All Products
Search
Document Center

Secure Access Service Edge:Enable network connections for a global office

Last Updated:Jul 18, 2026

The Secure Access Service Edge (SASE) Global Office feature provides secure cross-border access for employees who use the SASE client. Supported scenarios include employees outside the Chinese mainland accessing overseas business resources, employees outside the Chinese mainland accessing applications in the Chinese mainland, and employees in the Chinese mainland accessing overseas business resources. CombineSASE with your private cross-border leased line to build a secure global office solution.

How it works

The SASE Global Office feature is based on SASE. When your employees are outside the Chinese mainland, administrators can define an access route that uses a specific POP cluster, a SASE connector, and your private cross-border leased line to build a secure global office network. When your employees are in the Chinese mainland, the SASE client uses intelligent routing to connect through available POP clusters. Therefore, you only need to create a SASE connector in the Chinese mainland region where your business applications are hosted.

The following cross-border access scenarios and network topologies are supported:

  • Employees outside the Chinese mainland accessing overseas business resources

  • Employees outside the Chinese mainland accessing business resources in the Chinese mainland

  • Employees in the Chinese mainland accessing overseas business resources

Prerequisites

  • You have activated the Advanced edition of SASE Private Access. For more information, see Billing Overview.

  • Your enterprise has a private cross-border leased line from a carrier that supports route connectivity between the two office locations.

  • You have created a SASE connector. For more information, see Enable network connections for services not on Alibaba Cloud.

    To minimize network latency, employees must connect to the nearest SASE POP cluster. Therefore, the SASE connector you create must be associated with the POP cluster closest to your office location.

Procedure

Step 1: Enable the Global Office feature

When you enable the Global Office feature, the system synchronizes application management and SASE configurations to overseas SASE POP clusters. This allows employees outside the Chinese mainland to authenticate through the nearest SASE server.

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Private Access > Network Settings.

  3. On the Global Office tab, click Authorization Management.

  4. In the Authorization Management dialog box, turn on the switch for the Global Office feature and select the authorized overseas SASE POP clusters.

    The following overseas SASE POP clusters are supported:

    • POP Cluster (Singapore)

    • POP Cluster (Virginia)

    • POP Cluster (Silicon Valley)

Step 2: Create a dynamic route

An administrator creates a SASE in the SASE console and associates it with the enterprise's private cross-border leased line. The SASE connector establishes a network connection between the SASE POP clusters and the cross-border business network.

  1. On the Global Office tab, click Create Route.

  2. In the Create Route panel, configure the parameters as described in the following table.

    Parameter

    Description

    Route Name

    Enter a name for the route.

    Route Description

    Enter a description for the route.

    Priority

    Specify the route priority.

    Routing Mode

    Fixed to Private Leased Line.

    Note

    In Private Leased Line mode, route connectivity between the two office locations is required.

    Select Application

    Select the applications for Private Access.

    POP Access Point

    Select the authorized POP access points.

    Status

    The route is active only when enabled.

  3. Click Next, select the SASE connector instance that you created, and then click OK.

Next steps

Employees can log on to the SASE client, select the appropriate POP cluster access point, and access cross-border business applications. For more information, see Install and Log On to the SASE Client and Enable or Disable Security Protection for Private Access.

FAQ

SASE connectors and dynamic routing both can configure business applications. If the configured business applications are inconsistent, which applications can employees access?

Employees can access only the applications associated with the SASE. This is because dynamic routing has a higher priority than the SASE connector.