Create Secure Mesh Site v2
Overview
This document provides instructions on how to deploy an F5 Distributed Cloud Customer Edge (CE) Site across all supported providers. For on-premises providers, this includes VMware, Nutanix, OpenShift Virtualization, and OpenStack. For public cloud providers, this includes AWS, AWS Elastic Kubernetes Service (EKS), Azure, GCP, and Oracle Cloud Infrastructure (OCI).
This new and simplified workflow also includes enhancements to remove certified hardware, and a single endpoint for CE registration.
Available providers
The following providers are Generally Available (GA):
- VMware
- AWS
- Azure
- GCP
- OCI
- Nutanix
- OpenStack
- Equinix
- Bare metal
- OpenShift Virtualization
The following providers are Early Access (EA):
- KVM
- AWS EKS
Plan your deployment
Read the following documents before deploying a Secure Mesh Site in any provider environment:
- Understanding F5 Distributed Cloud - Customer Edge (CE)
- CE Datasheet
- CE Supported Platforms Guide
- Customer Edge Site Sizing Reference
- CE Performance Guide: Contact your account representative on CE performance-related information.
- Proxy for CE Registration and Upgrades Reference
- Secure Mesh Sites v2 Frequently Asked Questions
- Customer Edge Registration and Upgrade Reference
- F5 Customer Edge IP Address and Domain Reference for Firewall or Proxy Settings
Before you begin
Before you begin, make sure you have:
-
An F5 Distributed Cloud account. If you don't have an account, see Get Started with Distributed Cloud Console.
-
One or more devices or VMs consisting of interfaces with Internet reachability for CE Site deployment.
-
The resources required per node:
- A minimum 8 vCPUs, 32 GB RAM, and 80 GB disk storage. For a full listing of the resources required, see the Customer Edge Site Sizing Reference guide.
- All the nodes in a given CE Site must have the same resources regarding the compute, memory, and disk storage. When deploying in cloud environments, these nodes must use the same instance type.
-
Opened the port for ICMP between the CE nodes on the Site Local Outside (SLO) interfaces to make sure intra-cluster communication checks work.
-
Configured your firewall or proxy server to allow connections from and to the IP addresses and domains listed in the F5 Customer Edge IP Address and Domain Reference for Firewall or Proxy Settings guide.
-
Reviewed additional deployment information to prevent any unwanted configuration or deployment issues.
-
Reviewed the latest features and releases. See Node Operating System and Software Changelogs for more information.
-
Turned on AVX (Advanced Vector Extensions) on hardware where your CEs are deployed if you're using F5 Distributed Cloud WAF. If you don't turn on AVX, you can't use the AI features for F5 Distributed Cloud WAF.
Important: You can't change the IP address for the SLO interface or the MAC address after the CE deploys.
Configuration overview
Use the following sequence of actions to deploy a CE Site in your provider's environment:
-
Choose the provider where your Secure Mesh Site is deployed. Configure additional parameters as required. Apart from the provider, all parameters are optional.
-
Prepare to deploy nodes. The recommended options to deploy depend on your provider environment:
- For VMware, OpenStack, Nutanix, KVM, Baremetal, OCI, and OpenShift Virtualization: Download the CE node image from the F5 Distributed Cloud Console. Use the Download Image or Copy Image Name options.
- For AWS, Azure, GCP, and Equinix: Use the Launch Instance option to deploy your instance directly from the corresponding provider's marketplace.
-
Check out node token when deploying a node. Each node you deploy requires a unique token generated in F5 Distributed Cloud Console.
-
Deploy nodes. If the high availability (HA) option is turned off, then your CE Site can only support one node. If the HA option is turned on, then the CE Site requires three nodes. You can only add additional nodes to your CE Site when the HA option is turned on.
Additional deployment information
You must review all optional parameters while configuring the site object to make sure the CE node deployment matches your environment. You can't change a few properties after you deploy the CE Site. If you need to change any of these, redeploy your CE Site.
Tokens are ephemeral and expire within seven days. Generate the node token while deploying a node. Don't pre-stage tokens.
You can't change the High Availability option after your CE Site is created.
If you add a new network interface, all the data plane services restart. Therefore, do this during maintenance windows. As data plane services restart, expect traffic drops and tunnel outages. When adding interfaces, add the interfaces to each node in the cluster. Nodes with non-homogenous interfaces within a CE Site might cause issues. Therefore, each node in a given CE Site should have the same number of interfaces placed in the same VRFs.
Power off each node VM when adding new interfaces or changing existing ones.
Create a Secure Mesh Site
Log in to F5 Distributed Cloud Console to create a Secure Mesh Site object.
Note: Default values work for most deployments. Customize only for advanced use cases.
Step 1: Enter metadata information for Site.
-
In the Multi-Cloud Network Connect workspace, go to Manage > Site Management > Secure Mesh Sites v2.
-
Select Add Secure Mesh Site to open the configuration form.
-
In the Metadata section, enter a name for the Site.
-
Optionally, select labels and add a description.
Step 2: Select the infrastructure provider settings for Site.
-
From the Provider Name menu, select the infrastructure provider from the options available. See the following provider-specific documentation to deploy infrastructure in that provider:
- For High Availability, select an option. If it's turned off, your CE Site can only support one node. If it's turned on, then your CE Site requires three nodes. You can only add more nodes to CE sites when High Availability is set to Enable.
Important: You can't change the High Availability option after your CE Site object is created and deployed.
Step 3: Configure RE Site options.
Use the following steps to configure the regional edge (RE) Site settings in the Regional Edge section. Your CE Site connects to the RE Site for registration purposes.
-
From the Regional Edge Selection drop-down menu, select the RE geography to use. By default, the Based on Geo-proximity option selects the closest RE to where you are deploying your CE. However, you can select any RE that suits your geographical needs by selecting Specific Geography. If you select Specific Geography, make sure that you select the primary and backup RE, which must be different. The Primary RE Geography and Backup RE Geography options can't be the same.
-
Optionally, select the Site-to-Site tunnel encryption type from the Tunnel Type menu. The default option is IPsec/SSL. When IPsec/SSL is used, IPsec takes priority. If registration happens over a private application delivery network (ADN), only select SSL.
-
Optionally, configure the timeout value for Site tunneling from the Tunnel Dead Timeout (msec) menu. The default option is 0 milliseconds.
-
Optionally, turn on the offline survivability feature from the Offline Survivability Mode menu. For more information, see the Manage Site Offline Survivability guide.
Step 4: Configure Site networking options.
Use the following steps to configure the CE Site networking settings in the Site Networking section.
Site Local Outside Network (SLO) connects the CE node with the F5 Distributed Cloud Regional Edges (REs). It can also work as a public/WAN network. This network typically requires connectivity to the Internet. To add a custom DNS server or static routes to this network, then from the Site Local Outside Network menu, select Configure Site Local Outside Network. Then select View Configuration. You can add custom static routes and common VIP for load balancers (this can be overridden on a per load balancer basis in the Advertisement Policy). And you can add DNS servers for the SLO network. The SLO network supports secondary DNS servers. To configure secondary DNS servers, make sure that you are on version crt-20251001-0189. See the official releases notes guide for more information.
Note: After you configure the SLO interface with a static IP address, DHCP displays in the Console. However, your static IP configuration is well taken into account. Also, remember that you can't change SLO parameters after the node is registered and deployed.
Site Local Inside Network (SLI) represents the internal network (LAN). If a custom DNS server or static routes need to be added into this network, then from the Site Local Inside Network menu, select Configure Site Local Inside Network. Then select Configure. Here you can add custom static routes, common VIP for load balancers (this can be overridden on a per load balancer basis in the Advertisement Policy), or DNS servers for the SLI network. The SLI network supports secondary DNS servers. To configure secondary DNS servers, make sure that you are on version crt-20251001-0189. See the official releases notes guide for more information.
Note: Site Local Inside is an optional network. Consider using Network Segments from Multi-Cloud Network Connect > Networking > Segments for internal networks. Network segments are flexible and can be used to keep networks isolated within an environment. In other words, they are restricted to a single CE Site or can be also used for seamless extension of networks across multiple hybrid/multi-cloud environments (across multiple CE sites).
-
Optionally, configure any network settings for each of the segments that are configured on the CE. Under Segment VRF Settings, select Add Item. Do the following:
- From the Segment (Global VRF) menu, select your segment.
- From the Manage Static Routes menu, select whether to configure static routes with Manage Static routes. Select Add Item for each route you want to add. Configure the route settings, and then select Apply.
- Optionally, add DNS and secondary DNS servers for this new segment. This helps make sure that your CE Site can resolve origins defined by name. It acts as a DNS client and sends DNS requests within the segment to the defined DNS server. Only single-node CE sites (non-cluster mode) support per-segment DNS and secondary DNS. Make sure that you are on version crt-20251001-0189. See the official releases notes guide for more information.
- Select Apply.
-
To configure virtual IP address (VIP) redundancy when operating load balancers advertised on a CE in L2 adjacency mode: From the Load Balancer Settings section, select Enable VRRP for VIP(s) from the VRRP Mode drop-down menu.
Step 5: Configure Site-to-Site connectivity options.
Use the following steps to configure the CE Site networking settings in the Site To Site Connectivity section.
-
To connect your Site to other sites using the SLO network: From the Connect using SLO Local VRF drop-down menu, select an option:
-
Site Mesh Group: This option connects your Site to other Sites in a mesh network. You can connect using a public IP or a private IP. For more information, see the Configure Site Mesh Group guide.
-
Member of DC Cluster Group: This option places your Site within a Direct Connect (DC) Cluster Group. For more information, see the Configure DC Cluster Group guide.
-
-
To connect your Site to other sites using the SLI network, from the Connect using SLI Local VRF menu, select Member of DC Cluster Group. For more information, see the Configure DC Cluster Group guide.
Step 6: Configure network security for Site.
Use the following steps to configure the CE Site networking security settings in the Network Security section.
-
From the Network Firewall menu, turn on an enhanced firewall by selecting it from the drop-down menu. Use Add Item to add more than one firewall. For more information, see the Create Network Firewall guide.
-
From the Forward Proxy menu, turn on a forward proxy by selecting it from the drop-down menu. Use Add Item to add more than one policy. The network traffic is processed based on the order set. For more information, see the Create Forward Proxy Policies guide.
Step 7: Configure performance mode.
Use the following steps to configure the CE Site performance mode in the Services & Resources section.
-
In the Services & Resources section, from the Performance Mode menu, select an option:
-
L7 Enhanced: This option optimizes the CE Site for Layer 7 traffic processing and is the default option. Jumbo frames for L7 Enhanced mode can only be turned on for single-node sites (non-cluster deployments). Multi-node sites (clusters) currently require jumbo frames to be turned off. You can turn on jumbo frames for your HTTP and TCP load balancers that are deployed on your CEs. If you turn on jumbo frames on existing single-node CEs, it may cause the CE to restart. F5 recommends that you make mode changes during a maintenance window.
-
L3 Enhanced: This option optimizes the CE Site for Layer 3 traffic processing. If you select this option, then no L7 functionality is provided for your Site, such as load balancing. If you are using this mode, select whether to use this mode with or without jumbo frames. If L3 Enhanced mode isn't turned on for every CE site in a Site Mesh Group, then the MTU on the Site-to-Site tunnel interfaces won't be consistent. F5 recommends that you turn on L3 Enhanced mode on all CE sites participating in a Site Mesh Group.
-
Important: To turn on jumbo frames for L7 Enhanced mode, make sure that you're on version crt-20251001-0189. See the official releases notes guide for more information.
- Optionally, from the URL Categorization menu, select whether you want your CE Site to include the required egress domains in an allowlist. If you turn on this option, a container downloads into your CE. This container turns on a service that includes the allowlist domains from the
Webroot URL Classification Databasein this section: Egress Domain Rules. URL Categorization classifies domains and URLs into different categories. For example, business, communication, and entertainment.
Step 8: Configure Site management options.
Step 8.1: Configure software settings.
-
From the F5XC Software Version menu, keep the default selection of Latest SW Version or select F5XC Software Version to specify an older version number.
-
From the Operating System Version menu, keep the default selection of Latest OS Version or select Operating System Version to specify an older version number.
Step 8.2: Configure node upgrade settings.
From the Node by Node Upgrade menu, select how each worker node is upgraded. This configuration doesn't apply to the control node(s). Optionally, configure Upgrade Wait Time, Node Batch Size, and Node Batch Size Count.
Step 8.3: Configure admin credentials.
-
Under Admin Password, select Configure. Configure the options for Secret Type, Action, and Policy Type. Enter your password in the Secret to Blindfold box. Select Apply.
-
Enter your public SSH key.
Step 8.4: Optionally, configure management network for single-node CE Site only.
From the Management Network menu, select whether to turn on the management network for your single-node CE Site. This feature isn't supported for a multi-node CE Site (cluster). This is off by default.
If you turn on this option, a separate network interface is created. This new network interface isn't an SLO or SLI network interface. You can use the management network for out-of-band management of services (SSH and web UI) and troubleshooting (run Site CLI commands and send syslog files out). Because the management network is an out-of-band interface, it isn't involved in the CE node forwarding plane.
Make sure that you are on version crt-20251001-0189. See the official releases notes guide for more information.
The management interface operates in a separate Virtual Routing and Forwarding (VRF) function on the kernel, which ensures complete isolation from the data plane traffic.
If you turn on the management network interface, the order of interfaces becomes:
-
Management network interface
-
Site Local Outside (SLO) interface
-
Any additional interfaces added become part of the Site Local Inside (SLI) interface
Step 8.5: Configure node services, monitoring, and log streaming.
The local web UI, SSH, and DNS services on each node in a CE Site are turned on by default.
-
To turn off any of these services, from the Node Local Services menu, select Disable. Select Add Item for each service you want to turn off. Then, select the Site Local VRF on which the service will be turned off. By default, these services are turned on to help with CE Site troubleshooting.
-
From the Logs Streaming menu, select Enable to configure a log receiver. Keep Disable selected if log streaming isn't required. If you turn on streaming, select the log receiver and the network to use from the Network for Log Streaming menu.
Step 8.6: Configure enterprise proxy server settings.
By default, all CE sites use the F5 Enterprise Proxy, which is hosted by F5 in the F5 Global Network to register with F5 Distributed Cloud.
- If you want to use a custom proxy hosted in your enterprise environment:
- From the Enterprise Proxy menu, select Custom Enterprise Proxy and provide your enterprise proxy settings, such as Proxy IPv4 Address, Proxy Port, Username, and Password. Also, you can select to use this custom enterprise for proxy-to-proxy tunnels from the nodes of this CE Site to the F5 Distributed Cloud Regional Edges (REs) by choosing Enable from the Use for RE Tunnels menu.
Important: When Use for RE Tunnels is turned on, the CE Site always establishes a connection to the F5 REs using SSL tunnel encapsulation, even if the RE tunnel type is set to IPsec and SSL. After the CE Site comes online, the tunnel type setting in the RE section (Step 3) changes to SSL. When RE tunnels are formed through a custom proxy, IPsec can't be supported because Internet Key Exchange (IKE), which is UDP-based, can't be routed through a custom proxy. The Site setting therefore turns off IPsec and uses SSL only.
You can't change Use for RE Tunnels after you create the CE Site. To change it, create a new CE Site and redeploy all nodes.
- From the Enterprise Proxy menu, select the Private ADN Network - (EA) option when your CE Site needs to use private connectivity for registration with the F5 Distributed Cloud Global Controller and tunnel connectivity with REs. Then select the network from the list.
Note: CE registration over Private ADN Network - (EA) is an Early Access feature and is only supported with AWS provider.
- From the Proxy Bypass Settings drop-down menu, select Custom to add domains to bypass the forward proxy server.
Step 8.7: Configure DNS and NTP server settings.
-
Optionally, configure custom DNS servers:
- From the DNS Servers menu, select Custom.
- Select Add Item and enter a server. You can add multiple DNS servers.
-
Optionally, configure custom NTP servers:
- From the NTP Servers menu, select Custom.
- Select Add Item and enter a server. You can add multiple NTP servers.
Step 9: Complete the Site object creation.
Select Add Secure Mesh Site to complete creating the Site. The Status field for the Site object displays Validation in progress. After validation, the field displays Validation Succeeded.
Important: You can't change certain settings after the CE Site object is created. Make sure that all settings for your CE Site are configured as required before selecting Add Secure Mesh Site to avoid recreating the CE Site object and redeploying the CE nodes.
Deploy and register a CE Site
See the following provider-specific documentation to deploy and register your CE Site:
Day 2 operations
See the following documentation for additional CE Site operations:
- To monitor your Site, see the Monitor Site guide.
- To manage your Site software and OS updates, see the Manage Site guide.
- For troubleshooting issues, see the Troubleshooting Guide for Secure Mesh Site v2 Deployment guide. It provides step-by-step instructions to debug and fix registration and provisioning errors.
- For the latest on Distributed Cloud Services releases, see Changelogs.
- To view the various types of events generated, see the Events Reference guide.
Related how-to guides
To create a load balancer on the CE Site, see the HTTP Load Balancer or the TCP Load Balancer guides.
References
For more information, see: