Operator manual
The SASE console, screen by screen
How to build an overlay between your sites, let people in from outside it, and decide what each of them may reach — written for the person who has to do it, with every control named as it appears on screen.
Captures come from a running console. The estate in them is presented rather than reported: site names, hostnames, addresses and people are stand-ins, and every tunnel is shown established. What the interface itself says — every control, count and state — is untouched.
One idea holds the rest together
01 · Six tabs, six questions
What the console is for
Controls · The six tabs
- Overlaypanel
- Where topologies are drawn, deployed and watched. This is where sites become a network.
- SD-WANpanel
- What each firewall's own agent measures on each of its uplinks. A window, not a control: the firewall chooses paths, five seconds at a time.
- Private Accesspanel
- People who connect from outside, and the devices they hold. One row per person, one card per device.
- Securitypanel
- Where the inspection actually happens, and the honest list of what this product does not do.
- Monitorpanel
- Health, alert rules, what fired, and the audit trail of every change the console made to a firewall.
- Settingspanel
- Four tabs of their own: who may connect, what they may reach, which networks exist, and how things are linked.
- The Glossary button in the tab bar defines every term this product uses, including the ones it deliberately does not claim.
- Nothing on the canvas is a drawing of an intention. A line is drawn from what the console has written to a firewall, and its colour says what that tunnel is actually doing.
6 controls explained
02 · Choosing a topology
The four shapes, and when each is right
Hub and spoke
Everything reaches one place. Start here unless you have a reason not to.
Traffic between two sites takes the long way round — and is inspected on the way.
Dual hub
An outage at the hub site must not take the other sites with it.
A second listening hub to run. It holds host routes only until it is needed.
Spoke shortcut
Two sites talk to each other enough that the detour costs real time.
That pair's traffic stops passing the hub, so it stops being inspected there.
Full mesh
Every pair talks to every other. Capped at eight sites.
Every site carries a peer for every other, and one node still brokers the pairs.
Controls · Shapes
Every shape has exactly one primary hub: the node with an address the others can dial.
- Hub and spokeselect
- Every site dials one hub, and all traffic between sites passes through it. The simplest shape and the easiest to reason about, because everything crosses one engine. Choose it unless you have a reason not to.
- Dual hubselect
- A second listening hub that holds host routes only until it is needed. When the primary stops answering, the console moves every spoke across in one operation and moves them back once the primary has been stable again. Choose it when an outage at the hub site must not take the other sites with it.
- Spoke shortcutselect
- The hub stays the rendezvous point, but a configured pair of spokes is told each other's observed address and both ends hold a keepalive, so they open their own path through their NATs. Choose it when two branches talk to each other enough that the detour costs real time.
- Full meshselect
- Shortcuts for every pair, capped at eight sites because each site then carries a peer for every other. One node still holds the hub role: it brokers the pairs and carries any pair that cannot be joined directly.
Controls · Transports
- WireGuardselect
- The default, and the only one that carries every feature in this manual — per-device switching, shortcuts, per-device firewall rules. Keys are generated on the firewalls themselves.
- OpenVPNselect
- A per-topology certificate authority on the console. A device gets a certificate and the server hands it an address at connect time, which is precisely why per-device rules and the per-device switch do not apply to it.
- GREselect
- Site to site only, in /30 pairs. There is no remote-user enrolment on a GRE topology, and the dialog says so rather than letting you find out later.
- A shortcut is a security decision as much as a performance one: traffic that stops transiting the hub also stops being inspected there. The spoke's own engine still sees it.
7 controls explained
03 · Hub and spoke, end to end
Building your first overlay
Procedure
- 1
Create the topology
Overlay → New Topology. Name it for the estate rather than the technology — HQ and branches survives a transport change, WireGuard mesh does not. The name appears in every alert and in the audit trail. - 2
Add the hub first
Drag the firewall that has an address the others can reach. Everything else dials it, so a firewall behind a NAT with no forwarded port cannot be a hub. The first node you drop is made the hub automatically, because a topology without one cannot be deployed at all. - 3
Add the spokes
Drag each remaining firewall onto the canvas. A spoke needs only to reach the hub's address and port; it may sit behind any NAT, including a carrier-grade one. - 4
Tell each site what it advertises
Open a node's settings, press Detect to read the networks behind that firewall, then move the ones the other sites should reach into Advertised subnets. Detecting a network does not publish it. A site that advertises nothing is reachable and leads nowhere, which is the most common reason a working tunnel looks useless. - 5
Read the readiness card
It lists what is still missing, in the order it has to be fixed. A blocker disables Deploy — and the orchestrator refuses with the same sentence, so the button and the error never disagree. - 6
Deploy
Press Deploy All. Keys are written first, then peer lists. Watch the links turn: a node that fails is marked and the others still converge, so one unreachable branch does not hold up the rest. - 7
Prove it from a client, not from the console
From a machine behind one spoke, reach something behind another. A green line means the console wrote what it intended and the tunnel handshaked; it does not prove that the thing you wanted to reach is reachable.
- Deploy All is a reconciliation, not an append. Pressing it again is safe, and a node that already matches is left alone.
- History shows every deploy of this topology and what each node answered. Ops Log shows who pressed what. When something changed and nobody remembers doing it, start there.
04 · What changes, and what to watch
The other three shapes
Controls · Dual hub
- Set as Backup Hubmenu
- Right-click a second listening node. It holds host routes only — it never quietly attracts traffic while the primary is healthy.
- Failover classselect
- How patient to be with a silent primary. It feeds the box-local monitor where that is enabled; the console's own failover uses the topology's silence threshold.
- Promote Backupbutton
- Triggers the swap yourself, with a preview of exactly which peers change on which node before anything is written.
- Preferred hubselect
- Where the sites belong when everything is healthy. Failback returns them there automatically once it has been stable for the configured window.
Controls · Spoke shortcut
Draw a link between two spokes and the console brokers the pair. Nothing else changes.
- PROBINGbadge
- The pair has been written and is trying to handshake. Both ends hold a keepalive so each opens its own NAT.
- DIRECTbadge
- The two ends are talking to each other. Their traffic no longer transits the hub.
- VIA HUBbadge
- The pair was measured and the hub path is better, or the direct path stopped handshaking. It is retried later; nothing is broken.
- NO DIRECTbadge
- The pair was refused, and the tooltip says why. Two sites behind one NAT are refused as a hairpin unless each one's reachable address is pinned in its node settings.
Controls · Full mesh
- Adding a sitebutton
- A new spoke is linked to every existing spoke automatically. The console repairs a missing pair rather than leaving a hole, so a mesh stays a mesh.
- Removing a pairmenu
- Refused. A mesh is defined by having every pair; if you want one pair gone, the shape you want is shortcuts, not a mesh.
- Eight sitesbadge
- The cap, because every site carries a peer for every other. Past that, the shape to reach for is shortcuts on the pairs that matter.
11 controls explained
05 · What one site is and carries
Node settings, control by control
Controls · Identity and role
- Roleselect
- Hub, backup hub, spoke or relay. A hub and a relay listen; a spoke dials. A relay here is a listening transit node that does not hold the hub slot. It is a different thing from the NAT relay: a pair where both ends sit behind a port-rewriting NAT is carried by a relay service in the console's own stack, arranged for you, with nothing to set on this node.
- Listen portnumber
- The UDP port this node listens on. Fixed rather than random, because a shortcut partner is told this port and a port that moved on every deploy would break the pair.
- Overlay IPtext
- Assigned by the console from the topology's range. Read-only, because two nodes with the same address is a class of outage nobody should be able to cause by typing.
Controls · What it carries
- Route all traffic through the hubtoggle
- Sends this site's internet traffic through the hub for inspection instead of out of its own uplink. Off by default, deliberately. Turning it on at a site whose hub cannot carry the traffic takes that site off the internet.
- Local subnets · Detectbutton
- Reads the networks behind this firewall from the firewall itself. Detection fills the list; it publishes nothing.
- Advertised subnetstext
- What the other sites are told they can reach here. This is the field that makes a tunnel useful, and the one most often left empty.
- Application Routing through this tunneltoggle
- Gives a spoke a second, engine-native identity so application-routing rules can steer flows into the overlay while the hub still sees the real client address. Off means the overlay is a routed interface only.
Controls · Transport tuning
- Keepalivenumber
- How often a dialling node reminds the far side it is there, which is also what holds its NAT mapping open. 25 seconds suits almost everything.
- MTUnumber
- 1420 on ordinary Ethernet uplinks, 1380 where PPPoE eats the difference. Set too high, it shows up as large transfers stalling while pings succeed — the most misdiagnosed fault in any tunnel.
- Rotate WireGuard keymenu
- Has the firewall generate a new keypair and rewrites every peer that referred to the old one. The tunnel drops for as long as the rewrite takes.
10 controls explained
06 · Changing something that is live
Deploying, undoing and deleting
Controls · Removing
- Remove from topologymenu
- Takes one firewall out. Its instance is destroyed on the box and every remaining node is rewritten without it, so nothing is left dialling something that is gone. The firewall stays registered and can be used elsewhere.
- Disconnectmenu
- Removes one tunnel between two spokes. In a full mesh this is refused, because the shape is defined by having every pair.
- Deactivatebutton
- Stops the overlay without forgetting it: instances come down, the design stays. Reactivating redeploys it as it was.
- Delete topologybutton
- Type the name to confirm. Every instance on every node is torn down before the record is removed. Remote users of that topology lose access and their configuration files cannot be reused.
4 controls explained
07 · Access Management → Enrol a device
Letting a person in
Procedure
- 1
Person — who this device belongs to
Search your directory. Picking someone fills their address and name from the same directory that will assert them at sign-in, and shows which access group they will land in and what they will reach. Typing an address by hand works too and produces an unbound device — one with no identity behind it, which no re-authentication deadline can apply to. - 2
Device — the machine and its file
Name the machine as your management system knows it, because device posture matches on that name; without it the person's most recently seen machine is judged instead. Config file name is optional and decides what the person downloads — useful when somebody has to recognise one file among forty at a support desk. The extension is the transport's, not yours. - 3
Access — what they may reach
Pick the overlay: the device reaches that overlay's sites and no others. Allowed subnets is client-side routing only — it tells the person's machine what to send down the tunnel, and it is not a firewall rule. When an access group applies to this person, that group's destinations replace this list and the hub enforces them. - 4
Link & term — how long, and the path out
Device term is how long the machine keeps working once enrolled. Link expires after is a different clock: how long the invitation stays open, which only has to survive the time between sending it and the person opening it. Then choose split or full tunnel, and where their internet leaves. - 5
Link ready — send the two halves apart
The link and the password are shown once and cannot be shown again; a lost one is replaced by minting a new link, never re-sent. Mail one, read the other out, or use a different messenger.
Controls · The two clocks, which are not the same clock
Operators confuse these because both say “expires”. They govern different things and one of them cuts a working tunnel off.
- Link expires afterselect
- How long the one-time invitation stays usable — minutes or hours. Once redeemed it is spent whatever the clock says. Nothing that has already enrolled is affected by it.
- Device termselect
- How long the device keeps working after it enrols, in days. At the end the hub switches the peer off. The person is warned a week before the date, and keeps working for a further week after that warning, so nobody loses a tunnel without notice. Change it later from the device card — Extend offers the same choices.
Controls · Handing the file over yourself
Sometimes the operator is holding the machine. The last step offers a shortcut that skips the link and the password entirely.
- Direct Download Configuration Filebutton
- Redeems the invitation there and then and downloads the finished file. The keypair is still made in a browser and the private half is still never sent anywhere — what changes is whose browser: yours. Two consequences follow, and both are stated on the button. It spends the invitation, so the link stops opening. And the file now carries the device's private key, so it has to travel as carefully as the password would have.
Controls · Fields worth understanding
- Person (from your directory)text
- Searches the people synced from Active Directory, Entra, Google Workspace or SCIM. Picking one fills the address and name and shows their groups and the access group they resolve to.
- Email addresstext
- The key for everything afterwards: the sign-in must match it, and the posture source is asked about this address. A directory account that authenticates correctly but belongs to somebody else does not open this invitation.
- Config file nametext
- What the person downloads, and on most clients the name of the tunnel they see. Letters, digits, dot, dash and underscore survive; anything else becomes a dash. Empty derives a name from the device label.
- What will apply to this accesspanel
- The four things that will be true of the device once it exists: whether a sign-in is required, when access is re-checked, whether the machine's state is enforced, and what the hub will allow. All set elsewhere, shown here so nobody enrols under assumptions that do not hold.
- A step that is not finished will not let you past it: the dialog sends you back to the step that owns the problem and says what it is, rather than failing at the end.
7 controls explained
08 · Suspending, reinstating, revoking
Devices after they exist
Controls · Badges
- Active · suspended · expired · revokedbadge
- Suspended is the console holding the device off at the hub — for a lapsed sign-in, an account the directory disabled, or a machine reported non-compliant. The reason is on the card.
- identity · unboundbadge
- Whether the device is bound to a person at a provider, or was enrolled with a link and a password only and is therefore time-limited rather than identity-limited.
- device ok · at risk · unknownbadge
- What the management system says about the machine. Absent entirely when device posture is off, because a badge nothing is maintaining is worse than no badge.
Controls · Actions
- Require sign-inbutton
- Puts the device into re-authentication now instead of at its deadline. A reminder is mailed and the link is copied for any other channel.
- Copy sign-in linkbutton
- The same link that lives as a comment in the person's configuration file, for when they cannot find it.
- Extendbutton
- Moves the deadline and reinstates a suspended device. An operator override, logged as one.
- Check nowbutton
- Asks the management system about this machine immediately and applies whatever the mode calls for. Use it after fixing a laptop instead of waiting for the next sweep.
- Revokebutton
- Removes the peer from the hub and releases its address. The configuration file stops working immediately and cannot be un-revoked.
8 controls explained
09 · Settings → Identity
Who may connect
Controls · The sign-in provider
- Providerselect
- Google Workspace, Microsoft Entra ID, or any provider with an OpenID Connect discovery document. Separate from the console's own operator login.
- Require sign-in for every new enrolmenttoggle
- Off means devices keep enrolling with a link and a password and show as unbound. On means no device is created until someone has proved who they are.
- Require multi-factortoggle
- Checks the token's
amrclaim for a multi-factor sign-in. The factor is the provider's; the console refuses a token that does not carry the claim. - Sign in again every N hoursnumber
- The re-authentication interval. A reminder goes a day ahead; at the deadline the device is switched off at the hub until the person signs in again.
- Redirect URItext
- The one address to allow at the provider. Which enrolment a sign-in belongs to travels in the state parameter, so one URI serves the whole console.
Controls · Identity sources
- Kindselect
- Active Directory, RADIUS, Entra, Google Workspace or SCIM. Each can verify people, read the directory, or both — a RADIUS server can verify but cannot be enumerated, and the dialog only offers what the protocol supports.
- Sync nowbutton
- Reads the directory immediately instead of waiting for the interval. The counts on the row are the result of the last read, not an estimate.
- Testbutton
- Proves the credentials and, for a source that can verify people, proves one person's sign-in without creating anything.
- A directory that reports someone as disabled suspends their devices without waiting for the deadline. That is the fastest off-switch in the product, and it is the directory's, not the console's.
8 controls explained
10 · Enrolment, renewal, and — for OpenVPN only — every connection
When the person is actually asked who they are
Procedure
- 1
At enrolment — in a browser, before the key exists
The person opens the invitation link and, if your tenant requires it, proves who they are right there on that page. Only then does their browser generate the key and receive a configuration. The identity is stored on the device and is what every later check compares against. - 2
At renewal — on a deadline, by a link
A device bound to an identity carries a re-authentication date. A day before it, the person is mailed a link; at the date, the hub switches their peer off until they open that link and sign in again. The tunnel goes quiet — no prompt appears on their machine, because there is nowhere for one to appear. - 3
On every connection — OpenVPN topologies only
OpenVPN can ask, so it does: it asks on every connection and every renegotiation. Tick use for OpenVPN connections on an Active Directory or RADIUS source and the console writes that server into the hub's own authentication servers. From then on the firewall asks your directory directly — not the console — so people keep getting in while the console is unreachable.
Controls · What each kind of source can actually do
The dialog only offers what a protocol supports, which is why a source you added may not appear as a sign-in option. Reading a directory and checking a password are different capabilities and not every kind has both.
- Active Directory / LDAPbadge
- Checks passwords ✓ · Lists people ✓. The only kind that does both. Its people fill the person picker, its groups drive access groups, and it can verify a sign-in at enrolment, at renewal and on an OpenVPN connection.
- RADIUSbadge
- Checks passwords ✓ · Lists people ✗. It can verify somebody but cannot be enumerated, so it never populates the person picker. It is the only kind that can come back with a challenge — a one-time code — and an answered challenge is recorded as a multi-factor sign-in. MS-CHAPv2 is not offered.
- Microsoft Entra IDbadge
- Checks passwords ✗ · Lists people ✓. Read-only over Graph. It tells the console who exists and which groups they are in. It cannot verify anybody — for that, add Entra as the sign-in provider instead, which is a browser redirect, not a password check.
- Google Workspacebadge
- Checks passwords ✗ · Lists people ✓. Same shape as Entra: a directory to read, not a place to verify a password.
- SCIM (push or pull)badge
- Checks passwords ✗ · Lists people ✓. SCIM is provisioning: your identity provider tells the console who joined and who left. It carries no password and can never authenticate anyone.
- Sign-in provider (OpenID Connect)badge
- Not in the source list at all — a tenant has exactly one and it lives in Settings → Identity, because it works by sending the browser to the provider rather than by checking a password. It is what verifies people when your directory cannot.
Controls · What the person sees on the enrolment page
- Sign in with ‹provider›button
- Leaves for your identity provider, comes back proved. The console never sees the password. This is the row you get from the sign-in provider.
- Work accounttext
- An account name and a password, checked against your Active Directory or RADIUS. Shown when a source has use for authentication ticked. If both methods exist the page offers the button, then “or”, then this form.
- One-time codetext
- The same form after a RADIUS challenge. The server's own wording is shown above the box; the person types the code and continues.
- Neither offeredpanel
- A tenant with no sign-in provider and no password-checking source has nothing to ask with. Enrolment still works — the link and the password are the authorisation — and the device is created unbound.
- Whoever signs in must be the person who was invited. A perfectly valid directory account that answers with a different address is refused, so one employee cannot redeem another's invitation.
- An unbound device — enrolled without any identity — has no re-authentication deadline, because there is nobody to ask. It lives until its device term ends or somebody revokes it.
10 controls explained
11 · The model behind the Access tab
What a group and an application are, and what this is not
Controls · The words, precisely
- Applicationpanel
- A named destination: one or more IPv4 addresses (a single host is a /32) and the ports it answers on, each with its protocol. It describes the server side only. On its own it grants nobody anything; it exists so a group can name a service instead of a subnet.
- Access grouppanel
- The policy. Who: the group names your directory or sign-in provider reports for a person, matched case-insensitively. What: the applications it grants, plus any whole networks. A person in the group gets every application and network the group lists, and nothing else.
- Default grouppanel
- The floor. Whoever matches no group — and every device enrolled without a sign-in — lands here. Without one, those people are not enforced at all and reach whatever the tunnel routes.
- Whole networkpanel
- A network granted on every port. Wider than an application, and sometimes exactly right: the management network for the people who run it. It is what every group used before applications existed.
- The group's second jobpanel
- The dialog says it: the group name is also the policy-template group name for these people. The same word therefore decides two things — what the hub lets through, and which of the firewall's own per-group policies apply to their traffic afterwards. The dialog's Applications blocked at Layer 7 list is the direct form of that second job: the console writes a policy group of its own on every hub,
zedmos-sase-<name>, naming these people and the applications the engine is to refuse them.
Controls · Three artefacts from one group
A group produces three things, and only the last two enforce anything.
- The person's configuration filetext
- Its
AllowedIPsline lists the group's destinations, so the person's machine sends only that traffic down the tunnel. This is routing, and it lives on a machine the person controls: helpful, never enforced. - The hub's rulespanel
- For each person, keyed on their tunnel address, on the user-tunnel interface only: DNS at the hub, one line per application and protocol, then a drop for everything else. This is the boundary. It does not care what the file says.
- The engine's policy grouppanel
- Only when the group lists applications to block at Layer 7: a policy group on each hub's engine, naming the same people, that refuses those applications inside the traffic the rules above let through. Where the rules ask which address, this asks which application — and needs the engine to see the tunnel, which the Access chapter explains.
Controls · Where identity is checked
- At enrolment and at renewalbadge
- The person proves who they are in a browser when the device is enrolled and again at each re-authentication deadline. In between, the tunnel address is the identity: the rules are written against it. There is no per-request check, because the tunnel never sees a request — only packets. The chapter before this one has the detail.
Controls · What this is, and what it is not
Products that do this work come in two families, and it matters which one you are holding.
- Broker-basedbadge
- A cloud proxy sits between the person and the service. It identifies the person on every request, understands hostnames and URL paths, and never lets a tunnel into the network at all. This console is not that.
- Network-basedbadge
- The person's device joins the network through a tunnel, identity is bound to that tunnel, and a packet filter at the gateway decides what each tunnel may reach. This console is that. The same family as the mesh and gateway products built on WireGuard.
- What follows from itpanel
- Destinations are addresses: an application is
10.10.20.5, or a hostname the console resolves to addresses for you — never a URL path. Rules are address and port. Identity holds between checks rather than per request. IPv4 only, today. Application-level control exists, but it is the engine's, on the hub, recognising GitHub or YouTube inside permitted traffic — not a proxy reading paths. In exchange, the gateway keeps enforcing exactly what it was last told even while the console is unreachable, and nothing of yours transits anybody's cloud.
Controls · Five things people build with it
- A contractor and one systempanel
- Application: the ERP host on
tcp/443. Group: contractors, granting that one application. The contractor's tunnel reaches one port on one host; the rest of the site does not exist to them. - The people who run the networkpanel
- Group: it-admins, granting the management network as a whole network. Every port, because that is what administration needs — and only to the people in that directory group.
- No directory yetpanel
- A single default group granting the two or three services everyone actually uses. Every device lands in it, bound or not. It is not least privilege by person, but it is a floor, and it is what to run until a directory is connected.
- Someone leavespanel
- Disable them in the directory, or delete the application they used, or take them out of the group. The hub's rules are rewritten within seconds and their open sessions end with them. Nothing has to be done on the person's machine.
- Access that ends on a datepanel
- Every device carries a term. A contractor's laptop can be given thirty days at enrolment; it is warned before the date and switched off after it, without anyone remembering to do so.
- Name applications after the service as people say it — Payroll, Wiki — not after the host. The device card shows the group, the group dialog shows the applications, and a name a person recognises is what makes an access review readable.
17 controls explained
12 · Settings → Access
What they may reach, and on what machine
Procedure
- 1
Define the service
Applications → Add application. An address and its ports:10.10.20.5/32,tcp/443, tcp/8443. A single host is a /32, and a /32 is usually right. Nothing changes on any hub yet — an application on its own grants nobody anything. - 2
Grant it to a group
Access groups → Add group. Name it, list the directory groups it matches, tick the applications. Save & apply pushes rules to every hub that carries a person in this group, and the device cards showaccess: <group>for each of them. - 3
What the hub writes
Per person, keyed on their tunnel address, on the user-tunnel interface only — never on the site's LAN traffic. First DNS at the hub, then one line per application and protocol, then a drop for everything else. A person in the group above gets, on the hub, exactly:pass in quick on wg1 inet proto tcp from 10.200.4.10 to { 10.10.20.5/32 } port { 443, 8443 } keep state, thenblock drop in quick on wg1 inet from 10.200.4.10 to any. - 4
What the person experiences
The granted port answers as if nothing were in the way. Every other port on that host, every other host, and even ping are dropped silently — a connection attempt sits for its full timeout rather than being refused, which is the drop rule doing its job. Measured on a hub::443answered in under half a second;:22,:80, another host and ICMP all timed out. - 5
Take it away
Delete the application, untick it in the group, or edit the group so the person no longer matches. The hub's rules are rewritten within seconds, new connections to the service are refused from then on, and the person's open sessions end: the hub is told which people's access changed and drops their established connections, so a revoked service does not linger in a browser tab or an SSH window until it idles out. People whose access did not change are not touched.
Controls · Access groups
- Provider groupstext
- The group names as your provider reports them, matched case-insensitively against what the person's sign-in carried.
- Applications this group may reachpanel
- Named services with their ports. This is the narrow grant, and the one to reach for first.
- Whole networkstext
- IPv4 ranges granted on every port. Wider than an application, and sometimes exactly right — a management network for the people who run it.
- Applications blocked at Layer 7text
- Application names as the engine classifies them —
GITHUB, YOUTUBE, DROPBOX. The people of this group cannot use these applications even at an address the grants above allow. Enforced by the engine on the hub, not by the packet filter; see the table below for what that needs. - Default grouptoggle
- Applies to everyone who matches nothing else, including unbound devices. Give it the least you can live with.
- Reapply on hubsbutton
- Rewrites every hub's rules from the current groups. This happens automatically after every enrolment, sign-in, suspension and group change; the button is for when you want to be sure.
Controls · Applications
Where a service lives and which ports it answers on.
- Where it livestext
- One or more IPv4 ranges, or a hostname. A single host is a /32, and a /32 is usually the right answer. A hostname —
erp.acme.internal,api.stripe.com— is resolved by the console and the hub enforces the addresses it resolves to; the row shows what a name currently resolves to, and re-resolves on its own as the answer moves. A name is the honest way to grant a service whose address you should not have to track by hand. Wildcards are not accepted here yet. - Which portstext
443,8000-8080, orudp/53. Without a protocol a port is read as tcp. Each protocol becomes its own firewall rule, because that is how the packet filter reads them.- Enabledtoggle
- Off keeps the application on the groups that grant it but stops granting it — the quickest way to take a service out of reach without unpicking policy.
Controls · Naming a service instead of numbering it
How a hostname becomes a firewall rule, and what to trust it for.
- What resolves the nametext
- The console, not the box. It renders the whole rule set and the box only loads it, so a name is resolved in one place and enforced the same way on every runtime — OPNsense, pfSense, Zedmos NGFW — with nothing new on the box.
- What the hub enforcespanel
- The addresses, never the name. Grant
dns.googleontcp/443and the hub writes, per person,pass in quick on wg1 inet proto tcp from 10.200.4.77 to 8.8.8.8 port = httpsand the same for 8.8.4.4, then the block-drop. The name is a convenience for you; the packet filter still matches addresses and ports. - When the address movestext
- A background job re-resolves every name in play and, for a tenant whose answers changed, rewrites only the rules that moved and ends exactly those people's open sessions — the old address closes and the new one opens with nothing else disturbed.
- What it does NOT dotext
- It is not deep packet inspection. It does not read the TLS SNI or the URL, and it cannot tell two services apart that share an address. A name is a way to find the right addresses, not a Layer-7 identity — that is the engine's job, and the next table is where the same group asks it.
- Fail-closedtext
- A name that has never resolved contributes no address, so its rule is simply absent and the person reaches nothing for it — access is never widened by a DNS failure. A name that resolved once keeps its last good answer through a later hiccup rather than dropping access.
Controls · Application-level, Layer 7: what they may not use
The same group, a second enforcement plane. The grants above decide which addresses a person may reach; this decides which applications the engine refuses them, whatever address the application is on.
- Where it is settext
- In the access group dialog, Applications blocked at Layer 7. One place to author both planes: a group that grants the internet and blocks
GITHUBlets its people browse and refuses them GitHub, at every address GitHub answers from. - What the console writespanel
- One managed engine policy group per access group,
zedmos-sase-<name>, on every hub that carries a user tunnel, placed ahead of the catch-all so a matching person is judged by it first. It names exactly the people the group reaches — the same resolution that wrote their firewall rules — together with the group's directory groups, and carries the block list. Proven on a hub:groups=[Finance] users=[finance-user@…] block=[GITHUB], orderzedmos-sase-finance, Default. - What the person experiencestext
- GitHub is reset the moment the engine recognises it — measured at four milliseconds through the tunnel, at an address the firewall rules allow — while everything else on that same grant answers normally. Take the application off the list and the next connection goes through; nothing to do on their machine.
- Kept currenttext
- Rewritten when a group changes and when a person enrols, is suspended, reinstated or revoked, and only when the result differs from what the hub already holds — the engine reloads on every save, so an unchanged policy is never pushed. The identity feed the engine needs to recognise the person is re-pushed alongside.
- What it needs on the hubtext
- The engine must see the tunnel: the hub's user-tunnel interface has to be a protected interface (Firewall → Settings → Interfaces → Protected interfaces; give it a zone). Until it is, the policy is written but inert, and the save result says so —
wg_not_protectednaming the topology and the interface. Turn it on there, deliberately; the console never toggles the data plane for you. - What it does NOT dotext
- It does not replace the grants: a person still reaches only what the group grants. It does not run where the engine is off or the tunnel is not protected. And it classifies applications, not content — what is written inside an allowed application is the DLP layer's business, not this table's.
Controls · Device posture
Read from the management system you already run. Nothing of ours is installed on the endpoint.
- Off · Observe · Enforceselect
- Off reads nothing. Observe reads and shows. Enforce switches a non-compliant device off and lets it back in by itself once the machine is healthy. Turning it back down releases everything it had switched off.
- Read fromselect
- Intune uses its own compliance verdict plus disk encryption and the threat state its security product reports. CrowdStrike Falcon has no compliance verdict, so the question asked is the one it can answer: whether the sensor is installed and running.
- Read each device again everynumber
- How often a device is re-read. A management API is a shared resource; this is the dial that stops a thousand laptops being asked about every minute.
- Also switch off machines nobody can speak fortoggle
- The strict reading. Leave it off unless every machine is enrolled — with it on, a broken connector disconnects everybody.
- Event URLbutton
- A token-gated address your management system can call the moment something changes. It can ask for a device to be re-read, or report one compromised; it cannot assert that a device is healthy. Shown once; minting a new one retires the old.
Controls · A worked example, field by field
A contractor who must reach one accounting system and nothing else. Every value below is what to type; every line after it is what the console then does.
- 1 · Applications → Add applicationtext
- Name
Finance ERP. Where it lives10.10.20.5/32. Which portstcp/443, tcp/8443. Enabled. Save. Nothing reaches any hub yet. - 2 · Access groups → Add grouptext
- Name
contractors. Identity-provider groupsContractors— the group name exactly as your directory reports it. Tick Finance ERP. Leave whole networks empty. Default group off. Save & apply. - 3 · What the table now showspanel
- Grants: Finance ERP. People: how many enrolled devices resolve to the group right now. If it says nobody yet, no device carries the group name
Contractors— either the person has not enrolled with a sign-in, or the directory has not been read. Nothing is enforced until that number is at least one. - 4 · Enrol the contractortext
- Private Access → Enrol device. Pick them from the directory so the sign-in binds their groups. Device term: 30 days. Config file name:
acme-contractor. Send the link and the password apart. - 5 · What the person's file containstext
AllowedIPs = 10.10.20.5/32and the hub's DNS address — the group's destinations, nothing else. Their machine sends only that down the tunnel. This is routing on their side; it is not what protects you.- 6 · What the hub writes for thempanel
pass in quick on wg1 inet proto tcp from 10.200.4.10 to { 10.10.20.5/32 } port { 443, 8443 } keep state, DNS to the hub, thenblock drop in quick on wg1 inet from 10.200.4.10 to any. Keyed on their tunnel address, on the user-tunnel interface only.- 7 · Check it from their sidetext
https://10.10.20.5answers.ssh 10.10.20.5hangs and times out — dropped, not refused. Any other host, the same. The device card readsaccess: contractors.- 8 · When the contract endstext
- Delete the application, or disable the person in the directory, or wait for the 30-day term. Within seconds the hub's rules are rewritten and the open sessions end. Nothing to do on their laptop.
- An application grants a service; a group grants it to people. Build the application first, then the group — a group saved with nothing ticked and no networks listed grants DNS at the hub and nothing else, which is a very quiet way to lock everyone out.
- Run posture in observe for a working day and count how many devices read unknown. That number is exactly how many people enforcing would disconnect if you also ticked the strict reading.
- An application with an empty port list is a network grant with a friendlier name. Allowed, and sometimes right, but it is not least privilege.
33 controls explained
13 · SD-WAN and Monitor
Watching it afterwards
Controls · SD-WAN
- Target rowpanel
- One uplink or tunnel on one firewall: latency, loss, jitter and the composite score, with the current best marked. An overlay tunnel appears beside the physical links and competes on the same score.
- Open Application Routingbutton
- Jumps to that firewall's own routing rules, where the steering is actually written. The console does not choose paths; the firewall does, five seconds at a time.
- No SLA agent on this platformbadge
- That node cannot measure. Its tunnels still work — they are simply not scored, and a rule that says best will not consider them.
Controls · Monitor
- Healthpanel
- Per-hub checks and per-spoke latency, loss and jitter, measured by the hub on every poll. Probe now takes a fresh reading instead of waiting.
- Alert rulespanel
- Failover fired or restored, both hubs down, a spoke offline, loss or latency past a threshold, a deploy that failed. Delivered by mail, webhook or Slack, with a cooldown so one flapping link does not become a hundred messages.
- Operation logpanel
- Every change the console made to a firewall and the answer it got back. The first place to look when something changed and nobody remembers doing it.
6 controls explained
If you read one thing twice
Build the overlay, then close the gap the tunnel leaves. A key proves a device; a directory proves a person; an access group decides what that person reaches; a deadline keeps it true; and the management system you already run says whether the machine in their hands should be there at all. Each of those is one screen in this manual, and each one is optional — which is exactly why it is worth knowing which ones you have turned on.