Learn how the private access feature works and how to quickly set it up after you enable SASE (Secure Access Service Edge).
Private access security
Private access is a SaaS-based zero-trust network access feature built on software-defined perimeter (SDP) technology. With the SASE private access solution, employees can securely reach cloud-based business resources over a private network while you manage their access permissions — without exposing public IP addresses or modifying the existing network architecture.
Procedure
Step 1: Configure an identity provider (IdP)
An identity provider (IdP) handles identity authentication for enterprise employees. SASE supports third-party and self-built authentication systems, including LDAP, DingTalk, WeChat Work, Feishu, IDaaS, and custom identity providers. If your business uses multiple IdPs, you can configure each one and enable its authentication status to use the SASE service with different IdPs.
To quickly test the feature, this topic uses a custom IdP as an example.
-
Log on to the SASE console.
-
In the left-side navigation pane, choose .
-
On the Identity synchronization tab, find the Custom IdP, click Actions in the Edit column, and follow the on-screen instructions to configure the custom IdP. For more information, see Connect to a custom identity provider.
-
On the User Group Management tab, click Create User Group.
-
In the Create User Group panel, configure information for the user group, such as Organizational Structure, Account Name, Email Address, and Mobile Phone Number. Then, click OK. For more information, see User group management.
Step 2: Configure a user group
When you configure a policy, you must specify the user group to which the policy applies.
-
In the navigation pane on the left, choose .
-
On the User Group Management tab, click Create User Group.
-
In the Create User Group pane, configure the Organizational Structure, Account Name, Email Address, and Mobile Phone Number for the user group. Then, click OK. For more information, see User Group Management.
Step 2: Configure a private application
In SASE, a private application represents an internal IT resource, such as an application, server, or database, that does not require a public IP address. To access a private application, employees must use a device with the SASE client installed and pass identity and security policy checks.
In the navigation pane on the left, choose .
-
On the Office Application page, in the Custom Tags section, click Add, set a tag name, and then click OK.
You can add up to 100 custom tags.
-
Click Add Application and configure the application by following these steps.
If you have a DNS server for resolving your enterprise's internal CIDR blocks, you can click Internal DNS Configuration. In the DNS Address dialog box, manually enter the Default DNS Service and Other DNS Services. The default DNS group (each DNS group can contain up to two DNS server IP addresses) is pushed to the SASE client as the primary enterprise DNS. Employees can switch DNS groups on the client to meet specific access requirements.
If you do not configure a DNS service, SASE automatically configures an Alibaba Cloud DNS server to resolve your enterprise's internal CIDR blocks. If Alibaba Cloud DNS PrivateZone is configured, it is prioritized for IP or domain name resolution.
-
On the Manual Configuration tab, configure the following parameters.
Parameter
Description
Example
Application Name
The name of the private application.
The name must be 1 to 128 characters in length and can contain Chinese characters, letters, digits, hyphens (-), underscores (_), and periods (.).
Attendance Management Application
Description
The description of the private application.
Attendance management address for employees
Tag
A custom tag for the application, which helps you classify, search for, and manage applications.
OA System
Status
The access status of the application. Valid values:
-
Enable: The application is available.
-
Disable: The application is unavailable.
Enable
-
-
Click Next and configure the following address and port information.
Parameter
Description
Example
Application Address
The private access address of the application. You can define applications or resources by using IP addresses, CIDR blocks, domain names, and wildcard domain names. Multiple private access addresses can be set for a single application.
10.10.1.100
Port
The port number or port range used by the application.
80-200
Protocol
The protocol of the application. Valid values: All Protocols, TCP, and UDP.
All Protocols
-
Step 3: Establish a network connection
Before you establish a network connection, confirm your current service deployment and select the appropriate connection solution.
Service deployment environment | Solution | Environment requirements |
Enterprise services and resources are deployed on Alibaba Cloud | Use the network configuration feature to establish network connections between specified Alibaba Cloud VPC resources and SASE end users. On the page, enable the network connection for the VPC where the target service server is located. | Requirements for office computers:
|
Enterprise services and resources are deployed in a non-Alibaba Cloud environment, such as AWS or Tencent Cloud, and an Alibaba Cloud Virtual Border Router (VBR), Cloud Connect Network (CCN), or VPN Gateway is already used for network connectivity. | Use Alibaba Cloud network channels, such as Leased Lines, SAG, or IPsec-VPN, to allow SASE clients to access service resources in non-Alibaba Cloud environments. On the tab, configure the origin fetch VPC and enable the network connection. | Requirements for office computers:
|
Enterprise services and resources are deployed in a non-Alibaba Cloud environment | SASE provides a connector feature that you can use to connect to your non-Alibaba Cloud network. This lets you use the SASE app to access services in the non-Alibaba Cloud environment. This method does not depend on other network products for network access. On the tab, manually add an SASE connector. Then, run commands to deploy the connector and ensure that the connector instance is enabled. | Requirements for office computers:
Server requirements for deploying the connector:
|
This topic uses business resources deployed in a non-Alibaba Cloud environment as an example.
-
In the left-side navigation pane, choose .
-
On the Network Settings page, click Services Outside Alibaba Cloud.
-
Add and deploy a connector.
-
On the Connectors tab, click Add Connector.
You can add up to five connectors.
-
In the Add Connector panel, configure the parameters based on your business requirements. Then, click OK.
Parameter
Description
Example
Region
The region of the connector. For optimal access quality, select the region closest to your server.
China (Beijing)
Instance Name
The name of the connector.
private-access-connector-for-company-A
Instance Switch
SASE end users can access applications associated with the connector only when the instance is Enable.
ImportantIf you disable the Instance Switch, end users cannot access private applications by using the SASE client. Proceed with caution.
Enabled
In the left-side navigation pane, choose Private Access > Network Configuration, and click the Non-Alibaba Cloud Services tab. In the Connector List section, you can view the added connector instances and their status, and add new connectors by clicking Add Connector.
-
-
Install and deploy the connector.
-
In the Actions column, click Deploy. In the Deploy panel, copy the deployment command for the connector.
curl -sSL https://sase-app.oss-cn-hangzhou.aliyuncs.com/connector.default.sh | ALIUID=1637xxxx0585 CODE=AE854025xxxxDB714E2C INSTANCE_ID=connector-09fcxxxxd8ba bash -
Log on to the server or virtual machine on which you want to deploy the connector as the root user and run the command.
-
Step 4: Create a zero trust policy
A zero trust policy controls access by mapping user groups to specific applications. By default, all access is denied. You must create Allow policies to grant users access to applications.
-
In the left-side navigation pane, choose .
-
On the Zero Trust Policies tab, click Create Policy.
-
In the Create Policy panel, configure the following parameters, and then click OK.
You can create an unlimited number of zero trust policies based on your business requirements.
Parameter
Description
Example
Policy Name
The name of the zero trust policy.
The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Allow policy for attendance app
Description
The description of the zero trust policy.
All users can access the attendance management application.
Priority
A number that determines the evaluation order. A lower number indicates a higher priority (1 is the highest). Policies are evaluated from highest to lowest priority.
If policies conflict, the policy with the higher priority takes effect.
1
Action
The action of the policy. Valid values:
-
Allow Access: The policy allows users or devices to access the specified application.
-
Access Denied: The policy denies users or devices from accessing the specified application.
Allow
Applicable User
The policy is applied to the endpoint devices of users in the specified user groups. SASE then allows or blocks matching access behaviors accordingly.
Click Add. On the User Group tab, select the user group to which the policy applies. If the current user groups do not meet your needs, you can configure a new one on the Custom User Group tab. For more information about how to configure user groups, see User group management.
All employees of the company
Selected Applications
The applications that are allowed or denied based on the Action setting.
Click Add. On the Tag tab, select the specified applications based on the configured tags. You can also select applications directly on the Application tab.
Attendance Management Application
Security Baselines
Select a security baseline template that meets your enterprise's requirements.
-
Policy Status
Set the status of the policy.
Enabled
-
Step 5: Verify the configuration
-
Open the SASE client that you have installed.
Enter the enterprise verification ID and click OK.
You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.
-
Log on by using the initial username and password that you received by email or phone.
-
Click Connect to Private Network.
-
Access the enterprise attendance management application.
If you can access the application, the configuration is successful.