Use Custom Options to Configure Secure Edge Connector
Use custom provider option to configure tunnel provisioning or to support site-to-site VPN.
Juniper Mist™ offers custom options for tunnel provisioning. With minimal configuration, your WAN Edge device can establish connections to the Secure Service Edge (SSE) using either IPsec or GRE protocols.
The Custom option gives you the flexibility to specify the exact encryption and authentication algorithm used to best suit your deployment needs.
For example, you can set up site-to-site VPN using custom options for tunnel provisioning. A site-to-site VPN is a secure, software-defined network connection that links two or more remote sites over the internet. Enterprises use this type of VPN to securely and efficiently connect branch offices, data centers, or other remote locations.
Configure Tunnel Provisioning
Before You Begin: Ensure you have the local and remote network account details on hand.
To configure a tunnel from the WAN Edge to SSE:
Verify Juniper Secure Edge Tunnels
On the Mist portal, you can verify the established tunnel's details in WAN Edges > WAN Edges, then click WAN Edge Insights. You should see the WAN Edge Tunnel Auto Provision Succeeded event under WAN Edge Events.
Get the established tunnel's status details by navigating to WAN Edges > WAN Edges, then scroll down to the Secure Edge Connector Details section.
To verify the BGP over GRE session you created, you can use the WAN Edge testing tools, navigate to WAN Edges > WAN Edges > Click the WAN Edge > Utilities > Testing Tools
- Open the BGP tab > Summary tab > Show Summary. You can also verify the tunnel in the Routes tab > Show Routes.
You can view the tunnel statistics under Probe Stats on the WAN Edge Insights page. To view an example of this, see Tunnel Statistics.



