VMware provides an advanced feature called Secure Access Service. SASE Orchestrator allows you to configure the Secure Access Service on the Device Settings page for a Profile. Different services can be applied for different Segments.

Configure Secure Access Service for a Profile
  1. In the SD-WAN service of the Enterprise portal, go to Configure > Profiles. The Profiles page displays the existing Profiles.
  2. Click the link to a Profile. Alternatively, you can click the View link in the Device column of the Profile.
  3. Go to the VPN Services section, and then turn on Secure Access Service.
  4. Select a pre-defined service from the drop-down list.
  5. Click Save Changes.

Prerequisites

To turn on the Secure Access feature, an Operator user must navigate to the Global Settings service of the Enterprise portal. From the left menu, click Customer Configuration, and then on the Secure Access card, click Turn On. If the Secure Access service is deactivated, follow the below steps to activate it before turning it on:
  1. Click Go to Gateway Pools link on the Secure Access card. Select a Gateway pool, and then select a Gateway.
  2. In the Properties section, select the Cloud Web Security check box.
  3. In the Cloud Web Security section of the screen, enter appropriate details for Geneve Endpoint IP Address and PoP name.
  4. Click Save Changes.
  5. Go back to the Global Settings > Customer Configuration screen, and then turn on the Secure Access service.

What to do next

To configure the Secure Access Service for an Edge, see Configure Secure Access Service for Edges.