QuestionQ14

Protect and Defend

Your company has an HPE Aruba Networking infrastructure that includes a variety of HPE Aruba Networking APs and gateways. The company has recently added HPE Aruba Networking SSE. The company needs to enhance security for branch users behind an HPE Aruba Networking SD-WAN gateway.

You need to control users’ actions across various SaaS applications. What is included in the setup?

  • A Enable gateway IDS/IPS on the gateway's group in HPE Aruba Networking Central
  • B Configure an HPE Aruba Networking Central API token on HPE Aruba Networking SSE
  • C Use HPE Aruba Networking Central to establish an IPsec tunnel between the gateway and HPE Aruba Networking SSE
  • D Configure IPsec crypto maps on HPE Aruba Networking SSE
Explanation

To apply SSE-based controls governing specific user actions within SaaS applications to traffic originating behind an SD-WAN gateway, that traffic must first be forwarded to the SSE service for inspection; HPE Aruba Networking Central is used to configure and establish the IPsec tunnel between the SD-WAN gateway and HPE Aruba Networking SSE so gateway traffic is steered to the cloud service where CASB-style application-action policies are enforced.

Community Discussion

No comments yet. Be the first to start the discussion!