HPE SSE

Configuration > Cloud Services > HPE SSE

HPE SSE automates Secure Web Gateway (SWG) and SSE connector functionalities. SWG protects and governs internet-bound traffic, while the SSE connector enables secure, identity-based access to private applications.

NOTE: HPE SSE is not supported in air-gapped environments.

Click one of the following buttons to configure HPE SSE:

Secure Web Gateway

HPE Aruba Networking SSE is a cloud security service. EdgeConnect traffic can be service chained to HPE SSE for additional security inspection. Orchestrator supports IPSec tunnel mode for HPE SSE.

IMPORTANT: By default, the maximum limit is 100 tunnels per HPE SSE tenant. If you want to increase the limit, you must contact HPE Aruba Networking support for assistance.

The following table describes the fields on the Secure Web Gateway view of the HPE SSE tab.

Field Description
Appliance Name of the appliance to connect to HPE SSE.
Interface Label Interface label for the interfaces you want to connect to HPE SSE.
Location Physical location of the appliance to connect to HPE SSE.
HPE SSE POP IPs These are the HPE SSE endpoints to which the tunnels connect. This field is populated with discovered Public Service Edges based on the appliance’s geographical location.
HPE SSE Deployment Status Status of the HPE SSE deployment (Creating, Pending, or Deployed). Deployed indicates successful deployment.
Connection Status Status of the HPE SSE connection based on tunnel and IP SLA statuses.

Configure Secure Web Gateway

Before you configure HPE SSE, you must create an HPE SSE account and have an HPE SSE tenant provisioned. Contact HPE Networking support for assistance with provisioning an HPE SSE tenant.

Subscription

Complete the Subscription dialog box to establish connectivity between Orchestrator and the HPE SSE (Axis) portal. The subscription is shared by Secure Web Gateway and SSE Connector.

  1. In Orchestrator, navigate to Configuration > Cloud Services > HPE SSE.

  2. Click Subscription.

    The Subscription dialog box opens. Leave the dialog box open, so you can paste your HPE SSE API token key in the API Token Key field.

  3. In a new browser tab, go to https://auth.axissecurity.com/ and log in to your HPE SSE account.

  4. From the Dashboard, click Settings and then click Admin API.

    The Admin API page opens.

  5. Click New API Token.

    The New API Token dialog box opens.

  6. Enter a Name for the new API token. The name should identify your Orchestrator.

  7. Under Token Permissions, select Read and Write.

  8. Under Token Scopes, select only Tunnels and Locations.

  9. Under Token Expiration, enter 12.

  10. Click Submit.

    The New API Token dialog box opens and displays the token you created.

  11. Copy the token.

  12. In Orchestrator on the Subscription dialog box, paste the token into the API Token Key field.

  13. In your HPE SSE account after you have copied the token, click OK.

  14. In Orchestrator, enter the appropriate information in the remaining fields on the Subscription dialog box to reflect your HPE SSE account.

    The following table describes the fields.

    Field Description
    HPE SSE Indicates whether you are connected to your HPE SSE account.
    API token name Enter the name you assigned to the API token you created in your HPE SSE account.

    NOTE: The name should match exactly what you entered in the HPE SSE dashboard.
    API token key Enter (paste) the API token you created in your HPE SSE account. This token is used to access the HPE SSE APIs.
    API domain The domain name of the HPE SSE APIs that are used in tunnel creation. Leave the default setting.
    Tunnel identifier A unique identifier for the tunnel that is used when building the tunnel IKE identifiers. Enter the domain name for your company. For example, arubanetworks.com.
    Orchestrator identifier A unique identifier for the Orchestrator instance. This value is used to uniquely associate connectors created by this Orchestrator in the SSE (Axis) portal.

    By default, this is the configured hostname for the Orchestrator. You can change this to be any string, but it should be entered in the format of a hostname (containing no spaces or special characters).
    Polling interval Indicates how often Orchestrator should check for configuration changes in HPE SSE. The default polling interval is ten minutes.
  15. Click Save. The HPE SSE field should indicate Connected.

Interface Labels

Select the WAN interfaces you want to use for HPE SSE internet traffic. You can specify primary and backup interfaces as described below. If a primary interface is unavailable, Orchestrator will use a backup interface if specified. Optionally, you can specify secondary interfaces as well. In this case, the fallback order is primary, secondary, and then backup.

  1. On the HPE SSE tab, click Interface Labels.

    The Build HPE SSE Tunnels Using These Interfaces dialog box opens.

  2. Drag the interfaces you want to use from the right side of the dialog box to the Primary and Backup areas. The interfaces are grayed out until you move them into the areas.

  3. If you want to specify secondary interfaces, click Show Secondary to display the Secondary area, and then drag the appropriate interfaces to this area.

  4. Click Save.

WARNING: This is service affecting. Any changes to the interface selection can cause previously built tunnels to be deleted and rebuilt.

Tunnel Settings

The Tunnel Settings button opens the HPE SSE Tunnel Setting dialog box, enabling you to define the tunnels associated with HPE SSE and EdgeConnect. The Mode field on the General tab allows you to select IPSec as the tunnel protocol for the specified WAN interface label. Use HPE SSE defaults for tunnel settings defined by the system.

NOTE: You can configure General, IKE, and IPSec tunnel settings. Settings are automatically generated, but you can change them if you want to.

IP SLA

Configure IP SLA for HPE SSE tunnels. This configuration ensures tunnel connectivity and internet availability between HPE SSE and Orchestrator. If the tunnel cannot reach HPE SSE, the tunnel is considered DOWN.

IMPORTANT: You must configure a loopback interface and a unique LAN-side label (such as “LOOPBACK”) for the orchestrated loopback interface before you can set up IP SLA for HPE SSE tunnels. See Loopback Orchestration and Interface Labels for more information.

  1. On the HPE SSE tab, click IP SLA.

    The HPE SSE Configuration dialog box opens.

  2. If all fields are dimmed, click Enable IP SLA rule orchestration.

  3. Select an orchestrated loopback label from the Source Interface field.

  4. (Optional) In the Route Label field, select a route label to apply to this orchestration. Orchestrator automatically revokes the associated static default route when the IP SLA rule goes down, without requiring a separate standalone IP SLA rule. Depending on the IP SLA Condition set for the route label, the route is marked DOWN if any of the associated IP SLA rules are DOWN or only when all associated IP SLA rules are DOWN. For more information, see Route Labels.

  5. Accept the default values for the remaining fields and click Save.

    Orchestrator builds the tunnels.

Sub-Locations

Sub-locations are a mechanism to configure and deploy different security policies to different types of traffic, at scale. When configuring a sub-location, you specify a subnet range to which the sub-location applies. Orchestrator then creates a corresponding sub-location in HPE SSE using that subnet range, and EdgeConnect appliances automatically provision the sub-location names.

From HPE SSE, you can apply policy rules to sub-locations. The policy rules are applied to all appliances that are configured as part of a sub-location regardless of physical location.

  1. On the HPE SSE tab, click Sub-Locations.

    The HPE SSE Sub Locations dialog box appears.

  2. Click Add.

    The Sub-Location Match Criteria dialog box opens. Enter the appropriate information for the following fields.

  3. Enter a name for the sub-location in the Name field. This name will also be used for the corresponding sub-location in HPE SSE.

  4. In the Appliances field, do one of the following to specify appliances to which the sub-location applies:

    • Start typing in the field and select “any”.

    • Enter “group” and select the name of an appliance group from the list.

    • To specify the appliances currently selected in the appliance tree, click Use Tree Selection. The appliance names appear beneath the Appliances field.

  5. In the Internal IPs field, do one of the following to specify the subnet range for the sub-location:

    • Enter the name of a configured LAN label, firewall zone, or address group.

    • Enter an IP address or IP address range and click +Add.

  6. Click Save.

    The Sub-Location Match Criteria dialog box closes.

  7. Click Save.

HPE SSE POP Override

You can override the automatically selected endpoints for specific sites. You have the option to add this exception to one or more sites within your network.

  1. On the HPE SSE tab, click HPE SSE POP Override.

    The HPE SSE POP Override dialog box opens.

  2. Enter the appliance name, the interface label, and the primary and secondary FQDNs or IP addresses. Orchestrator will build tunnels to those endpoints.

    Field Description
    Appliance Appliance for which to override HPE SSE endpoints.
    Interface Label Interface label from which tunnels are built.
    Primary FQDN or IP FQDN or IP address of the primary HPE SSE endpoint.
    Secondary FQDN or IP FQDN or IP address of the secondary HPE SSE endpoint.
  3. Click Save.

HPE SSE Association

The final step to configure the integration in Orchestrator is to associate EdgeConnect appliances to HPE SSE.

  1. In the Orchestrator appliance tree, select one or more appliances to associate with HPE SSE.

  2. On the HPE SSE tab, click HPE SSE Association.

    The HPE SSE Appliance Association dialog box opens.

  3. In the table, select one or more appliances you want to associate with HPE SSE, and then select the Add check box.

    Select the Remove check box to remove HPE SSE association from selected appliances in the table.

  4. Verify the changes, and then click Save.

Pause Orchestration

When troubleshooting, you can click Pause Orchestration and then click Save to pause orchestration. To restart, click Resume Orchestration.

Redirect HPE SSE Application Traffic via Break Out Locally

Traffic categorized as HPE SSE, which includes HPE SSE agent traffic (formerly known as Axis Security client), should break out locally, so it is not redirected to the HPE SSE tunnel and does not consume SASE secure web gateway bandwidth. To do this, you need to select the HPE SSE service in at least one Business Intent Overlay (BIO) Breakout Traffic Policy to steer traffic to it.

  1. Navigate to Configuration > Overlays & Security > Business Intent Overlays.

  2. Click an overlay at the top of the BIO priority to use for breakout traffic to HPE SSE.

    The Overlay Configuration dialog box opens.

  3. Click the Breakout Traffic to Internet & Cloud Services tab.

  4. Drag HPE SSE Cloud from the Available Policies column to the Preferred Policy Order column.

  5. Drag Break Out Locally from the Available Policies column to the Preferred Policy Order column and make sure that it appears below HPE SSE Cloud.

  6. Continue to Set Match Criteria.

Set Match Criteria

In the Overlay ACL, you need to set match criteria to steer the HPE SSE application traffic appropriately.

NOTE: Modify the top BIO to ensure that “HPE-SSE” application traffic is matched at the top of the BIO list. You can easily match HPE SSE flows using the built-in “HPE-SSE” application. This built-in application matches various “axisapps.io” domains and known public IPs used by HPE SSE. See Application Definitions Tab.

  1. In the Match field, ensure that Overlay ACL is selected from the menu, and then click the edit icon.

    The Associate ACL dialog box opens.

  2. Click Add Rule.

  3. In the Match Criteria field click the edit icon.

    The Match Criteria dialog box opens.

  4. Select the Application check box, enter “HPE-SSE” in the field, and select HPE-SSE from the drop-down menu.

  5. Ensure that the Permit field shows “permit”.

    NOTE: If the overlay at the top of the BIO priority list is breaking out to the HPE SSE Cloud path, in the Permit field select deny from the menu, so the traffic for the HPE SSE application goes through another BIO policy that does break out locally.

  6. Click Save to close the Match Criteria dialog box.

  7. Click Save.

  8. Click OK.

Verify HPE SSE Deployment

After HPE SSE is configured, deployment will begin automatically. Navigate to the HPE SSE tab to verify successful deployment. The HPE SSE Deployment Status column should have a green status of Deployed, and the Connection status column should have a green status of Up. The Connection Status column indicates the status of the HPE SSE connection based on tunnel and IP SLA statuses.

NOTE: HPE SSE is deployed and orchestrated for an appliance based on the HPE SSE Appliance Association dialog box. Business Intent Overlays (BIOs) are used to configure breakout internet policies to HPE SSE. This is used for automatic load distribution and failover.

You can also verify that your HPE SSE tunnels have been successfully deployed on the Tunnels tab. The Passthrough Tunnel column should list your HPE SSE tunnels, and the Status column should have a green status of up – active.

You can view the Audit Log to check for orchestration errors. Navigate to Orchestrator > Audit Logs and enter hpesse in the search field above the table.

SSE Connector

The SSE Connector enables EdgeConnect appliances to integrate with the HPE SSE cloud security service. The SSE Connector provides secure, identity-based access to private applications. It is supported in both Edge HA and Traditional HA deployments. Each appliance can have only one connector installed.

NOTE: The SSE connector is not supported on EC-US models or older EC-XS models.

NOTE: On EdgeConnect appliances with fewer than 16 cores, the WAN Optimization feature (formerly called Boost) is disabled when the SSE Connector is installed. You must reboot to apply this change.

The following table describes the fields on the SSE connector view of the HPE SSE tab.

Field Description
Appliance Name of the appliance to connect to HPE SSE.
Eligible Indicates whether the appliance meets the minimum hardware and platform requirements to support the SSE connector. Any supported EC or EC-V with 4 or more cores can support the SSE connector.
Admin Indicates whether the SSE connector is administratively enabled or disabled in the Axis portal.
Connector name Name of the SSE connector created for the appliances. This name is automatically generated by Orchestrator using the Orchestrator identifier and the appliance name to create a unique identifier in the Axis portal.
Connector zone SSE connector zone associated with the connector. This zone is required for connector operation. It is derived from the subscription configuration and site or cluster information, if available. If no connector zone is specified and no site or cluster information is available, Orchestrator automatically creates a default connector zone using the connector name. This ensures that the connector zone is unique and valid.
Version Software version of the SSE connector currently installed on the appliance. If no connector is installed, this field is set to “None”.
Public IP Public IP that is automatically populated after the connector is created and successfully registered with the SSE cloud.
Status Current operational state of the connector on the appliance (for example, “Up” or “No connector installed”). This column reflects real-time connector availability and connectivity to the Axis portal.
Details Click to display a detailed status and diagnostics view for the connector. This view provides installation and operational information, including download progress, image verification, installation steps, connection status, and error messages. The Details view is the primary troubleshooting interface for connector install, upgrade, and uninstall operations.

NOTE: Closing the Details dialog box does not stop an active operation. Installation or uninstall operations continue in the background.
Actions Hover to view available actions for this row (edit, delete, and so on).

Configure SSE Connector

Before you configure HPE SSE, you must create an HPE SSE account and have an HPE SSE tenant provisioned. Contact HPE Networking support for assistance with provisioning an HPE SSE tenant.

Before you begin:

  • Ensure that you have access to the HPE SSE (Axis) Admin Portal. You will use this portal to create API tokens required for HPE SSE configuration.

  • Plan a maintenance window for installing the HPE SSE connector, as installation may temporarily interrupt connector traffic and may require an appliance restart on low-end platforms.

Subscription

Complete the Subscription dialog box to establish connectivity between Orchestrator and the HPE SSE (Axis) portal.

TIP: The subscription is shared by Secure Web Gateway and SSE Connector. If the HPE SSE status on the Subscription dialog box indicates Connected and your subscription includes API tokens with permissions for Connector Zones and Connectors, you can skip this step. Otherwise, update the subscription to include the required tokens.

  1. In Orchestrator, navigate to Configuration > Cloud Services > HPE SSE.

  2. Click SSE Connector.

  3. Click Subscription.

    The Subscription dialog box opens. Leave the dialog box open, so you can paste your HPE SSE API token key in the API Token Key field.

  4. In a new browser tab, go to https://auth.axissecurity.com/ and log in to your HPE SSE account.

  5. From the Dashboard, click Settings and then click Admin API.

    The Admin API page opens.

  6. Click New API Token.

    The New API Token dialog box opens.

  7. Enter a name for the new API token. The name should identify your Orchestrator.

  8. Under Token Permissions, select Read and Write.

  9. Under Token Scopes, select only Connector Zones and Connectors.

  10. Under Token Expiration, enter 12.

  11. Click Submit.

    The New API Token dialog box opens and displays the token you created.

  12. Copy the token.

  13. In Orchestrator, paste the token into the API Token Key field on the Subscription dialog box.

  14. In your HPE SSE account after you have copied the token, click OK.

  15. In Orchestrator, enter the appropriate information in the remaining fields on the Subscription dialog box to reflect your HPE SSE account.

    The following table describes the fields.

    Field Description
    HPE SSE Indicates whether you are connected to your HPE SSE account.
    API token name Enter the name you assigned to the API token when you created it in your HPE SSE account.

    NOTE: The name should exactly match what you entered in the HPE SSE dashboard.
    API token key Enter (paste) the API token key you created in your HPE SSE account. This token is used to access the HPE SSE APIs.
    API domain Domain name of the HPE SSE APIs that are used in tunnel creation. Do not change the default setting.
    Tunnel identifier Unique identifier for the tunnel that is used when building the tunnel IKE identifiers. Enter the domain name for your company. For example, hpearubanetworks.com.
    Orchestrator identifier Unique identifier for the Orchestrator instance. This value is used to uniquely associate connectors created by this Orchestrator in the SSE (Axis) portal.

    By default, this is the configured hostname for the Orchestrator. You can change this to be any string, but it should be entered in the format of a hostname (containing no spaces or special characters).
    Polling interval Indicates how often Orchestrator should check for configuration changes in HPE SSE. The default polling interval is ten minutes.
  16. Click Save. The HPE SSE field should change to Connected.

SSE Connector Interface Orchestration

A connector interface is required to pass traffic between EdgeConnect appliances and the SSE connector. A single subnet is specified for all appliances using the “Global” region. These SSE connector interfaces (“veth” interfaces) are required for connecting EdgeConnect appliances to the SSE connector. The SSE connector software is installed and managed separately.

The following table describes the fields on the SSE connector interface orchestration dialog box.

Field Description
Segment Network segment associated with the connector interface. After this value is created, it cannot be modified.

If the connector is deployed to a non-default segment, be sure to configure the appropriate intersegment rules and firewall policies to allow connector traffic. You can match traffic based on Zone, Role, or the configured veth pool range. Additionally, all traffic to and from the HPE SSE cloud services can be identified and matched using the “HPE-SSE” application name.

NOTE: All traffic to and from the connector is subject to existing policies, similar to any other LAN- or WAN-side flows.
Region In Orchestrator release 9.7.0, the region setting is fixed to “Global” and cannot be changed.
Label Label to identify the interface for organizational or policy purposes.
Zone Security zone assigned to the connector interface.
Role Role applied to traffic originating from the connector interface.
IP pool IP address pool used for connector interfaces. The pool size determines how many appliances can be supported. Each appliance consumes two IP addresses from the SSE connector interface pool.
Allocated / Total Shows how many IPs are currently assigned versus the total number of IPs available in the pool.
Actions Hover to view available actions for this row (edit, delete, and so on).
Add SSE Connector Interface Pools

IMPORTANT: Plan the SSE connector interface subnet and segment before you begin. You cannot change the IP subnet or the segment after the SSE connector is installed. If you need to change these values, you must uninstall the SSE connector from all associated appliances, remove the SSE connector interface, and then recreate the SSE connector interface orchestration. SSE connector interfaces will appear as “veth20000”.

IMPORTANT: Ensure that among the top three DNS Server IPs, at least one is an IPv4 address and is reachable from the connector segment. This can be achieved by either placing the DNS server within the same segment as the connector or adding an inter-segment rule from the connector segment to the DNS server’s segment.

NOTE: If the DNS Server IP is reachable only via the SD-WAN fabric, then the veth IP subnet should be configured as “subnet shared” with the peer to ensure proper return traffic flow.

NOTE: Management Services configuration is not applicable for packets generated from the “ssecon” namespace.

The following table describes the fields on the SSE connector interface pool dialog box.

Field Description
Segment Network segment associated with the connector interface. You cannot modify this value. All interfaces in the region inherit the same segment.
Label Label to identify the interface for organizational or policy purposes. All interfaces in the region inherit the same label. This field is optional.
Zone Security zone assigned to the connector interface. All interfaces in the region inherit the same zone.
Role Role applied to traffic using the connector interface. All interfaces in the region inherit the same role.
Region Region is a logical grouping used for SSE connector interface orchestration. In Orchestrator release 9.7.0, the region setting is fixed to “Global” and cannot be changed.
IP pool Virtual interface automatically created on each appliance to enable communication between the appliance and the SSE connector. The interface is assigned IP addresses from an SSE connector interface pool. The SSE connector interface pool can be defined in the Global region. A pool defined in the Global region will be used across multiple regions.

Support for creating SSE connector interface pools for specific regions will be in future releases.

To add an SSE connector interface pool:

  1. Click Add.

    The SSE connector interface pool dialog box opens.

  2. From the Segment field, select the segment for this connector interface. The list contains existing segments defined in Orchestrator. If you select Default, the SSE connector interface is placed in the default network segment (VRF) on the appliance.

  3. From the Label field, select the label for this connector interface. The list contains existing labels defined in Orchestrator. If you select NONE, no label is applied to the SSE connector interface. The interface is created without label-based classification and will not be included in policies that depend on interface labels.

    NOTE: Do not assign the same label to the connector interface as any other LAN-side interface. The connector should have its own dedicated label, role, and zone. Sharing labels with loopback interfaces or other LAN interfaces can lead to policy conflicts.

  4. From the Zone field, select the zone for this connector interface. The list contains existing zones defined in Orchestrator. If you select Default, the SSE connector interface is assigned to the default security zone defined in Orchestrator. The interface inherits the policies and access controls associated with that zone.

  5. In the Role field, select the role to assign to this interface. If you select Default, the SSE connector interface uses the default role defined in Orchestrator. The interface inherits the traffic policies and behavior associated with that role.

  6. In the Region field, select the region you want Orchestrator to create an SSE connector interface for. In release 9.7.0, the region setting is fixed to “Global” and cannot be changed.

  7. In the IP pool field, enter the IPv4 subnet in CIDR notation (for example, /16). The subnet size determines how many appliances the fabric can support.

    NOTE: Ensure that the pool is large enough. Each appliance requires two IP addresses from the pool, and the subnet size determines how many appliances a region can have.

  8. Click Save.

    Orchestrator automatically creates the SSE connector interface on each appliance in the region. You may see new virtual interfaces or assigned IP addresses before the SSE connector is installed or active.

  9. Click Close.

  10. Continue to SSE connector interfaces to confirm that the interface orchestration completed successfully. The configuration is successful when the SSE connector interface appears in the SSE Connector Interfaces view with Admin set to Enabled and Status set to Up.

SSE Connector Interfaces

Use the SSE connector interfaces dialog box to view and validate that interface orchestration completed successfully.

The following fields describe the connector interface created on each appliance.

Field Description
Appliance Appliances that are selected in the appliance tree.
Segment Inherited from interface orchestration configuration.
Zone Inherited from interface orchestration configuration.
Role Inherited from interface orchestration configuration.
Label Inherited from interface orchestration configuration.
Interface Automatically generated virtual interface created for the connector (for example, veth20000).
IP/Mask A /31 address block assigned from the SSE connector interface. Each appliance is allocated two IP addresses within this range.
Admin Indicates whether Orchestrator has configured and enabled this interface.
Status Indicates whether the interface is up and operational on the appliance.

If the interface status is UP, continue to SSE connector management to download/install the HPE SSE connector.

SSE Connector Management

The final step to configure the SSE connector is to download and install the SSE connector on the appliances. You can either download only or download and install the SSE connector image to appliances. Traffic on the selected appliances is interrupted when the SSE connector is installed. HPE Networking recommends that you install connectors in a maintenance window.

NOTE: A reboot is required when installing or uninstalling the Connector on any appliance with 16 cores or fewer. Additionally, WAN Optimization (formerly called Boost) is disabled when the connector is installed on EdgeConnect appliances with less than 16 cores.

The following tables explain the fields on this dialog box.

Connector Images Table
Field Description
Connector name Auto-generated name created by Orchestrator using the Orchestrator identifier and appliance name. This name uniquely identifies the connector in the Axis portal.
Version Connector image version available for installation.
Build date Date on which the connector image was built.
Release notes Click the information icon (i) to download the release notes for the selected SSE connector image.
Certified appliance version Indicates whether the connector image is certified for the current ECOS version. HPE Networking tests and certifies the current HPE SSE connector version at the time of the EdgeConnect software release.
Target Appliances Table
Field Description
Appliance The appliance on which the connector image will be installed, upgraded, or removed.
Site/Cluster name The site or cluster with which the appliance is associated. This field is blank if no site or cluster is associated with the appliance.
Status The current connector state of the appliance (for example, no connector installed, connector installed and running, or an error message). This field updates dynamically.
Progress The real-time progress of the install, upgrade, or uninstall operation.
Image certified Indicates whether the selected connector image is certified for the ECOS version running on the appliance.
Restart required Indicates whether installing a connector image requires a reboot (appliances with 16 cores or less).
Actions Hover to view available actions for this row (edit, remove, and so on).
Download and Install an SSE Connector Image

To download or download and install an SSE connector image to appliances:

  1. In the appliance tree, select the appliances you want to download and install the SSE connector image to.

  2. Click SSE connector management.

    The SSE connector management dialog box opens.

  3. In the Target appliances table, verify that the appliances you want to install the SSE connector on are listed in the table. The Restart required column indicates whether a restart is required after the connector is installed.

    IMPORTANT: Check the Image certified column in the Target appliances table to verify that the image is certified for use with the appliance’s ECOS version.

  4. If you do not want to install the connector image on a target appliance, hover your cursor in the Actions column of that appliance and click the trash can icon.

    Orchestrator removes the appliance from the Target appliances table.

  5. From the Connector images table, select the connector image you want to download to the appliances. Use the Image certified column to determine which images are certified for your ECOS version.

    TIP: Click Refresh connector images to update the list of available connector images.

  6. Click the information icon (i) in the Release notes column to download the release notes associated with the connector image. The release notes provide critical information concerning the connector installation or upgrade. Review the release notes before you proceed.

  7. Select one of the following options:

    • Download: Downloads the SSE connector image to the selected appliances but does not install it. This option does not require a maintenance window.

    • Install already downloaded image: Installs the SSE connector image that has already been downloaded to the selected appliances. This option requires a maintenance window only for low-end appliances (fewer than 16 CPU cores), that reboot during installation. High-end appliances do not require a reboot, but connector traffic is briefly interrupted during installation.

    • Download and install: Downloads and installs the SSE connector image on the selected appliances. This option requires a maintenance window only for low-end appliances (fewer than 16 CPU cores), that reboot during installation. High-end appliances do not require a reboot, but connector traffic is briefly interrupted during installation.

    NOTE: To reduce the risk of connectivity disruption, HPE Networking recommends downloading the connector image first and performing the installation in a separate step.

    IMPORTANT: Appliances with fewer than 16 CPU cores require a reboot during connector install or uninstall. This automatic reboot temporarily interrupts traffic on the appliance. Perform these operations during a maintenance window. Appliances with 16 CPU cores or more do not require a reboot during connector install or uninstall. However, connector traffic is still briefly interrupted. Additionally, WAN Optimization (formerly called Boost) is disabled when the Connector is installed on EdgeConnect appliances with less than 16 cores.

  8. Click Install to initiate the selected action (download, install, or both).

    The Progress column in the Target appliances table indicates the progress of the download or installation.

  9. If a restart is required, a Connector install confirmation dialog box opens. Confirm the restart.

  10. Click Install to continue.

The Progress column in the Target appliances table updates in real time to show the current progress. You can click Cancel to close this dialog box without interrupting the download or installation.

Uninstall a Connector Image

To uninstall a connector:

  1. Hover over the Actions column for the appliance whose connector you want to uninstall and click the trash can icon.

    The Uninstall connector dialog box opens.

    IMPORTANT: Uninstalling the connector interrupts connector traffic on all appliances. Low-end appliances (fewer than 16 CPU cores) are automatically restarted during uninstall, which temporarily disrupts all traffic on the appliance. HPE Networking recommends uninstalling connectors during a maintenance window.

  2. Click Uninstall. The uninstall operation starts immediately and cannot be cancelled.

EdgeHA Functionality and Connector Traffic Flow

The following diagram illustrates how connector traffic is handled within the EdgeConnect appliance and forwarded to the SSE service. Use this diagram to understand how interfaces, zones, and roles influence traffic flow and policy enforcement, and to assist with troubleshooting connectivity issues.

img

Troubleshoot SSE Connector

The ZTNA Connector button on the Flows tab allows you to filter and identify traffic flows associated with the HPE SSE connector. You can use this feature to:

  • Verify that ZTNA traffic is reaching the connector.

  • Confirm that traffic is being forwarded to the SSE cloud.

  • Troubleshoot connectivity issues with ZTNA-protected applications.

To view ZTNA traffic:

  1. Navigate to Monitoring > Tunnel Bandwidth > Flows.

  2. Click More options.

  3. From the appliance tree, select the appliance or appliances you want to monitor.

  4. Click the ZTNA connector button to filter the traffic so that only SSE connector traffic is displayed.

  5. In the Details column, click the information icon (i) to display the details for a specific ZTNA connector flow.

  6. Confirm that the Source IP corresponds to the SSE connector interface IP and that the Destination IP corresponds to either the protected application or the SSE cloud PoP, depending on the flow direction.

    If the endpoints are not communicating, validate that the SSE connector is installed and that the connector interface Admin state is enabled and the Status state is UP.

    Ensure that the EdgeConnect firewall policies are properly configured to allow the ZTNA connector traffic. As a best practice, assign a specific role to the connector’s veth interface and then permit that role across the entire fabric.

  7. On the top of the dialog box, click NAT.

  8. Confirm that the implicit SNAT is being applied to the connector to ZTNA-protected application traffic as expected.

    If the source IP addresses match the expected values, the SNAT is functioning correctly. If not, verify that the Original Source IP is the SSE connector interface IP and that the Translated Source IP is the appliance’s LAN interface IP.