Introduction to ZPE Cloud

Prev Next

ZPE Cloud is a cloud-based management and monitoring solution specifically designed to efficiently oversee Nodegrid devices. By registering all Nodegrid devices with the ZPE Cloud, you can establish a singular point of access, facilitating comprehensive control over the entire infrastructure— making remote management a seamless and efficient experience easing the troubleshooting processes and effectively minimizing downtime.

ZPE Cloud places a strong emphasis on security and adopts a Zero Trust-based access policy incorporating features such as multi-factor authentication and role-based access control. The development life cycle follows a secure approach through thorough code analysis, zero CVE policy, encrypting both data at rest and data in motion, and so on. The platform holds industry-leading certifications including SOC2 Type 2 and FIPS140-3, ensuring a high level of security.

Pre-requisites

To enable your device to establish communication with the ZPE Cloud, ensure that the following configuration requirements are met. If your device is situated behind a firewall or within a corporate environment, it is crucial to verify that the required firewall rules have been configured correctly to permit incoming and outgoing traffic to and from the ZPE Cloud services.

  • The Nodegrid appliance needs to be on v4.2.13 or later. If the upgrade is needed, see the Upgrading a Nodegrid Device section.

  • If the unit has TPM 1.2, TPM needs to be enabled, for more information, see How to enable TPM on BIOS. For other versions, the TPM is enabled by default.

  • Configure the Firewall Rules: ZPE Cloud uses some IP addresses and hostnames that the Firewall rules may block. This can prevent the Nodegrid appliances from connecting to the Cloud and/or utilizing specific ZPE Cloud features. Refer to the following table for information on the IP addresses and hostnames.

    Supported IPv4 and IPv6 Address

    US ZPE Cloud Servers

Hostname(s)

IPv6 Address

IPv4 Address

Usage

second-tier-ca.zpecloud.com

device-api.zpecloud.com

device-apiv2.zpecloud.com

2600:1901:0:6091::

34.49.235.253

  • Required to sign the CSR to connect to Remote Access.

  • Required to Upload/Restore Backups.

  • Required to upload output from executed profiles.

api.astarte.zpecloud.com

2600:1901:0:53ce::

34.49.39.37

  • Required for Pairing API - without which the device cannot authenticate against PubSub service and consequently connect to the ZPE Cloud.

access.zpecloud.com

2600:1901:0:ab8f::

34.49.235.61

  • Required for Remote Access - without which the device cannot connect to the Remote Access.

broker.astarte.zpecloud.com

2600:1901:0:5abb::

34.49.26.197

  • Required for Broker connection - without which the device cannot connect to PubSub service and consequently connect to the ZPE Cloud.

www.zpecloud.com, api.zpecloud.com, proxy-access.zpecloud.com, zpecloud.com

2600:1901:0:910b::

34.120.236.72

  • Required for Enrollment.

  • Required to SSO from ZPE Cloud to Nodegrid appliance; also needs to be enabled on the Nodegrid appliance under Security :: Authentication :: SSO.

  • Required to access ZPE Cloud Website and API.

European ZPE Cloud Servers

Hostname(s)

IPv6 Address

IPv4 Address

Usage

second-tier-ca.zpecloud.eu

device-api.zpecloud.eu

device-apiv2.zpecloud.eu

2600:1901:0:b0cb::

34.128.171.100

  • Required to sign the CSR to connect to Remote Access.

  • Required to Upload/Restore Backups.

  • Required to upload output from executed profiles.

api.astarte.zpecloud.eu

2600:1901:0:7123::

34.49.228.213

  • Required for Pairing API - without which the device cannot authenticate against PubSub service and consequently connect to the ZPE Cloud.

access.zpecloud.eu

2600:1901:0:e8af::

34.128.152.77

  • Required for Remote Access - without which the device cannot connect to the Remote Access.

broker.astarte.zpecloud.eu

2600:1901:0:9065::

34.36.11.79

  • Required for Broker connection - without which the device cannot connect to PubSub service and consequently connect to the ZPE Cloud.

www.zpecloud.eu, api.zpecloud.eu, proxy-access.zpecloud.eu, zpecloud.eu

2600:1901:0:ec0d::

34.111.34.34

  • Required for Enrollment.

  • Required to SSO from ZPE Cloud to Nodegrid appliance; also needs to be enabled on the Nodegrid appliance under Security :: Authentication :: SSO.

  • Required to access ZPE Cloud Website and API.


Recommended Network Properties for ZPE Cloud

To ensure ZPE Cloud performs as expected, your Nodegrid device’s network must meet the following configuration requirements to avoid issues such as device remote access delays or failures, delayed software upgrade times, connection instability, and failed data transfers.

Parameter

Recommended Value

Latency

<=80ms

Jitter

<=20ms

Packet-loss

<=1%

Bandwidth

>=20Mb

To ensure a seamless experience with ZPE Cloud, it is important to maintain a well-configured and reliable network. A stable connection ensures quick and successful remote access, smooth software updates, and consistent connection stability without frequent reconnections. The network link connecting to a Nodegrid device plays a vital role, as it serves as the bridge between your managed devices and ZPE Cloud. For the best results, ensure this link is robust and dependable. Additionally, when accessing ZPE Cloud through a browser, a strong network connection for Nodegrid will further enhance performance and usability.