If your business resources are deployed outside Alibaba Cloud and you already use an Alibaba Cloud Virtual Border Router (VBR), Cloud Connect Network (CCN), or VPN Gateway, you can use a SASE gateway to connect your on-premises network to those resources, allowing users to access them as internal resources.
Manage multi-account resources
To manage connector resources in a member account, first add the account. After the account is added, the SASE tab displays all VBR, IPsec-VPN, and Smart Access Gateway (SAG) resources from the management account and any added member accounts. If no member accounts are added, only resources from the management account are displayed. For more information, see multi-account management.
Network connection diagram
Enable network connection
Step 1: Synchronize cloud network instances
SASE automatically synchronizes your cloud network instances. The following table describes the fields displayed after synchronization:
|
Parameter |
Description |
|
Connector Type |
SASE supports three types of connectors: Virtual Border Router (VBR), Cloud Connect Network (CCN), and VPN Gateway. |
|
Instance ID/Name |
The ID of the connector instance, such as a VBR, VPN Gateway, or CCN instance. |
|
Owner Account |
The account that owns the connector, either the management account or a member account. |
|
Network Channel |
The network channel used by the connector. For VBR, the network channel is Leased Line; for CCN, the network channel is SAG; and for VPN Gateway, the network channel is IPsec-VPN. |
|
Internal CIDR Block |
The internal CIDR block of your on-premises network or the vSwitch CIDR block of your VPC.
Separate multiple CIDR blocks with a comma (,). |
Step 2: Configure a back-to-origin VPC
A back-to-origin VPC is a VPC that is already connected to your on-premises network through a SAG instance, an IPsec-VPN connection, or a Leased Line. SASE routes traffic through this VPC back to your on-premises resources.
-
For an IPsec-VPN (VPN Gateway) connector, the back-to-origin VPC is fixed because only one VPC can be connected to the on-premises network.
-
For a VBR connector, you must manually set the back-to-origin address in the Back-to-origin VPC column.
-
For a CCN connector, click Select Back-to-origin VPC in the Operation column to configure the back-to-origin VPC.
NoteAlthough all VPCs within a CCN instance can technically connect to the on-premises network, you may have routing or security policies that restrict access. Select only the VPC permitted to reach the on-premises network.
Step 3: Enable network connection
On the Cloud Network Instance tab, find the target instance and turn on the Network Connection switch. This allows SASE users to access Services Outside Alibaba Cloud.
Disable network connection
If you no longer need a network channel, turn off its Network Connection switch.
Turning off the Network Connection switch for a VBR, IPsec-VPN, or SAG connector will prevent users from accessing internal applications through the SASE App. Proceed with caution.
Next steps
After you enable network connection, configure which office applications users can access. For more information, see Configure an office application and Configure a zero trust policy.
Related documents
-
To allow traffic from specific IP addresses after you configure an application, set up an application whitelist. For more information, see Configure an application whitelist.
-
If your business applications are deployed on Alibaba Cloud network resources, see Connect to services on Alibaba Cloud.
-
To support global office scenarios, see Connect to applications for global offices.