---
title: "Configure a Netskope cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/1611202/Configure%20a%20Netskope%20cloud%20connector"
format: markdown
---
The Netskope Security Cloud platform enables enterprises to secure sensitive data as they migrate workloads into the public cloud infrastructure. It provides visibility into risk exposure and compliance, while detecting possible misconfigurations, inventorying assets, and protecting against malware and insider threats. This topic describes Netskope-specific configuration settings for connecting your Aryaka ANAP device to the Netskope Security Cloud platform using GRE, IPSec VTI-IKEv1, or IPSec VTI-IKEv2 tunnels. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors . It assumes the configuration is completed through the Basic Information pane on the Cloud Security Connector (Add) tab page at Sites >  siteName  > Cloud Security Vendors > Cloud Connector (Add). This integration is supported for the following Aryaka ANAP topologies: Inline routed mode Edge routed mode Prerequisites Aryaka SmartServices subscription with read/write access Netskope Security Cloud subscription with access to the Configuration > Traffic Steering functionality  Netskope configuration Log in to the Netskope Security Cloud portal at  https://alliances.de.goskope.com/ . Navigate to  Settings  >  Security Cloud Platform  >  IPSec . The IPSec page appears. Click  Add New Tunnel  to add a new tunnel to the site. The Add New IPSec Tunnel dialog appears.   Enter the following information in the corresponding field in the Add New IPSec Tunnel dialog: Tunnel Name—A descriptive name for the connection. Source IP Address—IP address of your Aryaka site's ANAP device. Source Identity—IP address or the fully qualified domain name (FQDN) of the ANAP. Primary Netskope POP—Netskope point of presence (POP) that is closest to your Aryaka site. Failover Netskope POP—Secondary Netskope POP used if the primary POP is unavailable. Select the POP that is the next closest geographically to the Aryaka site. Preshared Key—Phase-1 key to use to secure the tunnel. Encryption Cipher—Select the desired encryption method for the tunnel. Bandwidth—Select the bandwidth based on expected throughput. Click  Add  to create the IPSec tunnel. You are returned to the IPSec page with the new tunnel listed in the IPSec Tunnels table. Click the more options  …  icon to the right of the new tunnel, then select  Enable . The tunnel is enabled in Netskope. Click the more options  …  icon to the right of the tunnel again, then select  View Details . The tunnel's configuration details appear. Capture these details (in text or as a graphic) and share them with the Aryaka support team so they can complete the ANAP configuration. MyAryaka configuration The Aryaka enables you to connect to a third-party cloud security service using a vendor-specific cloud security connector. Connector configuration is performed in MyAryaka or with the assistance of Aryaka’s technical support team. To configure the Netskope connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right), then click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations tab page appears. Configure the tunnel in the Tunnel Details pane as follows: Click the  Tunnel Source Interface  drop-down list and select one of the following interface types: M1 or M2—Both options appear if the site's ANAP has  two  ISPs and uses a copper connector. M1—This option appears selected by default if the site's ANAP has  one  ISP and uses a copper connector. F1 or F2—Both options appear if the site's ANAP has  two  ISPs and uses a fiber connector. F1—This option appears selected by default if the site's ANAP has  one  ISP and uses a fiber connector. Click the  Tunnel Source Type  drop-down list and select one of the following tunnel types: Use Interface IP—Uses the IP address of the tunnel source interface (that is, M1, M2, F1, or F2). Use Interface Aux IP—When selected, you must specify the source IP address in the Tunnel Source IP Address field that appears.  Use FQDN—When selected, you must specify the fully qualified domain name in the Tunnel Source FQDN field that appears. Do one of the following depending on the tunnel type selected: If you selected GRE, enter the destination IP address in the Tunnel Destination IP field. If you selected VTI, click the  Tunnel Destination Type  drop-down list and select either IP or FQDN, and then enter either the destination IP address or fully qualified domain name in the field that appears. (Conditional) If you are using a VTI tunnel type, enter the shared key that is configured for the IKE Gateway in the Netskope administrator portal. Configure a keepalive message for the tunnel in the ICMP Keepalive pane to ensure that the tunnel is kept active: Enter the IP address from which the keepalive messages are sent in the Ping Source Address field. (Optional) Enter the source mask from which the keepalive messages are sent in the Ping Source Mask field. Enter the destination IP address to which the keepalive messages are sent in the Ping Destination Address field. Click  OK . The following events occur: The tunnel configuration is saved. You are returned to the Tunnel Configurations (Add) tab page. The new tunnel is listed in the table in the Tunnel Configurations pane. (Optional) Click  Add New  and repeat this procedure to create one or more additional tunnels. After they are added to the table, click the  Move  icon to reposition any of the tunnels. Tunnels are prioritized from the first (top) row downward to the last (bottom) row. Click the  Forward Traffic  toggle to select match rules for forwarding traffic to the selected cloud security vendor: Click  Choose  in the Traffic Details table. The Match Rules and If Forward Fails fields appear. Click the  Match Rules  drop-down list and select one of the user-defined match rules from the list. Click the  If Forward Fails  drop-down list and select one of the following options to define what action is performed if the forward operation is not successful: Blackhole—Deny the flow and do  not  send a message to the sender. Unreachable—Deny the flow and send an ICMP Unreachable message to the sender. Aryaka Default—Cycle through all the rules until the last rule is reached. If no match has been found, the security rules are consulted. See  Create internet policies  for detailed information. Continue Through Local Policies—Override the routing table lookup and send the traffic flow to the desired destination. Use Security Rules—Security rules decide what should happen to traffic as it crosses segments or zones. This operation allows the ANAP to directly refer to these policies to determine the required action. See  Create internet policies  for detailed information. Click the  Save  icon in the match rule's row in the Traffic Details table. Click  Advanced  (top right). The following panes appear: Tunnel Properties ICMP Keepalive Settings Phase 1 Properties Phase 2 Properties Phase 2 Optional Properties (Optional) Configure the Tunnel Properties fields as follows: Tunnel MTU—Enter the maximum transmission unit (MTU) size in bytes for the tunnel. Restrictive Mode—Select one of the following options: Aryaka Default Yes No Unicast RPF—Select one of the following unicast reverse path forwarding options: Aryaka Default Yes No (Optional) Configure the ICMP Keepalive Settings fields as follows: Keepalive Interval—Enter the number of seconds between consecutive keepalive messages. Default is three (3). Keepalive Retries—Enter the number of times a keepalive message is sent before it is determined that the tunnel is closed. Default is five (5). (Optional) Configure the IKE Phase 1 Properties fields as follows: Enc Type—Select one of the following encryption types: Default—AES 3DES—Triple Data Encryption Standard implements 56 bit keys similar to the original DES encryption except 3DES is applied three times, using a different key each time to perform the encryption. Generally regarded as slower, but the associated hardware and software used can make the difference small. AES—Advanced Encryption Standard implements 128, 192, and 256 bit keys. It is generally regarded as secure and efficient. Hash Type—Select one of the following secure hash algorithms: Default - SHA SHA1 SHA2_256 SHA2_384 SHA2_512 Auth Type—Select one of the following authentication types: PSKEY—Authenticates using a  preshared key  (PSKEY) that is configured on each tunnel endpoint. RSASIG—Authenticates using an IPSec certificate that is configured on each tunnel endpoint. Life Time—Enter the phase 1 lifetime—the amount of time after which the tunnel must be reestablished—in seconds. Default is 3600 seconds (one hour). DH Group—Select one of the following Diffie-Hellman (DH) groups to determine the cryptography associated with the key exchange that establishes and secures  the tunnel: MODP1024 (default) MODP1536 MODP2048 MODP3072 MODP4096 MODP6144 MODP8192 Tunnels that use a larger group number are more secure, but require additional resources and time to calculate the key. DPD Delay—Enter the number of seconds between consecutive dead peer detection (DPD) messages that attempt to reach the IKE peer. Default is thirty (30). DPD Retry—Enter the number of times a DPD message is sent before it is determined that the tunnel is closed. Default is five (5). DPD Maxfail—Enter the number of unsuccessful authentication attempts before a peer is denied a connection. Default is five (5). (Optional) Configure the IKE Phase 2 Properties fields as follows: PFS Group—Select one of the following perfect forward secrecy (PFS) groups: MODP1024 (default) MODP1536 MODP2048 MODP3072 MODP4096 MODP6144 MODP8192 Tunnels that use a larger group number are more secure, but require additional resources and time to calculate the key. PFS requires that the tunnel generates and uses a different key than the one used to establish the tunnel in phase 1. It also requires periodic key regeneration as defined by the setting in the (Phase 2) Life Time field. Life Time—Enter the phase 2 lifetime for the tunnel in seconds. Default is 3600 seconds (one hour). (Optional) Configure the IKE Phase 2 Optional Properties fields as follows: Click  Add New . The empty row in the Properties Details table enters edit mode. Click the  Enc Type  drop-down list then select one of the following encryption types: 3DES—Triple Data Encryption Standard implements 56 bit keys similar to the original DES encryption except 3DES is applied three times, using a different key each time to perform the encryption. It is generally regarded as slower, but the associated hardware and software used can make the difference small. AES—Advanced Encryption Standard implements 128, 192, and 256 bit keys. It is generally regarded as secure and efficient. Click the  Hash Type  drop-down list then select one of the following secure hash algorithms: NON_AUTH HMAC_SHA1 HMAC_SHA2_256 HMAC_SHA2_384 HMAC_SHA2_512 Enter the encryption length of the key in the Enc Length field. For example, for a 256 bit key, enter 256. Click the  Save  icon in the property's row in the Properties Details table. Click  OK  below the Phase 2 Optional Properties pane to validate your entries. This caches the entries, but does  not  save them. They are lost if you reload the page.  Do one of the following: Click the  Save  icon to save a draft of the entries made on this page. Click  Submit  to send a change request with the entries made on this page to Aryaka support. In this topic Related topics Cloud connectors Route controller