---
title: "Configure a Menlo Security RBI cloud connector"
canonical: "https://docs.aryaka.com/space/KNOW/375128187/Configure%20a%20Menlo%20Security%20RBI%20cloud%20connector"
format: markdown
---
Aryaka enables you to connect your branch locations and remote users to Menlo Security by providing a cloud-controlled SD-WAN integration that selectively forwards internet traffic to the Menlo Security VPN Gateway using a secure IPSec tunnel. This integration is used to facilitate the Remote Browser Isolation (RBI) solution provided by Menlo Security.  This topic describes Menlo Security-specific configuration settings for connecting your Aryaka ANAP device to the Menlo Security Cloud platform using GRE, IPSec VTI-IKEv1, or IPSec VTI-IKEv2 tunnels. This guide also outlines how to monitor traffic and forward traffic to the cloud connector using DPI or a domain. This information is designed to be used in conjunction with the general configuration steps described in the  Configure cloud connectors  topic. It assumes the configuration is completed through the Basic Information pane on the Cloud Security Connector (Add) tab page at Sites >  siteName  > Cloud Security Vendors > Cloud Connector (Add). This integration is supported for the following Aryaka ANAP topologies: Inline routed mode Edge routed mode Solution architecture This section provides a high-level overview of sample deployments and details the configuration options for the following connection types: Branch office with an ANAP Branch office without an ANAP Remote users The following graphic illustrates the integrated architecture: You have the following options to deploy the architecture: Local breakout: Each type of office has the option to connect locally to the Menlo Security VPN Gateway using one or more IPSec tunnels (as illustrated by the branch office with ANAP segment of the graphic).  Internet-bound traffic from the client behind the ANAP is encrypted and sent over the IPSec tunnel to Menlo Security where their security policies are applied. Centralized breakout: A new site is configured on the Aryaka POP that uses a single or redundant IPSec tunnel to the Menlo Security VPN Gateway. Internet traffic originating from branch offices and remote users is optimized, accelerated, and encrypted before it is sent to the local POP. This traffic is routed to the new site over the Aryaka secure core, then exits the Aryaka POP traveling to the Menlo Security VPN Gateway.  This option reduces the number of IPSec tunnels required for the Menlo Gateway compared to local breakout. Prerequisites Aryaka SmartServices subscription with read/write access Menlo Security Remote Browser Isolation subscription Menlo Security configuration This configuration must be performed by the Menlo Security support team. They provision an IPSec tunnel with an Aryaka profile that sends specific traffic to be processed by Menlo Security RBI. While we have made every effort possible to ensure accurate descriptions and requirements at time of publication, updates to the third-party software are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. To request IPSec tunnel configuration Contact Menlo Security support and request that they provision IPSec tunnels with one of the following Aryaka IPSec endpoints: The ANAP's M1 or M2 interface IP. The ANAP's auxiliary IPs from the M1 or M2 ISP. For branches without an ANAP or for remote users, request that Menlo Security configure a  dummy  IP (for example: 8.8.8.8) as a placeholder until Aryaka configuration is complete. Aryaka support provides the actual IP for the tunnel after completing the Aryaka configuration, which you can then share with Menlo Security support. Obtain the following information from Menlo Security support after they complete the tunnel configuration: Menlo Security's public IP for the IPSec tunnel Pre-shared key Local and remote IKE IDs (if they are configured) Provide the configuration information (from step 2) to Aryaka support so they can provision the Aryaka side of the tunnel. MyAryaka configuration Aryaka enables you to connect to a third-party cloud security service using a vendor-specific cloud security connector. Connector configuration is performed in MyAryaka or with the assistance of Aryaka’s technical support team. Before you can configure a Menlo Security RBI connector, you must add Menlo Security RBI as a network. After you have configured the Menlo Security RBI connector, you have the option to forward network traffic to the Menlo Security cloud connector using DPI or a custom domain. If you use the default traffic forwarding (as configured in step 9 of the  To configure the Menlo Security RBI connector  procedure) and do not also configure forwarding using DPI or domains, you might encounter the following issue: The default behavior forwards traffic based on source and destination IPs and ports. For example, to send traffic to  http://facebook.com ,  all  Facebook IPs must be known. If you are using DPI in this example, you can specify to forward traffic for Facebook through the connector without having to specify the IP, domain, URLs, and so on. To add Menlo Security RBI as a new network Log in to MyAryaka. The Home page appears. Click  SD-WAN  >  Connectivity  in left navigation pane. The Connectivity page appears. It displays a summary tile for each of the networks types included in your subscription.  Click the  Add  icon. The Cloud Security Vendor page appears with the Aryaka Certified tab page displayed by default. Click  Custom  to display the Custom tab page, then enter Menlo RBI in the Vendor Name field. This name appears in the Site Configuration, Security Policy, and Traffic pages. Click  Submit . The following events occur: A message prompts you to confirm your request. Click  OK.  The custom or selected vendor's details page appears with no data in the Sites table. A summary tile for the Menlo RBI network appears on the Network page. Sites can now connect to the network as described in  Configure cloud connectors  and in the following procedure. To configure the Menlo Security RBI connector On the Cloud Security Connector (Add) tab page, ensure that  Basic  is selected (top right). In the Basic Information pane, verify the following: Click  Menlo RBI  in Vendor section. Because the Menlo RBI is a custom vendor, the Custom Connector Like drop-down list appears. It is populated with the predefined (non-custom) connectors. Select  Zscalar (VTI)  and then select  Yes  for the Enable IKEv2 option that appears.  Click  Add New  in the Tunnel Configurations pane. The Tunnel Configurations tab page appears. Configure the tunnel in the Tunnel Details pane as follows: Enter a name for your tunnel or select  Let Aryaka Decide . Provide the following tunnel details: Tunnel Source Interface—The ANAP interface used for tunnel. Tunnel Source Interface—The ANAP interface used for tunnel. Tunnel Source Type—Select one of the following options: Use Interface IP  to use the selected interface's IP for the tunnel. Use Interface Aux IP  to provide an alternate IP from the same ISP that is associated with the selected interface. Shared Key—Enter the shared key that Menlo Security support configured for the IKE gateway. Tunnel Destination Type—Must be set to  IP . FQDN is not supported for Menlo Security. Tunnel Destination IP—Public IP of the Menlo Security gateway where the tunnel terminates. This is provided to you by Menlo Security support. Local IKE ID—Unique identifier provided by Menlo Security support. Click  OK . The following events occur: The tunnel configuration is saved. You are returned to the Tunnel Configurations (Add) tab page. The new tunnel is listed in the table in the Tunnel Configurations pane. (Optional) Click  Add New  and repeat this procedure to create one or more additional tunnels. After they are added to the table, click the  Move  icon to reposition any of the tunnels. Tunnels are prioritized from the first (top) row downward to the last (bottom) row. Click  Advanced  (above the Tunnel Configurations pane), then configure the following tunnel properties: Select the following settings in the Phase 1 Properties pane:  Enc Type: AES Enc Length: 256 Hash Type: SHA2_256 Auth Type: PSKEY DH Group: MODP2048 All other fields: empty Click  Add New  in the Phase 2 Optional Properties pane, then enter or select the following settings:  Enc Type: AES Hash Type: HMAC_SHA2_256 Enc Length: 256 Click the  Save  icon in the Action column to save the Phase 2 Optional properties. (Optional) If the ANAP device topology mode is  inline routed  or  edge routed , and you want to specify the type of traffic that can flow through the tunnel, you must configure routes as described in  Route controller . Note that route controllers are  not  supported for cloud connectors created on sites that run versions that allow multiple segments. If this is the case, see  Create internet policies  for configuration details. Click  Basic  (above the Tunnel Configurations pane) to return to the Tunnel Configurations pane, then click the  Forward Traffic  toggle to display the following fields where you can configure L3-L4 traffic match criteria that, when matched, forwards traffic to the Menlo RBI connector:  Forward Using—Drop-down list that includes the following options: Internet Policies—Select this option if you want the site to route the traffic to Menlo RBI that only reaches the public interfaces after all other routing decisions have been made on the traffic.  Local Policies—Select this option if you want the site to override all other routing decisions that could possibly be made on that traffic. For example, traffic may be heading to remote site but you want to override that decision and send it to Menlo RBI. If Forward Fails—Drop-down list that includes the following options: Blackhole—Select this option if you want the site to silently discard the traffic and send no response to the sender. Prohibit—Select this option if you want to send a code 13 ICMP administratively prohibited message to the sender. Policy Name table with Add New button—Click  Add New  to define a local or internet policy (depending on your selection in the Forward Using field), then provide the following details in the Policy (Add) page that appears: Name—Enter a descriptive policy name. Zone—Select the zone where the traffic originates. Match Rules—Set the toggle to  Explicit , click  Choose  in the Match Rules Details table that appears, and then select a preconfigured match rule from the  Name  drop-down list that matches the traffic you want to forward to Menlo RBI. Click the  Save  icon in the Action column to save the match rule. Click  OK  to add the policy, and then click  Submit  to create a change request and send it to Aryaka support for processing. You also have the option to forward network traffic to the Menlo Security cloud connector using DPI or a custom domain as described in the last procedure of this topic. To view tunnel status in MyAryaka Click  SD-WAN  >  Status  in the left navigation pane, then click the site name where the Menlo Security cloud tunnel is configured. Click the  ANAP  tab. The connector type and status, tunnel status, and associated IPs appear in the Services table: To enable traffic forwarding using DPI or custom domains Create an application that uses DPI or the domain name (or both) as the application identifier as described in  Add a custom application . Create an application group that includes the application you created in step 1 as described in  Add a custom application group . Create an application group control policy that routes traffic to the cloud connector as described in  Create an application group control policy  and  Configure application group policy information . In this topic Related topics Cloud connectors Route controller