Configuring Your First Gateway
Hello and welcome to XQ, this is the second part of a multi-part tutorial series on deploying and managing XQ’s Secure Gateway. In this video, we will cover configuring your first XQ Secure Gateway.
General Features
- First, navigate to gateway.xqmsg.com and log in using a magic link or single sign-on.
- Select the “Gateways” option in the left-hand side navigation menu and click the “Create Gateway” button.
- Input a name for your gateway and click the create gateway button.
- In the general features menu, input a Connection IP for the gateway – the connection IP will be the publicly accessible IP address of the gateway we are creating. The public IP is identified by navigating to https://www.whatsmyip.org/.
- Additionally, you can optionally input “Tag(s),” which are used to easily identify the gateway, comma-separated local IPs, and select the gateway’s logging level.
- The “Is Private” toggle controls whether or not this configuration is viewable by other team members.
- The server settings should remain the same unless you are currently utilizing your own backend deployment of XQ, in which case you will need to adjust the URLs to your corresponding deployment.
- Click Next and begin creating and configuring your inbound routes.
Configuring Route(s)
- Input a name for the inbound route, followed by the Routing Type.
- Specify whether this route uses standard or raw transports and which Encryption Algorithm you would like to use.
- Input the Listen IP for this specific route, for standard transports, 0.0.0.0 may be used to listen on all incoming interfaces. For raw transports omitting this value will listen to all the traffic on an interface.
- Followed by Inputting the network port and listening interface.
- Update the Key Recycling, Lifetime, and Lifetime Units according to your preferences – The Key Recycling field is the amount of time in seconds before a new key is utilized. The Lifetime and Lifetime Unites of a key impact the expiry time of the key policy.
- Input a number for the number of concurrent connections permitted for this route, if you want to filter traffic based on a specific VLAN id, input that number into the VLAN Filter input.
- Lastly, input the recipient gateway devices that can decrypt the outgoing transmission – this can be set to xq.public to allow all gateways to decrypt the traffic, or you can input specific devices in the format of Device_Name-Local_IP@Team_ID.trusted.local followed by clicking next.
Configuring Mapping(s)
- Similar to the Route configuration, input a Title for the Output mapping as well as the transport type, and Protocol.
- If you want to specify the “Source Device” for this mapping, you can do so here.
- Input the Target IP for this output mapping; this is the publicly accessible IP address of the destination gateway and the outgoing destination port, and click save.
Download(s)
- Navigate to the download section by clicking on Download in the left-hand navigation pane.
- Select the Ubuntu 22.04 LTS option in the Binary Platform dropdown menu, followed by selecting Generate new keys in the API keys dropdown menu.
- Lastly, select your newly created Gateway Config from the dropdown menu, provide a name for your newly generated application keys, and click download now.
You are now ready to deploy your first Gateway.
Frequently asked questions
What is the XQ Secure Gateway?
The XQ Secure Gateway is an XQ zero trust data protection product that encrypts network traffic between gateway devices according to configured routes and mappings. Administrators set it up at gateway.xqmsg.com by defining a gateway's connection IP, inbound routes with an encryption algorithm, and output mappings to destination gateways, then download a binary and keys to deploy it.
How do you configure an inbound route on the XQ Secure Gateway?
To configure an inbound route, name it, choose the routing type, select standard or raw transport and an encryption algorithm, and set the listen IP, port and interface. Then set key recycling, key lifetime, concurrent connections and an optional VLAN filter, and list recipient gateways allowed to decrypt, either xq.public or specific trusted devices.
What does key recycling mean in XQ Secure Gateway settings?
Key recycling in the XQ Secure Gateway is the amount of time, in seconds, before a new encryption key is used for a route. It is configured alongside key lifetime and lifetime units, which determine when the key policy expires, letting administrators control how often keys rotate on encrypted gateway traffic.