to generate a new pair of public and private SSH keys. Note that the generated key downloads automatically. The SSH key generates in the default file format .pem. If using Windows, ensure that you convert the file format from .pem to .ppk, and then import the key. For instructions to convert .pem to .ppk, see Convert Pem to Ppk File Using PuTTYgen.
    • Import Key: Use this option to paste or enter the public key if you already have a SSH key pair.
  4. In the PassPhrase field, enter a unique passphrase to further safeguard the private key stored on your computer.
    Note: This is optional and only available only if you have selected the Generate Key option.
  5. From the Duration list, select the number of days to keep the SSH key active.
  6. Select Add Key.
Ensure that you enable secure Edge access for the Enterprise and switch the authentication mode from Password-based to Key-based. See Enable Secure Edge Access for an Enterprise.

Revoke SSH Keys

Ensure you have a Superuser role to delete the SSH key pair for other users.

To revoke your SSH key:

  1. In the Orchestrator, select the User. The User Information panel appears.
  2. Select Revoke SSH Key.
  3. To revoke the SSH keys of other Partner users:
    1. In the Partner portal, go to Partner Settings > Authentication .
    2. In the SSH Keys area, select the SSH usernames to delete the SSH keys.
    3. Select Revoke SSH Key.
    The SSH keys for a user automatically delete when the following events occur:
    • The user role changes to Operator Business or Business Specialist. These roles cannot access Edges using key-based authentication.
    • Delete a user from the Orchestrator.
      Note: When you delete or deactivate a user from external SSO providers, the user can no longer access the Orchestrator. But the user Secure Edge Access keys remain active until the user explicitly deletes from the Orchestrator. You must first delete the user from the IdP before deleting from the Orchestrator.

Enable Secure Edge Access for an Enterprise

After adding the SSH key, you must switch the authentication mode from Password-based, the default mode, to Key-based to access Edges using the SSH username and SSH key. When you create a new user, Orchestrator automatically creates the SSH username.

To enable Secure Edge Access:

  1. In the SD-WAN service of the Enterprise portal, go to Service Settings > Edge Management .
  2. Select Enable Secure Edge Access to allow the user to access Edges using Key-based authentication.
    Note:
    • Once you activate Secure Edge Access, you cannot deactivate it.
    • Only Operator users can enable secure Edge access for an Enterprise.
  3. Select Switch to Key-Based Authentication and confirm your selection.
    Note: Ensure that you have a Superuser role in order to switch the authentication mode.
Use the SSH keys to securely login to the Edge CLI and run the required commands. For additional information, see Secure Edge CLI Commands.

Secure Edge CLI Commands

Based on the configured Access Level, run the following CLI commands:

Note: Run the help <command name> to view a brief description of the command.
Table 1. CLI Commands
Commands Description Access Level = Basic Access Level = Privileged
Interaction Commands
help Displays a list of available commands. Yes Yes
pagination Paginates the output. Yes Yes
clear Clears the screen. Yes Yes
EOF Exits the secure Edge CLI. Yes Yes
Debug Commands
edgeinfo Displays the Edge hardware and firmware information. Yes Yes
seainfo Displays details about the user secure Edge access. Yes Yes
ping, ping6 Pings a URL or an IP address. Yes Yes
tcpdump Displays TCP/IP and other packets transmitted or received over a network attached to the Edge. Yes Yes
pcap Captures the packet data pulled from the network traffic and prints the data to a file. Yes Yes
debug Runs the debug commands for Edges. Run debug-h to view a list of available commands and options. Yes Yes
diag Runs the remote diagnostics commands. Run diag-h to view a list of available commands and options. Yes Yes
ifstatus Returns the status of all interfaces. Yes Yes
getwanconfig Returns the configuration details of all WAN interfaces. Use the logical names such as "GE3" or "GE4" as arguments to return the configuration details of that interface. Do not use the physical names such as "ge3" or "ge4" of the WAN interfaces. For example, run getwanconfig GE3 to view the configuration details of the GE3 WAN interface. Run the ifstatus command to understand the interface name mappings. Yes Yes
Configuration Commands
setwanconfig Configures WAN interfaces (wired interfaces only). Run setwanconfig -h to view configuration options. Yes Yes
Edge Actions Commands
deactivate Deactivates the Edges and reapplies the initial default configuration. No Yes
restart Restarts the SD-WAN service. No Yes
reboot Reboots the Edge. No Yes
shutdown Powers off the Edge. No Yes
hardreset Deactivates the Edges, restores the Edge default configuration, and restores the original software version. No Yes
edged Activates or deactivates the Edge processes. No Yes
restartdhcpserver Restarts the DHCP server. No Yes
Linux Shell Commands
shell Takes you into the Linux shell. Type exit to return to the secure Edge CLI. No Yes
Note: For sample outputs of some of the commands that can be run in a secure Edge CLI, see Sample Outputs.

Sample Outputs

This section provides the sample outputs of some of the commands that can be run in a secure Edge CLI.

edgeinfo

o10test_velocloud_net:velocli> edgeinfo
Model:      vmware
Serial:     VMware-420efa0d2a6ccb35-9b9bee2f04f74b32
Build Version:  5.0.0
Build Date: 2021-12-07_20-17-40
Build rev:  R500-20211207-MN-8f5954619c
Build Hash: 8f5954619c643360455d8ada8e49def34faa688d

seainfo

o10test_velocloud_net:velocli> seainfo
{
  "rootlocked": false,
  "seauserinfo": {
    "o2super_velocloud_net": {
      "expiry": 1641600000000,
      "privilege": "BASIC"
    }
  }
}

tcpdump

o10test_velocloud_net:velocli> tcpdump -nnpi eth0 -c 10
reading from file -, link-type EN10MB (Ethernet)
09:45:12.297381 IP6 fd00:1:1:2::2.2426 > fd00:ff01:0:1::2.2426: UDP, length 21
09:45:12.300520 IP6 fd00:ff01:0:1::2.2426 > fd00:1:1:2::2.2426: UDP, length 21
09:45:12.399077 IP6 fd00:1:1:2::2.2426 > fd00:ff01:0:1::2.2426: UDP, length 21
09:45:12.401382 IP6 fd00:ff01:0:1::2.2426 > fd00:1:1:2::2.2426: UDP, length 21
09:45:12.442927 IP6 fd00:1:1:2::2.2426 > fd00:ff01:0:1::2.2426: UDP, length 83
09:45:12.444745 IP6 fd00:ff01:0:1::2.2426 > fd00:1:1:2::2.2426: UDP, length 83
09:45:12.476765 IP6 fd00:ff01:0:1::2.2426 > fd00:1:1:2::2.2426: UDP, length 64
09:45:12.515696 IP6 fd00:ff02:0:1::2.2426 > fd00:1:1:2::2.2426: UDP, length 21

pcap

o10test_velocloud_net:velocli> pcap -nnpi eth4 -c 10
The capture will be saved to file o10test_velocloud_net_2021-12-09_09-57-50.pcap
o10test_velocloud_net:velocli> tcpdump: listening on eth4, link-type EN10MB (Ethernet), capture size 262144 bytes
10 packets captured
10 packets received by filter
0 packets dropped by kernel

debug

o10test_velocloud_net:velocli> debug --dpdk_ports_dump
name         port  link  ignore  strip  speed  duplex  autoneg  driver
ge3             0     1       0      1   1000       1        1     igb
ge6             4     0       2      1      0       0        1   ixgbe
ge5             5     0       2      1      0       0        1   ixgbe
ge4             1     0       2      1      0       0        0     igb
sfp2            2     0       2      1      0       0        1   ixgbe
sfp1            3     0       2      1      0       0        1   ixgbe
net_vhost0      6     0       0      1  10000       1        0        
net_vhost1      7     0       0      1  10000       1        0

diag

o10test_velocloud_net:velocli> diag ARP_DUMP --count 10
Stale Timeout: 2min | Dead Timeout: 25min | Cleanup Timeout: 240min 
GE3                  
192.168.1.254        7c:12:61:70:2f:d0    ALIVE                1s                   

LAN-VLAN1            
10.10.1.137          b2:84:f7:c1:d3:a5    ALIVE                34s

ifstatus

o10test:velocli> ifstatus
{
  "deviceBoardName": "EDGE620-CPU",
  "deviceInfo": [],
  "edgeActivated": true,
  "edgeSerial": "HRPGPK2",
  "edgeSoftware": {
    "buildNumber": "R500-20210821-DEV-301514018f\n",
    "version": "5.0.0\n"
  },
  "edgedDisabled": false,
  "interfaceStatus": {
    "GE1": {
      "autonegotiation": true,
      "duplex": "Unknown! (255)",
      "haActiveSerialNumber": "",
      "haEnabled": false,
      "haStandbySerialNumber": "",
      "ifindex": 4,
      "internet": false,
      "ip": "",
      "is_sfp": false,
      "isp": "",
      "linkDetected": false,
      "logical_id": "",
      "mac": "18:5a:58:1e:f9:22",
      "netmask": "",
      "physicalName": "ge1",
      "reachabilityIp": "8.8.8.8",
      "service": false,
      "speed": "Unkn",
      "state": "DEAD",
      "stats": {
        "bpsOfBestPathRx": 0,
        "bpsOfBestPathTx": 0
      },
      "type": "LAN"
    },
    "GE2": {
      "autonegotiation": true,
      "duplex": "Unknown! (255)",
      "haActiveSerialNumber": "",
      "haEnabled": false,
	…
	…
   }
  ]
}

getwanconfig

o10test_velocloud_net:velocli> getwanconfig GE3
{
  "details": {
    "autonegotiation": "on",
    "driver": "dpdk",
    "duplex": "",
    "gateway": "169.254.7.9",
    "ip": "169.254.7.10",
    "is_sfp": false,
    "linkDetected": true,
    "mac": "00:50:56:8e:46:de",
    "netmask": "255.255.255.248",
    "password": "",
    "proto": "static",
    "speed": "",
    "username": "",
    "v4Disable": false,
    "v6Disable": false,
    "v6Gateway": "fd00:1:1:1::1",
    "v6Ip": "fd00:1:1:1::2",
    "v6Prefixlen": 64,
    "v6Proto": "static",
    "vlanId": ""
  },
  "status": "OK"
}
..