Basic knowledge about local network configuration.
Overview
Gateway is a device that allows you to connect your local network to Acreto and secure whole network traffic and end-user devices without configuring them one-by-one. Take a look at the images below to compare standard network connection with the network secured by Acreto with the Gateway method.
Internet conection without Acreto
Internet conection with Acreto
Gateway may be configured in IPsec or vGateway mode. Each of these configurations may be used for different purposes and in different network structures:
choose vGateway when you want to download a preconfigured Acreto vGateway appliance and install it on a Raspberry Pi device or some virtualization platform (like KVM or VMware)
choose IPSec if you prefer to manually configure your existing device (like router or Linux machine) which supports IPSec protocol
Select your ecosystem and go to Objects using the left menu.
Click Add new Object and select Gateway.
Fill at least:
Name: - the name of the gateway that you creating, needs to be compatible with
Strongswan connection name requirements (basically, only letters and
numbers)
Category: IoT
Fill gateway type-specific settings described here: IPsec | vGateway
Save the created Gateway by pressing Add.
Add security policy that will allow communication from the Gateway
device to the Internet.
Commit pending changes (top of the screen)
Notice: To successfully test your connectivity, you also need to create a security policy that will allow traffic to go through your device.
IPsec Gateway
Set specific setting for IPsec Gateway:
Allow connection from: Empty (describes the source IP address where the connection will be permitted)
Local Networks: - your local network addresses that should be routed through this gateway
Tip: To simplify testing, add IP addresses of all interfaces connected to your gateway as Local Networks (you can use /32 prefix for public interface). This will allow testing connectivity from the gateway through Acreto using ping, traceroute, and similar tools.
vGateway
Set specific setting for IPsec Gateway:
DHCP/Static: - select the method of assigning addresses on the network
vGateway Local IP: - address of local (LAN) interface of your device (for example 192.168.200.1/24)
Local Networks: - your local network addresses that should be routed through this gateway
vGateway Internet IP - IP address with a netmask of internet-facing (WAN) interface, for example 1.2.3.4/24
vGateway Default Route - IP address of your Internet gateway/router that allows access to the Internet, for example 1.2.3.1
Tip: To simplify testing, add IP addresses of all interfaces connected to your gateway as Local Networks (you can use /32 prefix for public interface). This will allow testing
Next Steps
When Gateway is ready you should configure the gateway device on your end to act as a gateway to the Acreto platform and pass traffic from your endpoints through the gateway device. connectivity from the gateway through Acreto using ping, traceroute, and similar tools.