Data sheet

Ericsson NetCloud Exchange

2026-03-16

Simple SD-WAN and zero-trust security for distributed WANs

The Challenge

The adoption of Wireless WANs allows fast moving organizations to take advantage of agile connectivity for temporary and fixed sites, vehicles, IoT devices and remote workers. However, as the WAN becomes more distributed and dynamic, a simplified, cellular-centric approach to SD-WAN and security is required.

 

The Value

Optimized for LTE/5G Wireless WANs, NetCloud Exchange provides the modern SD-WAN and security features to help organizations increase WAN resiliency and quality of experience while also protecting their corporate assets, applications, and users from the threat of an attack.

 

Key features include:

  • Dynamically construct zero trust networks in under 6 minutes to replace VPNs or private APNs.
  • Deliver a highly resilient, high-performance WAN with SD-WAN and intelligent bonding.
  • Provide secure IoT remote monitoring and maintenance capabilities.
  • Apply application aware traffic filtering, web filtering, and IDS/IPS inspection with Hybrid Mesh Firewall.
  • Streamline operations with a truly unified solution (one policy engine, one pane of glass and one provisioning experience) that can be deployed on-premises or delivered through the cloud.

Available Services

Secure Connect – Offers a simple-to-manage alternative to complex VPN and private APN infrastructures for securely connecting IoT devices, sites, vehicles, and remote workers. As the foundation for all other services, Secure Connect delivers a policy-governed, zero-trust network that can be easily orchestrated.

 

SD-WAN – A simpler, more secure SD-WAN, optimized for cellular networks. Application-based traffic steering, intelligent bonding, and forward error correction ensure that an elevated level of resiliency and quality of experience is achieved for every user across every location.

 

Zero Trust Network Access (ZTNA) – Provides isolated user-to-resource access for authenticated users. It enables secure remote access for internal employees and third parties to resources (IoT devices and/or applications) on the network through granular user-based access policies. ZTNA operates with the NetCloud Client and in clientless mode for cloud-delivered environments.

 

Hybrid Mesh FirewallEnabled with a premium license, hybrid mesh firewall provides application governance, web content filtering and offers continuous inspection of traffic to detect and prevent malicious activity.

Flexible Deployment Models

Zero-trust security and SD-WAN services can be customer hosted or cloud delivered, depending on the customer's requirements. Customers with lean IT teams can choose to deploy using the Ericsson SG4000, a pre-loaded service gateway appliance.

 

Components of the NetCloud Exchange solution include:

  • Ericsson Cradlepoint WAN edge routers/ appliances provide reliable connectivity for IoT devices, vehicles and fixed/ temporary sites.  
  • NetCloud Client (available for Apple, Microsoft, and Linux devices) enables secure remote access for managed devices to specific resources on the network.
  • NetCloud Virtual Edge is a software-based solution that can be easily deployed in a private cloud or an on-premises data center to allow controlled access to customer-hosted applications.
  • NetCloud Manager simplifies the deployment, management, and ongoing troubleshooting of the network consolidating 5G, advanced networking and security into a single pane of glass.
  • NetCloud Exchange Service Gateway is for customer-hosted deployments and is a reliable headend solution that can reside standalone or in an active/standby configuration in a customer’s data center or private cloud. The NetCloud Exchange Service Gateway can be purchased as a virtual appliance, deployed in a customer's data center or private cloud, or as a physical appliance with the software already pre-loaded on a server for streamlined deployments. FIPS 140-3 is also supported.

Why NetCloud Exchange is Different

Cellular-Centric Optimized for roaming and mobility with features that preserve bandwidth, enhance performance, and deliver slicing-ready capabilities for 5G standalone networks.

 

Truly Unified Single management, control, and data plane with one policy engine and consistent provisioning across all networking and security services.

 

Built-In Zero Trust Combines security and networking by creating a foundation that is deny-all by default with obscured IP addresses, dark assets, and explicit access policies. 

 

Secure Access for Unmanaged Devices Clientless secure access with web application isolation to protect corporate resources from risky third-party devices and malware. Available only through the cloud delivered option.

Common Use Cases

IoT Deployments

Secure Connect – For zero-trust connectivity between IoT devices and their hosts, replacing complex VPN/Private APN architectures.

Zero Trust Network Access (ZTNA) – For granting internal and third parties secure remote access to IoT devices for maintenance and monitoring.

Hybrid Mesh Firewall – For continuous inspection of traffic to detect and prevent malicious activity.

Vehicle Deployments

Secure Connect – For securing vehicle-based communications across the WAN, replacing complex VPNs and/ or private APNs.

SD-WAN and intelligent bonding – For providing increased resiliency, performance, and quality of experience across multiple WAN connections (cellular, satellite, and Wi-Fi as WAN).

ZTNA – For secure remote access to corporate applications in the cloud or data center, or to remotely monitor IoT devices.

Hybrid Mesh Firewall – For web filtering, application governance and continuous inspection of traffic.

Branch Deployments

Secure Connect – For zero-trust connectivity between branches and corporate data centers and clouds, replacing complex VPN / private APN architectures.

SD-WAN and intelligent bonding – For providing increased resiliency, performance, and quality of experience across multiple WAN connections (wired, cellular and satellite).

ZTNA – For secure remote access to corporate applications in the cloud or data center, or to remotely monitor IoT devices.

Hybrid Mesh Firewall – For web filtering, application governance and continuous inspection of traffic.

NetCloud Management and Operations

NetCloud Exchange is deployed and managed through Ericsson’s powerful cloud management and orchestration platform, NetCloud. With features that include zero-touch deployment, multi-layered dashboards and intuitive troubleshooting tools, NetCloud Manager is a valuable assist to lean IT organizations. Some of the key features include: 

  • Virtual Expert capabilities – Ericsson’s NetCloud Assistant (ANA) uses Natural Language Processing to assist administrators with everyday queries about the network. 
  • AI-driven insights – An integrated AIOps dashboard simplifies the ongoing operations of the network by quickly identifying performance-driven anomalies, determining the root cause, pinpointing all affected sites, users, and applications and recommending remediation steps. 
  • Centralized flow level visibility –  NetCloud’s Traffic Monitor dashboard is a powerful tool that lets administrators drill into every flow for detailed traffic analysis and forensic.

Ordering Guidelines

  • Step 1 (required): Select the deployment model cloud delivered or customer hosted.
  • Step 2 (required): Select the NetCloud Service plan(s) for the compatible router(s).
  • Step 3 (customer hosted only): Select the NetCloud Service Gateway capacity for entire solution. NOTE: Separate part numbers for high availability.
  • Step 4 (required): Select the Secure Connect or SD-WAN site (router-based) license(s) in either Standard or Premium for each router. NOTE: Each NetCloud Exchange cloud-delivered license for mobile or branch routers includes 500 GB for a shared data pool. IoT routers have unlimited data.
  • Step 5 (optional): Select the number of ZTNA user licenses.
  • Step 6 (optional): Select the NetCloud Virtual Edge in either Standard or Premium per each additional data center or private cloud environment beyond where the NetCloud Service Gateway is located (selection of Standard or Premium must match Step 4). NOTE: Each NetCloud cloud-delivered license includes 500 GB for a shared data pool.
  • Step 7 (optional cloud delivered only for mobile and branch deployments): Select additional 500 GB data credits to add to the shared data pool.