Cisco Catalyst SD-WAN Control Components and Device Management Guide, Releases 26.x and Later

PDF

Cellular gateways

Want to summarize with AI?

Log in

Describes the role of a cellular gateway in bridging cellular WAN connectivity to enterprise LANs and enabling secure remote management.


A cellular gateway is a network device that

  • provides wireless connectivity to a wide area network (WAN),

  • functions as a bridge between cellular networks and enterprise LANs, and

  • supports secure remote management and monitoring.

Secure communication with devices through a vmanage-admin account

SD-WAN Manager communicates with devices, such as Cisco Catalyst Cellular Gateways, using a secure channel—either a datagram transport layer security (DTLS) tunnel or transport layer security (TLS) tunnel. Within this secure channel, it communicates with the devices or controllers using the NETCONF protocol, within an SSH session. It uses an internal-use-only passwordless "vmanage-admin" user account on the device or controller. The vmanage-admin account is created during the initial device setup. Cisco SD-WAN Manager uses this secure channel for monitoring, configuring, and managing devices.

As noted, the vmanage-admin user accounts do not have any password associated with them, so SD-WAN Manager uses a passwordless procedure to log in to the account. To accomplish this, SD-WAN Manager generates an asymmetric encryption public-private key pair. During deployment of a device, SD-WAN Manager copies the public key that it has generated to the device. It sends the public key using a proprietary protocol, within a secure channel—a DTLS or TLS tunnel.

The activity that SD-WAN Manager performs using the vmanage-admin account appears in syslog messages and in the output of certain show commands. The syslog messages are logged with the same level of detail as activities performed through any other user account. The level of syslog detail depends on the syslog configuration of the device.

Note

SD-WAN Manager requires the vmanage-admin account on devices in order to monitor, configure, and manage the devices. Removing, disabling, or altering this account on a device would prevent Cisco SD-WAN Manager from performing these activities, and is not supported.


Supported Cellular Gateway devices

This sections provides information about the supported Cisco Catalyst Cellular Gateway models.
  • CG418-E

  • CG522-E