Zedmos
Technik

Operator manual

The SASE console, screen by screen

How to build an overlay between your sites, let people in from outside it, and decide what each of them may reach — written for the person who has to do it, with every control named as it appears on screen.

13 Kapitel127 erklärte BedienelementeDieses Handbuch ist auf Englisch verfasst. Die Oberfläche selbst ist in jeder Sprache englisch.

Die Aufnahmen stammen aus einer laufenden Konsole. Der gezeigte Bestand ist dargestellt, nicht berichtet: Standortnamen, Hostnamen, Adressen und Personen sind Platzhalter, und jeder Tunnel wird als aufgebaut gezeigt. Was die Oberfläche selbst sagt — jedes Bedienelement, jede Zahl, jeder Zustand — bleibt unverändert.

One idea holds the rest together

A tunnel proves a device, never a person. Everything in this manual that looks like extra work — binding a device to a directory, granting applications instead of networks, re-checking access on a deadline, asking what state the machine is in — exists because of that one gap. Build the overlay first; then close the gap.

01 · Six tabs, six questions

What the console is for

The SASE section has six tabs, and each answers one question. Knowing which tab answers which is most of the learning curve.
The Overlay tab with a topology selected: the six section tabs across the top, the palette of firewalls on the left, the toolbar above the canvas, and the tunnels drawn as the console last wrote them.

Bedienelemente · The six tabs

Overlaypanel
Where topologies are drawn, deployed and watched. This is where sites become a network.
SD-WANpanel
What each firewall's own agent measures on each of its uplinks. A window, not a control: the firewall chooses paths, five seconds at a time.
Private Accesspanel
People who connect from outside, and the devices they hold. One row per person, one card per device.
Securitypanel
Where the inspection actually happens, and the honest list of what this product does not do.
Monitorpanel
Health, alert rules, what fired, and the audit trail of every change the console made to a firewall.
Settingspanel
Four tabs of their own: who may connect, what they may reach, which networks exist, and how things are linked.
  • The Glossary button in the tab bar defines every term this product uses, including the ones it deliberately does not claim.
  • Nothing on the canvas is a drawing of an intention. A line is drawn from what the console has written to a firewall, and its colour says what that tunnel is actually doing.

6 erklärte Bedienelemente

02 · Choosing a topology

The four shapes, and when each is right

A topology is a shape, a transport and an address range. The range is allocated for you and never overlaps another topology in the same organisation. The shape decides who dials whom — and, just as importantly, whose traffic passes an inspecting firewall.
Standort 1Standort 2Standort 3Standort 4Hub

Hub and Spoke

Alles erreicht eine Stelle. Beginnen Sie hier, wenn nichts dagegen spricht.

Verkehr zwischen zwei Standorten nimmt den Umweg — und wird dabei geprüft.

BackupStandort 1Standort 2Standort 3Standort 4Hub

Dual-Hub

Ein Ausfall am Hub-Standort darf die anderen Standorte nicht mitnehmen.

Ein zweiter lauschender Hub. Er hält nur Host-Routen, bis er gebraucht wird.

Standort 1Standort 2Standort 3Standort 4Hub

Spoke-Shortcut

Zwei Standorte sprechen so viel miteinander, dass der Umweg echte Zeit kostet.

Dieser Verkehr passiert den Hub nicht mehr und wird dort auch nicht mehr geprüft.

Standort 1Standort 2Standort 3Standort 4Hub

Full Mesh

Jedes Paar spricht mit jedem. Auf acht Standorte begrenzt.

Jeder Standort trägt einen Peer für jeden anderen, und ein Knoten vermittelt weiterhin.

Aufgebauter TunnelDirekter Pfad zwischen zwei StandortenStandby-Pfad — nur Host-Routen bis zum Failover
The New Topology dialog. Each shape carries what it is for; the transport below it decides what can be enforced afterwards.

Bedienelemente · Shapes

Every shape has exactly one primary hub: the node with an address the others can dial.

Hub and spokeselect
Every site dials one hub, and all traffic between sites passes through it. The simplest shape and the easiest to reason about, because everything crosses one engine. Choose it unless you have a reason not to.
Dual hubselect
A second listening hub that holds host routes only until it is needed. When the primary stops answering, the console moves every spoke across in one operation and moves them back once the primary has been stable again. Choose it when an outage at the hub site must not take the other sites with it.
Spoke shortcutselect
The hub stays the rendezvous point, but a configured pair of spokes is told each other's observed address and both ends hold a keepalive, so they open their own path through their NATs. Choose it when two branches talk to each other enough that the detour costs real time.
Full meshselect
Shortcuts for every pair, capped at eight sites because each site then carries a peer for every other. One node still holds the hub role: it brokers the pairs and carries any pair that cannot be joined directly.

Bedienelemente · Transports

WireGuardselect
The default, and the only one that carries every feature in this manual — per-device switching, shortcuts, per-device firewall rules. Keys are generated on the firewalls themselves.
OpenVPNselect
A per-topology certificate authority on the console. A device gets a certificate and the server hands it an address at connect time, which is precisely why per-device rules and the per-device switch do not apply to it.
GREselect
Site to site only, in /30 pairs. There is no remote-user enrolment on a GRE topology, and the dialog says so rather than letting you find out later.
The shape can be changed later; the transport cannot. Adding a second hub or turning on shortcuts is a change to an existing overlay. Moving from WireGuard to OpenVPN is a new topology and a re-enrolment of every person on it, because the keys, the addresses and the client configuration all differ.
  • A shortcut is a security decision as much as a performance one: traffic that stops transiting the hub also stops being inspected there. The spoke's own engine still sees it.

7 erklärte Bedienelemente

03 · Hub and spoke, end to end

Building your first overlay

This is the whole procedure for the simplest shape. Every other shape is this one plus a difference, and the next chapter covers the differences.
The readiness card lists what is still missing, in the order it has to be fixed. A blocker disables Deploy, and the orchestrator refuses with the same sentence.
Hub and spoke, deployed: two spokes dialling one hub, each link carrying its measured latency.

Vorgehen

  1. 1

    Create the topology

    Overlay → New Topology. Name it for the estate rather than the technology — HQ and branches survives a transport change, WireGuard mesh does not. The name appears in every alert and in the audit trail.
  2. 2

    Add the hub first

    Drag the firewall that has an address the others can reach. Everything else dials it, so a firewall behind a NAT with no forwarded port cannot be a hub. The first node you drop is made the hub automatically, because a topology without one cannot be deployed at all.
  3. 3

    Add the spokes

    Drag each remaining firewall onto the canvas. A spoke needs only to reach the hub's address and port; it may sit behind any NAT, including a carrier-grade one.
  4. 4

    Tell each site what it advertises

    Open a node's settings, press Detect to read the networks behind that firewall, then move the ones the other sites should reach into Advertised subnets. Detecting a network does not publish it. A site that advertises nothing is reachable and leads nowhere, which is the most common reason a working tunnel looks useless.
  5. 5

    Read the readiness card

    It lists what is still missing, in the order it has to be fixed. A blocker disables Deploy — and the orchestrator refuses with the same sentence, so the button and the error never disagree.
  6. 6

    Deploy

    Press Deploy All. Keys are written first, then peer lists. Watch the links turn: a node that fails is marked and the others still converge, so one unreachable branch does not hold up the rest.
  7. 7

    Prove it from a client, not from the console

    From a machine behind one spoke, reach something behind another. A green line means the console wrote what it intended and the tunnel handshaked; it does not prove that the thing you wanted to reach is reachable.
  • Deploy All is a reconciliation, not an append. Pressing it again is safe, and a node that already matches is left alone.
  • History shows every deploy of this topology and what each node answered. Ops Log shows who pressed what. When something changed and nobody remembers doing it, start there.

04 · What changes, and what to watch

The other three shapes

Each of the remaining shapes is the hub-and-spoke procedure with one addition. None of them changes how a site advertises its networks or how it is deployed.
Dual hub. The second hub is drawn holding host routes only — it does not attract traffic while the primary answers.
A brokered pair. The link between the two spokes reads DIRECT once both ends have opened their own path.
Full mesh: every pair joined, each with its own latency, and one node still holding the hub role.

Bedienelemente · Dual hub

Set as Backup Hubmenu
Right-click a second listening node. It holds host routes only — it never quietly attracts traffic while the primary is healthy.
Failover classselect
How patient to be with a silent primary. It feeds the box-local monitor where that is enabled; the console's own failover uses the topology's silence threshold.
Promote Backupbutton
Triggers the swap yourself, with a preview of exactly which peers change on which node before anything is written.
Preferred hubselect
Where the sites belong when everything is healthy. Failback returns them there automatically once it has been stable for the configured window.

Bedienelemente · Spoke shortcut

Draw a link between two spokes and the console brokers the pair. Nothing else changes.

PROBINGbadge
The pair has been written and is trying to handshake. Both ends hold a keepalive so each opens its own NAT.
DIRECTbadge
The two ends are talking to each other. Their traffic no longer transits the hub.
VIA HUBbadge
The pair was measured and the hub path is better, or the direct path stopped handshaking. It is retried later; nothing is broken.
NO DIRECTbadge
The pair was refused, and the tooltip says why. Two sites behind one NAT are refused as a hairpin unless each one's reachable address is pinned in its node settings.

Bedienelemente · Full mesh

Adding a sitebutton
A new spoke is linked to every existing spoke automatically. The console repairs a missing pair rather than leaving a hole, so a mesh stays a mesh.
Removing a pairmenu
Refused. A mesh is defined by having every pair; if you want one pair gone, the shape you want is shortcuts, not a mesh.
Eight sitesbadge
The cap, because every site carries a peer for every other. Past that, the shape to reach for is shortcuts on the pairs that matter.
Automatic failover is opt-in per topology, and it is decided by the console: it waits out a silence threshold and confirms with a health check before moving anything. That takes minutes, not seconds. If you need a number for a maintenance window, use Promote Backup and measure it on your own estate.

11 erklärte Bedienelemente

05 · What one site is and carries

Node settings, control by control

Everything that is true of one firewall inside one topology. Most of it has a safe default. The two that decide whether the overlay is useful at all are what the site advertises and whether its traffic leaves through the hub.
Connectivity settings: the tenant-wide defaults a node inherits before anything is overridden on the node itself.

Bedienelemente · Identity and role

Roleselect
Hub, backup hub, spoke or relay. A hub and a relay listen; a spoke dials. A relay here is a listening transit node that does not hold the hub slot. It is a different thing from the NAT relay: a pair where both ends sit behind a port-rewriting NAT is carried by a relay service in the console's own stack, arranged for you, with nothing to set on this node.
Listen portnumber
The UDP port this node listens on. Fixed rather than random, because a shortcut partner is told this port and a port that moved on every deploy would break the pair.
Overlay IPtext
Assigned by the console from the topology's range. Read-only, because two nodes with the same address is a class of outage nobody should be able to cause by typing.

Bedienelemente · What it carries

Route all traffic through the hubtoggle
Sends this site's internet traffic through the hub for inspection instead of out of its own uplink. Off by default, deliberately. Turning it on at a site whose hub cannot carry the traffic takes that site off the internet.
Local subnets · Detectbutton
Reads the networks behind this firewall from the firewall itself. Detection fills the list; it publishes nothing.
Advertised subnetstext
What the other sites are told they can reach here. This is the field that makes a tunnel useful, and the one most often left empty.
Application Routing through this tunneltoggle
Gives a spoke a second, engine-native identity so application-routing rules can steer flows into the overlay while the hub still sees the real client address. Off means the overlay is a routed interface only.

Bedienelemente · Transport tuning

Keepalivenumber
How often a dialling node reminds the far side it is there, which is also what holds its NAT mapping open. 25 seconds suits almost everything.
MTUnumber
1420 on ordinary Ethernet uplinks, 1380 where PPPoE eats the difference. Set too high, it shows up as large transfers stalling while pings succeed — the most misdiagnosed fault in any tunnel.
Rotate WireGuard keymenu
Has the firewall generate a new keypair and rewrites every peer that referred to the old one. The tunnel drops for as long as the rewrite takes.

10 erklärte Bedienelemente

06 · Changing something that is live

Deploying, undoing and deleting

Every change here is a reconciliation rather than an edit: the console works out the difference between what a firewall has and what it should have, and writes only that. Which is why removing things is as safe as adding them, and why an unreachable firewall stops a removal on purpose.
Deploy All writes the whole topology; History and Ops Log record what each firewall answered.

Bedienelemente · Removing

Remove from topologymenu
Takes one firewall out. Its instance is destroyed on the box and every remaining node is rewritten without it, so nothing is left dialling something that is gone. The firewall stays registered and can be used elsewhere.
Disconnectmenu
Removes one tunnel between two spokes. In a full mesh this is refused, because the shape is defined by having every pair.
Deactivatebutton
Stops the overlay without forgetting it: instances come down, the design stays. Reactivating redeploys it as it was.
Delete topologybutton
Type the name to confirm. Every instance on every node is torn down before the record is removed. Remote users of that topology lose access and their configuration files cannot be reused.
If a firewall cannot be reached, its tunnel cannot be torn down — and forgetting it here would leave a live instance on a box nobody is managing any more. The console refuses and names the node. Forcing it is possible, and says plainly that state will linger on that box.

4 erklärte Bedienelemente

07 · Access Management → Enrol a device

Letting a person in

The dialog walks five steps and you can go back to any of them: click Back, or click a step you have already passed in the rail. Nothing is sent until the last step. Two channels are used on purpose — the link identifies the enrolment and the password authorises it, so sending both the same way defeats the point.
Step 1. The rail on the left is the whole job: person, machine, reach, term. Searching the directory fills the address and shows, before anything is sent, which access group this person lands in.
Step 2. The device name is what posture matches on. The config file name below it is what the person will find in their downloads folder — leave it empty and the console derives one.
Step 3. Which overlay the device joins, and which networks its tunnel will carry.
Step 4. Two different clocks. The device term is how long the machine keeps working; the link expiry is only how long the invitation stays open.
Step 5. The link and the password, each shown once. The button on the right takes the finished file instead — faster, and it spends the invitation.

Vorgehen

  1. 1

    Person — who this device belongs to

    Search your directory. Picking someone fills their address and name from the same directory that will assert them at sign-in, and shows which access group they will land in and what they will reach. Typing an address by hand works too and produces an unbound device — one with no identity behind it, which no re-authentication deadline can apply to.
  2. 2

    Device — the machine and its file

    Name the machine as your management system knows it, because device posture matches on that name; without it the person's most recently seen machine is judged instead. Config file name is optional and decides what the person downloads — useful when somebody has to recognise one file among forty at a support desk. The extension is the transport's, not yours.
  3. 3

    Access — what they may reach

    Pick the overlay: the device reaches that overlay's sites and no others. Allowed subnets is client-side routing only — it tells the person's machine what to send down the tunnel, and it is not a firewall rule. When an access group applies to this person, that group's destinations replace this list and the hub enforces them.
  4. 4

    Link & term — how long, and the path out

    Device term is how long the machine keeps working once enrolled. Link expires after is a different clock: how long the invitation stays open, which only has to survive the time between sending it and the person opening it. Then choose split or full tunnel, and where their internet leaves.
  5. 5

    Link ready — send the two halves apart

    The link and the password are shown once and cannot be shown again; a lost one is replaced by minting a new link, never re-sent. Mail one, read the other out, or use a different messenger.

Bedienelemente · The two clocks, which are not the same clock

Operators confuse these because both say “expires”. They govern different things and one of them cuts a working tunnel off.

Link expires afterselect
How long the one-time invitation stays usable — minutes or hours. Once redeemed it is spent whatever the clock says. Nothing that has already enrolled is affected by it.
Device termselect
How long the device keeps working after it enrols, in days. At the end the hub switches the peer off. The person is warned a week before the date, and keeps working for a further week after that warning, so nobody loses a tunnel without notice. Change it later from the device card — Extend offers the same choices.

Bedienelemente · Handing the file over yourself

Sometimes the operator is holding the machine. The last step offers a shortcut that skips the link and the password entirely.

Direct Download Configuration Filebutton
Redeems the invitation there and then and downloads the finished file. The keypair is still made in a browser and the private half is still never sent anywhere — what changes is whose browser: yours. Two consequences follow, and both are stated on the button. It spends the invitation, so the link stops opening. And the file now carries the device's private key, so it has to travel as carefully as the password would have.

Bedienelemente · Fields worth understanding

Person (from your directory)text
Searches the people synced from Active Directory, Entra, Google Workspace or SCIM. Picking one fills the address and name and shows their groups and the access group they resolve to.
Email addresstext
The key for everything afterwards: the sign-in must match it, and the posture source is asked about this address. A directory account that authenticates correctly but belongs to somebody else does not open this invitation.
Config file nametext
What the person downloads, and on most clients the name of the tunnel they see. Letters, digits, dot, dash and underscore survive; anything else becomes a dash. Empty derives a name from the device label.
What will apply to this accesspanel
The four things that will be true of the device once it exists: whether a sign-in is required, when access is re-checked, whether the machine's state is enforced, and what the hub will allow. All set elsewhere, shown here so nobody enrols under assumptions that do not hold.
  • A step that is not finished will not let you past it: the dialog sends you back to the step that owns the problem and says what it is, rather than failing at the end.

7 erklärte Bedienelemente

08 · Suspending, reinstating, revoking

Devices after they exist

One row per person, expanding to one card per device. A person is an address; a device is a peer with its own key and its own fixed overlay address. Policy follows the person, enforcement lands on the device.
Private Access: one row per person, and the Zero Trust card above it saying which of the four answers this organisation has switched on.
A device card expanded: its badges, its access row with the deadline and the operator's overrides, and where its internet traffic leaves.

Bedienelemente · Badges

Active · suspended · expired · revokedbadge
Suspended is the console holding the device off at the hub — for a lapsed sign-in, an account the directory disabled, or a machine reported non-compliant. The reason is on the card.
identity · unboundbadge
Whether the device is bound to a person at a provider, or was enrolled with a link and a password only and is therefore time-limited rather than identity-limited.
device ok · at risk · unknownbadge
What the management system says about the machine. Absent entirely when device posture is off, because a badge nothing is maintaining is worse than no badge.

Bedienelemente · Actions

Require sign-inbutton
Puts the device into re-authentication now instead of at its deadline. A reminder is mailed and the link is copied for any other channel.
Copy sign-in linkbutton
The same link that lives as a comment in the person's configuration file, for when they cannot find it.
Extendbutton
Moves the deadline and reinstates a suspended device. An operator override, logged as one.
Check nowbutton
Asks the management system about this machine immediately and applies whatever the mode calls for. Use it after fixing a laptop instead of waiting for the next sweep.
Revokebutton
Removes the peer from the hub and releases its address. The configuration file stops working immediately and cannot be un-revoked.
Revoking a device is not the same as removing a person. Someone with a laptop and a phone holds two peers; revoking one leaves the other connected. The device count on their row is there to make that obvious.

8 erklärte Bedienelemente

09 · Settings → Identity

Who may connect

Two different jobs share this tab. A directory tells the console who exists and which groups they are in. A sign-in provider proves, at enrolment and at every re-check, that the person in front of the browser is that person. A tenant can have several of the first and one of the second.
Identity: the sign-in provider at the top, then every directory the console reads people and groups from.
The sign-in provider dialog. The redirect URI at the bottom is the one address to allow at the provider.

Bedienelemente · The sign-in provider

Providerselect
Google Workspace, Microsoft Entra ID, or any provider with an OpenID Connect discovery document. Separate from the console's own operator login.
Require sign-in for every new enrolmenttoggle
Off means devices keep enrolling with a link and a password and show as unbound. On means no device is created until someone has proved who they are.
Require multi-factortoggle
Checks the token's amr claim for a multi-factor sign-in. The factor is the provider's; the console refuses a token that does not carry the claim.
Sign in again every N hoursnumber
The re-authentication interval. A reminder goes a day ahead; at the deadline the device is switched off at the hub until the person signs in again.
Redirect URItext
The one address to allow at the provider. Which enrolment a sign-in belongs to travels in the state parameter, so one URI serves the whole console.

Bedienelemente · Identity sources

Kindselect
Active Directory, RADIUS, Entra, Google Workspace or SCIM. Each can verify people, read the directory, or both — a RADIUS server can verify but cannot be enumerated, and the dialog only offers what the protocol supports.
Sync nowbutton
Reads the directory immediately instead of waiting for the interval. The counts on the row are the result of the last read, not an estimate.
Testbutton
Proves the credentials and, for a source that can verify people, proves one person's sign-in without creating anything.
  • A directory that reports someone as disabled suspends their devices without waiting for the deadline. That is the fastest off-switch in the product, and it is the directory's, not the console's.

8 erklärte Bedienelemente

10 · Enrolment, renewal, and — for OpenVPN only — every connection

When the person is actually asked who they are

This is the question operators get wrong most often, so it is worth stating plainly: a WireGuard tunnel never asks anybody for anything. WireGuard authenticates keys, not people, and it has no way to show a login box. Nothing pops up when the tunnel comes up. Identity is therefore checked at moments around the tunnel, and enforced by taking the tunnel away.
The first thing the person sees, whatever else is configured: the out-of-band password. This is the second channel — it is what makes a leaked link useless on its own.
The identity step, which appears only when the tenant requires a sign-in. Here the tenant verifies against its own directory, so the person gets a work account form; a tenant with a sign-in provider gets a button that leaves for it instead, and a tenant with both gets the button, then “or”, then the form.

Vorgehen

  1. 1

    At enrolment — in a browser, before the key exists

    The person opens the invitation link and, if your tenant requires it, proves who they are right there on that page. Only then does their browser generate the key and receive a configuration. The identity is stored on the device and is what every later check compares against.
  2. 2

    At renewal — on a deadline, by a link

    A device bound to an identity carries a re-authentication date. A day before it, the person is mailed a link; at the date, the hub switches their peer off until they open that link and sign in again. The tunnel goes quiet — no prompt appears on their machine, because there is nowhere for one to appear.
  3. 3

    On every connection — OpenVPN topologies only

    OpenVPN can ask, so it does: it asks on every connection and every renegotiation. Tick use for OpenVPN connections on an Active Directory or RADIUS source and the console writes that server into the hub's own authentication servers. From then on the firewall asks your directory directly — not the console — so people keep getting in while the console is unreachable.

Bedienelemente · What each kind of source can actually do

The dialog only offers what a protocol supports, which is why a source you added may not appear as a sign-in option. Reading a directory and checking a password are different capabilities and not every kind has both.

Active Directory / LDAPbadge
Checks passwords ✓ · Lists people ✓. The only kind that does both. Its people fill the person picker, its groups drive access groups, and it can verify a sign-in at enrolment, at renewal and on an OpenVPN connection.
RADIUSbadge
Checks passwords ✓ · Lists people ✗. It can verify somebody but cannot be enumerated, so it never populates the person picker. It is the only kind that can come back with a challenge — a one-time code — and an answered challenge is recorded as a multi-factor sign-in. MS-CHAPv2 is not offered.
Microsoft Entra IDbadge
Checks passwords ✗ · Lists people ✓. Read-only over Graph. It tells the console who exists and which groups they are in. It cannot verify anybody — for that, add Entra as the sign-in provider instead, which is a browser redirect, not a password check.
Google Workspacebadge
Checks passwords ✗ · Lists people ✓. Same shape as Entra: a directory to read, not a place to verify a password.
SCIM (push or pull)badge
Checks passwords ✗ · Lists people ✓. SCIM is provisioning: your identity provider tells the console who joined and who left. It carries no password and can never authenticate anyone.
Sign-in provider (OpenID Connect)badge
Not in the source list at all — a tenant has exactly one and it lives in Settings → Identity, because it works by sending the browser to the provider rather than by checking a password. It is what verifies people when your directory cannot.

Bedienelemente · What the person sees on the enrolment page

Sign in with ‹provider›button
Leaves for your identity provider, comes back proved. The console never sees the password. This is the row you get from the sign-in provider.
Work accounttext
An account name and a password, checked against your Active Directory or RADIUS. Shown when a source has use for authentication ticked. If both methods exist the page offers the button, then “or”, then this form.
One-time codetext
The same form after a RADIUS challenge. The server's own wording is shown above the box; the person types the code and continues.
Neither offeredpanel
A tenant with no sign-in provider and no password-checking source has nothing to ask with. Enrolment still works — the link and the password are the authorisation — and the device is created unbound.
A tenant whose only directory is SCIM, Entra or Google Workspace has nothing that can check a password. Those sources tell the console who people are; they cannot prove that the person at the keyboard is one of them. If you want a sign-in on that estate, configure the sign-in provider — adding more directories will not produce one.
  • Whoever signs in must be the person who was invited. A perfectly valid directory account that answers with a different address is refused, so one employee cannot redeem another's invitation.
  • An unbound device — enrolled without any identity — has no re-authentication deadline, because there is nobody to ask. It lives until its device term ends or somebody revokes it.

10 erklärte Bedienelemente

11 · The model behind the Access tab

What a group and an application are, and what this is not

Before the controls, the two words. An application is where a service lives: an address and the ports it answers on. An access group is who may reach what: the directory groups it matches on one side, the applications and networks it grants on the other. Policy runs in one direction — from people to services — and nothing is ever routed to an application. A person's traffic is either permitted to that address and port or dropped; that is the boundary. Behind it, the same group can name the applications its people may not use — GitHub, YouTube — whatever address they use them at; that second plane is the engine's, and the Access chapter has its table.

Bedienelemente · The words, precisely

Applicationpanel
A named destination: one or more IPv4 addresses (a single host is a /32) and the ports it answers on, each with its protocol. It describes the server side only. On its own it grants nobody anything; it exists so a group can name a service instead of a subnet.
Access grouppanel
The policy. Who: the group names your directory or sign-in provider reports for a person, matched case-insensitively. What: the applications it grants, plus any whole networks. A person in the group gets every application and network the group lists, and nothing else.
Default grouppanel
The floor. Whoever matches no group — and every device enrolled without a sign-in — lands here. Without one, those people are not enforced at all and reach whatever the tunnel routes.
Whole networkpanel
A network granted on every port. Wider than an application, and sometimes exactly right: the management network for the people who run it. It is what every group used before applications existed.
The group's second jobpanel
The dialog says it: the group name is also the policy-template group name for these people. The same word therefore decides two things — what the hub lets through, and which of the firewall's own per-group policies apply to their traffic afterwards. The dialog's Applications blocked at Layer 7 list is the direct form of that second job: the console writes a policy group of its own on every hub, zedmos-sase-<name>, naming these people and the applications the engine is to refuse them.

Bedienelemente · Three artefacts from one group

A group produces three things, and only the last two enforce anything.

The person's configuration filetext
Its AllowedIPs line lists the group's destinations, so the person's machine sends only that traffic down the tunnel. This is routing, and it lives on a machine the person controls: helpful, never enforced.
The hub's rulespanel
For each person, keyed on their tunnel address, on the user-tunnel interface only: DNS at the hub, one line per application and protocol, then a drop for everything else. This is the boundary. It does not care what the file says.
The engine's policy grouppanel
Only when the group lists applications to block at Layer 7: a policy group on each hub's engine, naming the same people, that refuses those applications inside the traffic the rules above let through. Where the rules ask which address, this asks which application — and needs the engine to see the tunnel, which the Access chapter explains.

Bedienelemente · Where identity is checked

At enrolment and at renewalbadge
The person proves who they are in a browser when the device is enrolled and again at each re-authentication deadline. In between, the tunnel address is the identity: the rules are written against it. There is no per-request check, because the tunnel never sees a request — only packets. The chapter before this one has the detail.

Bedienelemente · What this is, and what it is not

Products that do this work come in two families, and it matters which one you are holding.

Broker-basedbadge
A cloud proxy sits between the person and the service. It identifies the person on every request, understands hostnames and URL paths, and never lets a tunnel into the network at all. This console is not that.
Network-basedbadge
The person's device joins the network through a tunnel, identity is bound to that tunnel, and a packet filter at the gateway decides what each tunnel may reach. This console is that. The same family as the mesh and gateway products built on WireGuard.
What follows from itpanel
Destinations are addresses: an application is 10.10.20.5, or a hostname the console resolves to addresses for you — never a URL path. Rules are address and port. Identity holds between checks rather than per request. IPv4 only, today. Application-level control exists, but it is the engine's, on the hub, recognising GitHub or YouTube inside permitted traffic — not a proxy reading paths. In exchange, the gateway keeps enforcing exactly what it was last told even while the console is unreachable, and nothing of yours transits anybody's cloud.

Bedienelemente · Five things people build with it

A contractor and one systempanel
Application: the ERP host on tcp/443. Group: contractors, granting that one application. The contractor's tunnel reaches one port on one host; the rest of the site does not exist to them.
The people who run the networkpanel
Group: it-admins, granting the management network as a whole network. Every port, because that is what administration needs — and only to the people in that directory group.
No directory yetpanel
A single default group granting the two or three services everyone actually uses. Every device lands in it, bound or not. It is not least privilege by person, but it is a floor, and it is what to run until a directory is connected.
Someone leavespanel
Disable them in the directory, or delete the application they used, or take them out of the group. The hub's rules are rewritten within seconds and their open sessions end with them. Nothing has to be done on the person's machine.
Access that ends on a datepanel
Every device carries a term. A contractor's laptop can be given thirty days at enrolment; it is warned before the date and switched off after it, without anyone remembering to do so.
Group matching reads the group names a person's sign-in or directory put on their device. A tenant with no directory and no sign-in provider has nobody carrying any group name — every one of its devices is unbound, and every one of them lands in the default group or, without one, in open access. Connect a directory before expecting a group to single anyone out.
  • Name applications after the service as people say it — Payroll, Wiki — not after the host. The device card shows the group, the group dialog shows the applications, and a name a person recognises is what makes an access review readable.

17 erklärte Bedienelemente

12 · Settings → Access

What they may reach, and on what machine

Three cards, read top to bottom. A group says who. An application says which service. Posture says on what machine. The hub turns the first two into firewall rules per person — their destinations, DNS at the hub, and a drop for everything else — evaluated before the rule that lets the tunnel in at all. A group can also say which applications its people may not use, whatever address they use them at; that second plane is the engine's, and it is described in its own table below. Everything below was proven on a live hub from a real client, not read from the code.
Access, with two applications defined and a group that grants them. The group row names the directory groups it matches, what it grants, and how many people currently resolve to it — <em>nobody yet</em> here, because no directory has put a group name on anyone. The application rows name an address and its ports; that pair is what becomes a firewall rule.
An application is an address and the ports it answers on. Leaving the ports empty is allowed and means every port, and the dialog says so.
The group dialog with applications ticked. Whoever lands in this group reaches exactly those services on exactly those ports; the whole-networks box below is the wider grant, for when a service is really a network.
Device posture. Observe reads and shows; enforce switches a non-compliant device off and lets it back in by itself.

Vorgehen

  1. 1

    Define the service

    Applications → Add application. An address and its ports: 10.10.20.5/32, tcp/443, tcp/8443. A single host is a /32, and a /32 is usually right. Nothing changes on any hub yet — an application on its own grants nobody anything.
  2. 2

    Grant it to a group

    Access groups → Add group. Name it, list the directory groups it matches, tick the applications. Save & apply pushes rules to every hub that carries a person in this group, and the device cards show access: <group> for each of them.
  3. 3

    What the hub writes

    Per person, keyed on their tunnel address, on the user-tunnel interface only — never on the site's LAN traffic. First DNS at the hub, then one line per application and protocol, then a drop for everything else. A person in the group above gets, on the hub, exactly: pass in quick on wg1 inet proto tcp from 10.200.4.10 to { 10.10.20.5/32 } port { 443, 8443 } keep state, then block drop in quick on wg1 inet from 10.200.4.10 to any.
  4. 4

    What the person experiences

    The granted port answers as if nothing were in the way. Every other port on that host, every other host, and even ping are dropped silently — a connection attempt sits for its full timeout rather than being refused, which is the drop rule doing its job. Measured on a hub: :443 answered in under half a second; :22, :80, another host and ICMP all timed out.
  5. 5

    Take it away

    Delete the application, untick it in the group, or edit the group so the person no longer matches. The hub's rules are rewritten within seconds, new connections to the service are refused from then on, and the person's open sessions end: the hub is told which people's access changed and drops their established connections, so a revoked service does not linger in a browser tab or an SSH window until it idles out. People whose access did not change are not touched.

Bedienelemente · Access groups

Provider groupstext
The group names as your provider reports them, matched case-insensitively against what the person's sign-in carried.
Applications this group may reachpanel
Named services with their ports. This is the narrow grant, and the one to reach for first.
Whole networkstext
IPv4 ranges granted on every port. Wider than an application, and sometimes exactly right — a management network for the people who run it.
Applications blocked at Layer 7text
Application names as the engine classifies them — GITHUB, YOUTUBE, DROPBOX. The people of this group cannot use these applications even at an address the grants above allow. Enforced by the engine on the hub, not by the packet filter; see the table below for what that needs.
Default grouptoggle
Applies to everyone who matches nothing else, including unbound devices. Give it the least you can live with.
Reapply on hubsbutton
Rewrites every hub's rules from the current groups. This happens automatically after every enrolment, sign-in, suspension and group change; the button is for when you want to be sure.

Bedienelemente · Applications

Where a service lives and which ports it answers on.

Where it livestext
One or more IPv4 ranges, or a hostname. A single host is a /32, and a /32 is usually the right answer. A hostname — erp.acme.internal, api.stripe.com — is resolved by the console and the hub enforces the addresses it resolves to; the row shows what a name currently resolves to, and re-resolves on its own as the answer moves. A name is the honest way to grant a service whose address you should not have to track by hand. Wildcards are not accepted here yet.
Which portstext
443, 8000-8080, or udp/53. Without a protocol a port is read as tcp. Each protocol becomes its own firewall rule, because that is how the packet filter reads them.
Enabledtoggle
Off keeps the application on the groups that grant it but stops granting it — the quickest way to take a service out of reach without unpicking policy.

Bedienelemente · Naming a service instead of numbering it

How a hostname becomes a firewall rule, and what to trust it for.

What resolves the nametext
The console, not the box. It renders the whole rule set and the box only loads it, so a name is resolved in one place and enforced the same way on every runtime — OPNsense, pfSense, Zedmos NGFW — with nothing new on the box.
What the hub enforcespanel
The addresses, never the name. Grant dns.google on tcp/443 and the hub writes, per person, pass in quick on wg1 inet proto tcp from 10.200.4.77 to 8.8.8.8 port = https and the same for 8.8.4.4, then the block-drop. The name is a convenience for you; the packet filter still matches addresses and ports.
When the address movestext
A background job re-resolves every name in play and, for a tenant whose answers changed, rewrites only the rules that moved and ends exactly those people's open sessions — the old address closes and the new one opens with nothing else disturbed.
What it does NOT dotext
It is not deep packet inspection. It does not read the TLS SNI or the URL, and it cannot tell two services apart that share an address. A name is a way to find the right addresses, not a Layer-7 identity — that is the engine's job, and the next table is where the same group asks it.
Fail-closedtext
A name that has never resolved contributes no address, so its rule is simply absent and the person reaches nothing for it — access is never widened by a DNS failure. A name that resolved once keeps its last good answer through a later hiccup rather than dropping access.

Bedienelemente · Application-level, Layer 7: what they may not use

The same group, a second enforcement plane. The grants above decide which addresses a person may reach; this decides which applications the engine refuses them, whatever address the application is on.

Where it is settext
In the access group dialog, Applications blocked at Layer 7. One place to author both planes: a group that grants the internet and blocks GITHUB lets its people browse and refuses them GitHub, at every address GitHub answers from.
What the console writespanel
One managed engine policy group per access group, zedmos-sase-<name>, on every hub that carries a user tunnel, placed ahead of the catch-all so a matching person is judged by it first. It names exactly the people the group reaches — the same resolution that wrote their firewall rules — together with the group's directory groups, and carries the block list. Proven on a hub: groups=[Finance] users=[finance-user@…] block=[GITHUB], order zedmos-sase-finance, Default.
What the person experiencestext
GitHub is reset the moment the engine recognises it — measured at four milliseconds through the tunnel, at an address the firewall rules allow — while everything else on that same grant answers normally. Take the application off the list and the next connection goes through; nothing to do on their machine.
Kept currenttext
Rewritten when a group changes and when a person enrols, is suspended, reinstated or revoked, and only when the result differs from what the hub already holds — the engine reloads on every save, so an unchanged policy is never pushed. The identity feed the engine needs to recognise the person is re-pushed alongside.
What it needs on the hubtext
The engine must see the tunnel: the hub's user-tunnel interface has to be a protected interface (Firewall → Settings → Interfaces → Protected interfaces; give it a zone). Until it is, the policy is written but inert, and the save result says so — wg_not_protected naming the topology and the interface. Turn it on there, deliberately; the console never toggles the data plane for you.
What it does NOT dotext
It does not replace the grants: a person still reaches only what the group grants. It does not run where the engine is off or the tunnel is not protected. And it classifies applications, not content — what is written inside an allowed application is the DLP layer's business, not this table's.

Bedienelemente · Device posture

Read from the management system you already run. Nothing of ours is installed on the endpoint.

Off · Observe · Enforceselect
Off reads nothing. Observe reads and shows. Enforce switches a non-compliant device off and lets it back in by itself once the machine is healthy. Turning it back down releases everything it had switched off.
Read fromselect
Intune uses its own compliance verdict plus disk encryption and the threat state its security product reports. CrowdStrike Falcon has no compliance verdict, so the question asked is the one it can answer: whether the sensor is installed and running.
Read each device again everynumber
How often a device is re-read. A management API is a shared resource; this is the dial that stops a thousand laptops being asked about every minute.
Also switch off machines nobody can speak fortoggle
The strict reading. Leave it off unless every machine is enrolled — with it on, a broken connector disconnects everybody.
Event URLbutton
A token-gated address your management system can call the moment something changes. It can ask for a device to be re-read, or report one compromised; it cannot assert that a device is healthy. Shown once; minting a new one retires the old.

Bedienelemente · A worked example, field by field

A contractor who must reach one accounting system and nothing else. Every value below is what to type; every line after it is what the console then does.

1 · Applications → Add applicationtext
Name Finance ERP. Where it lives 10.10.20.5/32. Which ports tcp/443, tcp/8443. Enabled. Save. Nothing reaches any hub yet.
2 · Access groups → Add grouptext
Name contractors. Identity-provider groups Contractors — the group name exactly as your directory reports it. Tick Finance ERP. Leave whole networks empty. Default group off. Save & apply.
3 · What the table now showspanel
Grants: Finance ERP. People: how many enrolled devices resolve to the group right now. If it says nobody yet, no device carries the group name Contractors — either the person has not enrolled with a sign-in, or the directory has not been read. Nothing is enforced until that number is at least one.
4 · Enrol the contractortext
Private Access → Enrol device. Pick them from the directory so the sign-in binds their groups. Device term: 30 days. Config file name: acme-contractor. Send the link and the password apart.
5 · What the person's file containstext
AllowedIPs = 10.10.20.5/32 and the hub's DNS address — the group's destinations, nothing else. Their machine sends only that down the tunnel. This is routing on their side; it is not what protects you.
6 · What the hub writes for thempanel
pass in quick on wg1 inet proto tcp from 10.200.4.10 to { 10.10.20.5/32 } port { 443, 8443 } keep state, DNS to the hub, then block drop in quick on wg1 inet from 10.200.4.10 to any. Keyed on their tunnel address, on the user-tunnel interface only.
7 · Check it from their sidetext
https://10.10.20.5 answers. ssh 10.10.20.5 hangs and times out — dropped, not refused. Any other host, the same. The device card reads access: contractors.
8 · When the contract endstext
Delete the application, or disable the person in the directory, or wait for the 30-day term. Within seconds the hub's rules are rewritten and the open sessions end. Nothing to do on their laptop.
A group reaches a person one of two ways: because their sign-in carried a directory group the group lists, or because it is the default group and they matched nothing. The first way needs a directory or sign-in provider (Settings → Identity) that puts group names on the person; without one, nobody carries any group name and every device — bound or not — lands in the default group. Without a default group, those people reach whatever the tunnel routes, because nothing is enforced for them. That is a choice to make deliberately, not one to discover.
  • An application grants a service; a group grants it to people. Build the application first, then the group — a group saved with nothing ticked and no networks listed grants DNS at the hub and nothing else, which is a very quiet way to lock everyone out.
  • Run posture in observe for a working day and count how many devices read unknown. That number is exactly how many people enforcing would disconnect if you also ticked the strict reading.
  • An application with an empty port list is a network grant with a friendlier name. Allowed, and sometimes right, but it is not least privilege.

33 erklärte Bedienelemente

13 · SD-WAN and Monitor

Watching it afterwards

Two tabs, two different questions. SD-WAN asks how each uplink is performing; Monitor asks whether the overlay itself is healthy and records what was done to it.
SD-WAN: what each firewall's own agent measures on each uplink. The console does not choose paths.
Monitor: health, the alert rules worth waking someone for, and the log of every change the console made to a firewall.

Bedienelemente · SD-WAN

Target rowpanel
One uplink or tunnel on one firewall: latency, loss, jitter and the composite score, with the current best marked. An overlay tunnel appears beside the physical links and competes on the same score.
Open Application Routingbutton
Jumps to that firewall's own routing rules, where the steering is actually written. The console does not choose paths; the firewall does, five seconds at a time.
No SLA agent on this platformbadge
That node cannot measure. Its tunnels still work — they are simply not scored, and a rule that says best will not consider them.

Bedienelemente · Monitor

Healthpanel
Per-hub checks and per-spoke latency, loss and jitter, measured by the hub on every poll. Probe now takes a fresh reading instead of waiting.
Alert rulespanel
Failover fired or restored, both hubs down, a spoke offline, loss or latency past a threshold, a deploy that failed. Delivered by mail, webhook or Slack, with a cooldown so one flapping link does not become a hundred messages.
Operation logpanel
Every change the console made to a firewall and the answer it got back. The first place to look when something changed and nobody remembers doing it.

6 erklärte Bedienelemente

If you read one thing twice

Build the overlay, then close the gap the tunnel leaves. A key proves a device; a directory proves a person; an access group decides what that person reaches; a deadline keeps it true; and the management system you already run says whether the machine in their hands should be there at all. Each of those is one screen in this manual, and each one is optional — which is exactly why it is worth knowing which ones you have turned on.