A Service Tunnel in Cloud Secure Edge (CSE) is a Split Tunnel Wireguard VPN, with Identity Aware Device Posturing layered on top. Service Tunnels are great options to provide remote or secure access into private and more sensitive environments. In this article, we will create a Service Tunnel that routes to both public and private resources, then apply the policy created from Part Five of the CSE Getting Started Series.
To begin this exercise, log into the CSE Command Center as well as keep note of the IP address of the internal service you wish to configure for your first Service Tunnel connection. Ensure this service is available from a networking perspective to the Connector that we deployed in Part Three.




NOTE: Public Domains do not need to be defined in this manner, for public domains or public IP Addresses, please ignore these ranges as they only apply to private resources accessed via a Connector. 
TIP: The Domains defined here should be in an FQDN format such as "example.com". Each entry is treated like a wildcard domain meaning they will match one domain level down. Therefore "test.example.com" will match the route for "example.com" created by Service Tunnel. If you wish to exclude a subdomain from this behavior, please use the public exclude section which is not covered by this article. 
NOTE: Policy Enforcement in Permissive Mode will allow users to access but will not block users with low scores from accessing.
Validation
To validate our work we, will want to test our connection to our service through the tunnel we just made. To start this be sure you have completed Step Two of the CSE Getting Started Guides as we will need to log into the CSE App from a registered device.

CAUTION: If you have multiple tunnels already, be sure to select the correct one from the drop-down under the power button.



You have now completed Part Six. You may feel free to continue to add to this tunnel, adjust as needed, or create as many as needed for your desired use cases. In Part Seven, we will look at Device Posture and how to tweak it to serve your environment's needs.
CSE Getting Started: Create A Trust Profile
Related Articles