All Products
Search
Document Center

Smart Access Gateway:Network configuration

Last Updated:Apr 01, 2026

Configure the network for a Smart Access Gateway (SAG) App instance to allow clients to connect to Alibaba Cloud.

Prerequisites

Before you begin, make sure that you have:

  • Purchased a SAG App instance as an administrator

  • Determined whether Quick Configuration has been applied to the instance — this determines which entry point you use in Step 4

Configure the network

  1. Log on to the SAG console.

  2. In the left-side navigation pane, choose Smart Access Gateway App > SAG App Instances.

  3. In the top navigation bar, select the target region.

  4. On the SAG App Instances page, find the target instance and open the network configuration:

    • Quick Configuration not yet applied: In the CCN Instance ID/Name column, click Network Configuration.

    • Quick Configuration already applied: In the Actions column, click Network Configuration.

  5. Set the following parameters.

    ParameterDescription
    Instance Name/IDThe name and ID of the SAG App instance.
    Resource GroupThe resource group to which the Cloud Connect Network (CCN) instance belongs. This resource group is created in Resource Management under your Alibaba Cloud account. For more information, see Create a resource group.
    Note

    This parameter appears only when Quick Configuration is not used.

    CCNThe CCN instance to attach. CCN is an important component of SAG. After you attach a CCN instance, clients associated with the SAG App instance can communicate with other gateway devices on the same CCN. For more information, see Introduction to Cloud Connect Network. Select one of the following options:
    • Existing CCN: Click the text box and select an existing CCN instance in the current region.
    • Create CCN: Enter a name for a new CCN instance. The system creates the CCN instance in the current region and attaches it automatically.
    Standby and Active DNSOptional. The primary and secondary DNS servers for clients connecting to the private network. After you configure the DNS servers, the system pushes the configuration to all clients automatically. See DNS configuration notes for platform requirements and known issues.
    Private CIDR BlockThe private CIDR block from which the system assigns IP addresses to connecting clients. Make sure private CIDR blocks do not overlap. Click Add Private CIDR Block to add more blocks. You can configure up to 11 private CIDR blocks. For example: 192.168.10.0/24.
  6. Click OK.

DNS configuration notes

The following platform requirements and known issues apply when you use the Standby and Active DNS parameter.

How DNS configuration works:

  • The system automatically pushes the DNS configuration to all clients.

  • If clients need Internet access, the configured DNS servers must be able to resolve public domain names.

  • To use PrivateZone when clients connect to Alibaba Cloud, set the DNS addresses to 100.100.2.136 and 100.100.2.138. For more information, see What is PrivateZone?.

Platform support and known issues:

PlatformMinimum versionNotes
Android2.1.1
macOS2.1.1After configuring DNS, go to System Preferences > Security & Privacy and deselect Require an administrator password to access system-wide preferences. This allows the client to write the DNS configuration to your system.
iOS 13The system may retain the default DNS configuration after you set a custom DNS. If the custom DNS does not take effect, exit the client and reconnect to Alibaba Cloud.

To download the client, see Install the client.

What's next

After completing network configuration, clients can connect to Alibaba Cloud through the SAG App instance. To modify the DNS servers or private CIDR blocks later, return to the SAG App Instances page and click Network Configuration in the Actions column.