The Secure Access Service Edge (SASE) Global Office feature provides secure cross-border access for employees who use the SASE client. Supported scenarios include employees outside the Chinese mainland accessing overseas business resources, employees outside the Chinese mainland accessing applications in the Chinese mainland, and employees in the Chinese mainland accessing overseas business resources. CombineSASE with your private cross-border leased line to build a secure global office solution.
How it works
The SASE Global Office feature is based on SASE. When your employees are outside the Chinese mainland, administrators can define an access route that uses a specific POP cluster, a SASE connector, and your private cross-border leased line to build a secure global office network. When your employees are in the Chinese mainland, the SASE client uses intelligent routing to connect through available POP clusters. Therefore, you only need to create a SASE connector in the Chinese mainland region where your business applications are hosted.
The following cross-border access scenarios and network topologies are supported:
-
Employees outside the Chinese mainland accessing overseas business resources
-
Employees outside the Chinese mainland accessing business resources in the Chinese mainland
-
Employees in the Chinese mainland accessing overseas business resources
Prerequisites
-
You have activated the Advanced edition of SASE Private Access. For more information, see Billing Overview.
-
Your enterprise has a private cross-border leased line from a carrier that supports route connectivity between the two office locations.
-
You have created a SASE connector. For more information, see Enable network connections for services not on Alibaba Cloud.
To minimize network latency, employees must connect to the nearest SASE POP cluster. Therefore, the SASE connector you create must be associated with the POP cluster closest to your office location.
Procedure
Step 1: Enable the Global Office feature
When you enable the Global Office feature, the system synchronizes application management and SASE configurations to overseas SASE POP clusters. This allows employees outside the Chinese mainland to authenticate through the nearest SASE server.
-
Log on to the SASE console.
-
In the left-side navigation pane, choose .
-
On the Global Office tab, click Authorization Management.
-
In the Authorization Management dialog box, turn on the switch for the Global Office feature and select the authorized overseas SASE POP clusters.
The following overseas SASE POP clusters are supported:
-
POP Cluster (Singapore)
-
POP Cluster (Virginia)
-
POP Cluster (Silicon Valley)
-
Step 2: Create a dynamic route
An administrator creates a SASE in the SASE console and associates it with the enterprise's private cross-border leased line. The SASE connector establishes a network connection between the SASE POP clusters and the cross-border business network.
-
On the Global Office tab, click Create Route.
-
In the Create Route panel, configure the parameters as described in the following table.
Parameter
Description
Route Name
Enter a name for the route.
Route Description
Enter a description for the route.
Priority
Specify the route priority.
Routing Mode
Fixed to Private Leased Line.
NoteIn Private Leased Line mode, route connectivity between the two office locations is required.
Select Application
Select the applications for Private Access.
POP Access Point
Select the authorized POP access points.
Status
The route is active only when enabled.
-
Click Next, select the SASE connector instance that you created, and then click OK.
Next steps
Employees can log on to the SASE client, select the appropriate POP cluster access point, and access cross-border business applications. For more information, see Install and Log On to the SASE Client and Enable or Disable Security Protection for Private Access.
FAQ
SASE connectors and dynamic routing both can configure business applications. If the configured business applications are inconsistent, which applications can employees access?
Employees can access only the applications associated with the SASE. This is because dynamic routing has a higher priority than the SASE connector.