---
title: "Ericsson NetCloud Exchange"
url: "https://cradlepoint.ericsson.com/datasheet/netcloud-sase/"
content_type: "pim_datasheet"
version_date: "2026-09-29"
breadcrumb: "[Home](https://cradlepoint.ericsson.com/) › Products › Datasheets › Ericsson NetCloud Exchange"
gated: false
---

# Ericsson NetCloud Exchange

*Data sheet · 2026-09-29*

![Ericsson NetCloud Exchange](https://images.contentstack.io/v3/assets/blt2588e757607604a2/blt816e4c36c01014e6/69e5908d69e50661e818e021/39658_spacer.png)

## Simple SD-WAN and zero-trust security for distributed WANs

## The Challenge
The adoption of Wireless WANs allows fast moving organizations to take advantage of agile connectivity for temporary and fixed sites, vehicles, IoT devices and remote workers. However, as the WAN becomes more distributed and dynamic, a simplified, cellular-centric approach to SD-WAN and security is required.

## The Value
Optimized for LTE/5G Wireless WANs, NetCloud Exchange provides the modern SD-WAN and security features to help organizations increase WAN resiliency and quality of experience while also protecting their corporate assets, applications, and users from the threat of an attack.

Key features include:

- Dynamically construct zero trust networks in under 6 minutes to replace VPNs or private APNs.
- Deliver a highly resilient, high-performance WAN with SD-WAN and intelligent bonding.
- Provide secure IoT remote monitoring and maintenance capabilities.
- Apply application aware traffic filtering, web filtering, and IDS/IPS inspection with Hybrid Mesh Firewall.
- Streamline operations with a truly unified solution (one policy engine, one pane of glass and one provisioning experience) that can be deployed on-premises or delivered through the cloud.

## Available Services

**Secure Connect** – Offers a simple-to-manage alternative to complex VPN and private APN infrastructures for securely connecting IoT devices, sites, vehicles, and remote workers. As the foundation for all other services, Secure Connect delivers a policy-governed, zero-trust network that can be easily orchestrated.

**SD-WAN – **A simpler, more secure SD-WAN, optimized for cellular networks. Application-based traffic steering, intelligent bonding, and forward error correction ensure that an elevated level of resiliency and quality of experience is achieved for every user across every location.

**Zero Trust Network Access (ZTNA)** – Provides isolated user-to-resource access for authenticated users. It enables secure remote access for internal employees and third parties to resources (IoT devices and/or applications) on the network through granular user-based access policies. ZTNA operates with the NetCloud Client and in clientless mode for cloud-delivered environments.

**Hybrid Mesh Firewall** – Enabled with a premium license, hybrid mesh firewall provides application governance, web content filtering and offers continuous inspection of traffic to detect and prevent malicious activity.

## Flexible Deployment Models

Zero-trust security and SD-WAN services can be customer hosted or cloud delivered, depending on the customer's requirements. Customers with lean IT teams can choose to deploy using the Ericsson SG4000, a pre-loaded service gateway appliance.

Components of the NetCloud Exchange solution include:

- **Ericsson Cradlepoint WAN edge routers/ appliances** provide reliable connectivity for IoT devices, vehicles and fixed/ temporary sites.

- **NetCloud Client** (available for Apple, Microsoft, and Linux devices) enables secure remote access for managed devices to specific resources on the network.

- **NetCloud Virtual Edge** is a software-based solution that can be easily deployed in a private cloud or an on-premises data center to allow controlled access to customer-hosted applications.

- **NetCloud Manager** simplifies the deployment, management, and ongoing troubleshooting of the network consolidating 5G, advanced networking and security into a single pane of glass.

- **NetCloud Exchange Service Gateway** is for customer-hosted deployments and is a reliable headend solution that can reside standalone or in an active/standby configuration in a customer’s data center or private cloud. The NetCloud Exchange Service Gateway can be purchased as a virtual appliance, deployed in a customer's data center or private cloud, or as a physical appliance with the software already pre-loaded on a server for streamlined deployments. FIPS 140-3 is also supported.

## Why NetCloud Exchange is Different

**Cellular-Centric ****–** Optimized for roaming and mobility with features that preserve bandwidth, enhance performance, and deliver slicing-ready capabilities for 5G standalone networks.

**Truly Unified ****–** Single management, control, and data plane with one policy engine and consistent provisioning across all networking and security services.

**Built-In Zero Trust ****–** Combines security and networking by creating a foundation that is deny-all by default with obscured IP addresses, dark assets, and explicit access policies.

**Secure Access for Unmanaged Devices ****–** Clientless secure access with web application isolation to protect corporate resources from risky third-party devices and malware. Available only through the cloud delivered option.

## Common Use Cases

### IoT Deployments
**Secure Connect** – For zero-trust connectivity between IoT devices and their hosts, replacing complex VPN/Private APN architectures.

**Zero Trust Network Access (ZTNA)** – For granting internal and third parties secure remote access to IoT devices for maintenance and monitoring.

**Hybrid Mesh Firewall** – For continuous inspection of traffic to detect and prevent malicious activity.

### Vehicle Deployments
**Secure Connect** – For securing vehicle-based communications across the WAN, replacing complex VPNs and/ or private APNs.

**SD-WAN and Intelligent Bonding** – For providing increased resiliency, performance, and quality of experience across multiple WAN connections (cellular, satellite, and Wi-Fi as WAN).

**ZTNA** – For secure remote access to corporate applications in the cloud or data center, or to remotely monitor IoT devices.

**Hybrid Mesh Firewall** – For web filtering, application governance and continuous inspection of traffic.

### Branch Deployments
**Secure Connect** – For zero-trust connectivity between branches and corporate data centers and clouds, replacing complex VPN / private APN architectures.

**SD-WAN and Intelligent Bonding** – For providing increased resiliency, performance, and quality of experience across multiple WAN connections (wired, cellular and satellite).

**ZTNA** – For secure remote access to corporate applications in the cloud or data center, or to remotely monitor IoT devices.

**Hybrid Mesh Firewall** – For web filtering, application governance and continuous inspection of traffic.

## NetCloud Management and Operations

NetCloud Exchange is deployed and managed through Ericsson’s powerful cloud management and orchestration platform, NetCloud. With features that include zero-touch deployment, multi-layered dashboards and intuitive troubleshooting tools, NetCloud Manager is a valuable assist to lean IT organizations. Some of the key features include: 

- **Virtual Expert capabilities** – Ericsson’s NetCloud Assistant (ANA) uses Natural Language Processing to assist administrators with everyday queries about the network. 

- **AI-driven insights** – An integrated AIOps dashboard simplifies the ongoing operations of the network by quickly identifying performance-driven anomalies, determining the root cause, pinpointing all affected sites, users, and applications and recommending remediation steps. 

- **Centralized flow level visibility** –  NetCloud’s Traffic Monitor dashboard is a powerful tool that lets administrators drill into every flow for detailed traffic analysis and forensic.

## Secure Connect

## NetCloud Exchange Services and Specifications
*Zero trust VPN / private APN replacement*

**Secure Connect** delivers a policy-governed, zero-trust network that can be easily orchestrated from the WAN edge to the cloud.

- **Domain name-based routing** – Translates complex IP addresses to more intuitive names to hide the network attack surface, simplify provisioning, and to create more intuitive policies.;
- **Support for overlapping IP addresses at sites** – With domain-based routing in place, overlapping IP addresses can easily be accommodated.
- **Resource-definition** – Applications and assets connecting to the network are “dark” until explicitly defined and an access policy is created.
- **Deny-all by default** – Rather than broad network access, access is restricted until explicitly defined by policy.
- **Blocks east/west traffic by default** – Contains breaches to where they occurred by blocking east/west and all incoming traffic to a site, unless enabled by policy.
- **Split routing from sites** – Enables Direct Internet Access from the edge router. Administrators define all the IP subnets that need to go through the cloud-delivered or customer-hosted service gateway; all other traffic goes direct to the internet.
- **Configurable options for cipher levels and encryption method** – Allows administrators to select desired cipher levels and encryption method. Administrators can select IPsec where all traffic is encrypted, even if it is already encrypted. The microtunnel encryption mode enables administrators to select which ports and protocols they want encrypted. This can increase throughput on a wireless WAN while still providing the same level of security as IPsec. Selectable IPsec cipher levels include:
Level 1 (the default) – AES 128, SHA2 256, Group 14 (ECP 256)
- Level 2 – AES 128, SHA 2 256, Group 19 (ECP 256)
- Level 3 – AES 256, SHA2 384, Group 20 (ECP 256)

Microtunnel uses AES 256 encryption.

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| IBR600C/IBR650C, IBR900, S400/S450, S700/S750, S700-FIPS/S750-FIPS | 5 | 10 Mbps | 10 |
| S700-FIPS/S750-FIPS † | 5 | 10 Mbps | 10 |

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| IBR1700 | 30 | 40 Mbps | 20 |
| R920 | 5 | 30 Mbps | 10 |
| R980 | 5 | 85 Mbps | 20 |
| R1900 | 100 | IPsec: 400 Mbps Microtunnel: 540 Mbps | 20 |
| R2105/R2155 | 100 | 400 Mbps | 20 |
| R2400 | 100 | 720 Mbps | 20 |
| IBR1700-FIPS † | 30 | 40 Mbps | 20 |
| R920-FIPS † | 5 | 30 Mbps | 10 |
| R1900-FIPS, R2105-FIPS/R2155-FIPS † | 100 | 400 Mbps | 10 |

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| AER2200 | 100 | 40 Mbps | 20 |
| E100, E102 | 5 | 40 Mbps | 20 |
| E300 | 50 | IPsec: 400 Mbps Microtunnel: 600 Mbps | 20 |
| E400 | 50 | 270 Mbps | 20 |
| E3000 | 100 | IPsec: 400 Mbps Microtunnel: 600 Mbps | 20 |
| E300-FIPS † | 50 | 400 Mbps | 20 |
| E3000-FIPS † | 100 | 400 Mbps | 20 |

†FIPS compliance is only supported with the customer-hosted deployment model and requires FIPS certified routers and a compliant service gateway.**
NOTE**: Secure Connect site performance may vary based on latency conditions.**†FIPS compliance is only supported with the customer-hosted deployment model and requires FIPS certified routers and a compliant service gateway.

NOTE**: Secure Connect site performance may vary based on latency conditions.**†FIPS compliance is only supported with the customer-hosted deployment model and requires FIPS certified routers and a compliant service gateway.

NOTE**: Secure Connect site performance may vary based on latency conditions.

Secure Connect is not yet supported on the X10 and X20 routers.

## SD-WAN

**SD-WAN **enhances WAN resilience and quality of experience (QoE) by optimizing traffic over multiple physical or logical connections including, wired, 5G/LTE, satellite, Wi-Fi as WAN, private APNs, and 5G standalone network slices.

- **Zero trust foundation for SD-WAN** – While traditional SD-WAN technology leverages encryption and site-based VPN technology to secure traffic over multiple WAN connections, NetCloud SD-WAN leverages a true zero trust foundation that minimizes the attack surface, limits the blast radius, and is deny-all by default.
- **Classification of traffic into predefined classes** – Through deep packet inspection, administrators can classify their traffic into business critical, real-time, interactive, or best effort.
- **Application-based traffic steering** – After traffic is classified, policies can be created to ensure business critical and real-time applications always traverse the highest performing WAN connection.
- **Traffic steering based on real-time WAN performance** – Using in-line traffic, NetCloud SD-WAN measures latency, loss, and available bandwidth across all available WAN connections.  If performance degrades beyond the predefined thresholds, traffic is dynamically steered to a better performing connection.
- **Direct Internet Access** – To enhance performance and reduce the costs of backhauling, NetCloud SD-WAN enables secure direct internet access capabilities from sites and vehicles.
- **Traffic steering across 5G network slices** – Select modems can support up to eight 5G SA network slices. Leveraging NetCloud SD-WAN, when a 5G SA network is in place, the ability to steer applications into the most suitable network slide is available.  (For example, business-critical traffic can be steered into an ultra-reliable low latency slice.)
- **Intelligent Link Bonding** – Allows the creation of a bonded interface using multiple WAN interfaces.
**Flow duplication across bonded WAN connections** – Provides a highly resilient connection for mission-critical applications by duplicating traffic flows across two diverse connections, increasing availability.
- **Dynamic or weighted flow balancing across bonded WAN connections** – Distributes application traffic flows across diverse WAN links according to the real-time performance of the various WAN links or through user-defined weights.
- **Bandwidth aggregation across bonded WAN connections** – Aggregates two or more WAN links into one logical link providing more bandwidth (especially for uploads) for applications like video and large file transfers.

- **Forward Error Correction** – Most effective for chatty TCP-based applications, FEC mitigates against lossy connections by adding parity bits to an application flow to prevent application retries, thereby improving application quality of experience.
- **Networkwide application-based policies** – With NetCloud SD-WAN, a single policy can be applied across heterogenous product types.

| PERFORMANCE |  |  |
| --- | --- | --- |
| Site Routers | Typical Client Count | Throughput |
| IBR1700 | 30 | 40 Mbps |
| R920 | 5 | 30 Mbps |
| R980 | 5 | 85 Mbps |
| R1900 | 100 | IPsec: 350 Mbps Microtunnel: 500 Mbps |
| R2105/R2155 | 100 | 400 Mbps |
| R2400 | 100 | 720 Mbps |

| PERFORMANCE |  |  |
| --- | --- | --- |
| Site Routers | Typical Client Count | Throughput |
| AER2200 | 100 | 40 Mbps |
| E100, E102 | 5 | 40 Mbps |
| E300 | 50 | IPsec: 350 Mbps Microtunnel: 550 Mbps |
| E400 | 50 | 270 Mbps |
| E3000 | 100 | IPsec: 350 Mbps Microtunnel: 550 Mbps |

The IBR1700, R920, and R980 routers do not yet support Forward Error Correction (FEC), Intelligent Bonding, or Fast Link Monitoring features. R2105 routers do not yet support Intelligent Bonding. R2155 routers do not yet support FEC or Intelligent Bonding features. Other SD-WAN functionality is supported.
The AER200 and E102 routers do not yet support Forward Error Correction (FEC), Intelligent Bonding, or Fast Link Monitoring features. Other SD-WAN functionality is supported. All features are supported when using E100, E300, E400, E3000, R1900, and R2400 routers. SD-WAN is not yet supported on the X10 and X20 routers.

## Zero Trust Network Access

*Secure remote access*

** Zero Trust Network Access (ZTNA) **integrates with an organization’s existing identity provider to provide isolated user-to-resource access for authenticated users.

- **Identity verification** – Offers integration to any SAML 2.0 compliant Identity Management Platform, preventing identity sprawl.
- **Isolated user-to-resource access** – Users are directly authenticated to their authorized resources per session.
- **Least privilege access** – Various levels of access, ranging from visibility only to full configuration, can be granted based on the user’s job function or identity.
- **Device posture visibility** – In conjunction with the customer's identity management platform, administrators can view details on the device posture (for example, anti-virus installed and running, OS version, and device type) for any device that has the client installed.
- **Flexible user authentication** – Users can authenticate through an Ericsson Cradlepoint router, a wide range of Windows, macOS, iOS/iPadOS, Android, and Linux clients, or a secure web browser to enable safe remote connectivity from anywhere.
- **NetCloud Client **(supported on cloud-delivered and customer-hosted deployment options)** – **This software enables secure remote access to an NetCloud Secure Connect network. The NetCloud Client supports Windows and macOS laptops, iOS mobile devices, and Linux devices. The NetCloud Client is available to download with a ZTNA license.
- **Clientless ZTNA** (supported on cloud delivered only) **– **Allows contractors and third parties to access specific resources without requiring a client. Clientless ZTNA supports HTTP, HTTPS, Virtual Network Computing (VNC), Remote Desktop Protocol (RDP), and Secure Shell (SSH) based access. This unique solution leverages isolation technology and protects company assets from unmanaged devices.

| SYSTEM REQUIREMENTS |  |
| --- | --- |
| Operating System: | Windows |
| Version: | Windows 10 and 11 |
| Processor: | Intel x86 |
| Memory: | 16 GB |
| Maximum NetCloud Client Count: | Unlimited (limited by NCX Service Gateway licensed throughput capacity per network) |

| SYSTEM REQUIREMENTS |  |
| --- | --- |
| Operating System: | macOS |
| Version: | Monterey 12.x or later |
| Processor: | Intel or Apple M1/M2 CPU |
| Memory: | 16 GB |
| Maximum NetCloud Client Count: | Unlimited (limited by NCX Service Gateway licensed throughput capacity per network) |

| SYSTEM REQUIREMENTS |  |
| --- | --- |
| Operating System: | iOS |
| Version: | iOS 16 or later |
| Processor: | ARM64 or Apple Silicon |
| Memory: | 64 GB |
| Maximum NetCloud Client Count: | Unlimited (limited by NCX Service Gateway licensed throughput capacity per network) |

| SYSTEM REQUIREMENTS |  |
| --- | --- |
| Operating System: | Linux Ubuntu |
| Version: | 22.04 or 24.04 |
| Processor: | Intel x86 Minimum four core CPU |
| Memory: | 16 GB |
| Maximum NetCloud Client Count: | Unlimited (limited by NCX Service Gateway licensed throughput capacity per network) |

## Hybrid Mesh Firewall

*(Requires a Premium license)*

**Hybrid Mesh Firewall (HMF)** is a service that can be added to a Secure Connect or SD-WAN network.  With application and web filtering plus integrated IDS/IPS. HMF brings in modern firewall features, without the complexity.

- **Application visibility and enforcement** – Uses policies and deep packet inspection to determine whether to block or allow traffic, including communications to or from an application.
- **IDS/IPS** – Provides continuous monitoring of all north/south and east/west traffic flows to detect and prevent malicious activity.
- **Web filtering** – Blocks access to inappropriate web content including high-risk domains that may contain malware.
- **Firewall-as-a-Service** (supported on cloud delivered only) – Simplifies firewall deployment by delivering firewall services from the cloud instead of requiring local firewalls in all locations.

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| IBR600C/IBR650C, S700/S750 | 5 | 10 Mbps | 10 |

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| IBR1700 | 30 | 40 Mbps | 20 |
| R920 | 5 | 10 Mbps | 10 |
| R1900, R2105/R2155 | 100 | 400 Mbps | 20 |

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Site Routers | Typical Client Count | Throughput | Concurrent Tunnels |
| AER2200 | 100 | 40 Mbps | 20 |
| E100, E102 | 5 | 40 Mbps | 20 |
| E300 | 50 | 400 Mbps | 20 |
| E3000 | 100 | 400 Mbps | 20 |

**NOTE**: Hybrid Mesh Firewall site performance may vary based on latency conditions.**NOTE**: Hybrid Mesh Firewall site performance may vary based on latency conditions.**NOTE**: Hybrid Mesh Firewall site performance may vary based on latency conditions.

## AI-Driven Insights

*(Requires a Premium license)*

- **AI-driven insights** – An integrated AIOps dashboard detects performance driven anomalies and flags them to the administrator pinpointing the root cause and recommended remediation.
- **Virtual Expert capabilities** – While Ericsson’s NetCloud Assistant (ANA) is available across all NetCloud Manager dashboards, more specialized functionality is available with a NetCloud Secure Connect or SD-WAN Premium license.

## NetCloud Virtual Edge

## NetCloud Exchange Appliances and Specifications

**NetCloud Virtual Edge** is a cost-effective and simple solution for organizations that need to connect to one or more data center or private cloud environments as part of their zero-trust network.

| PERFORMANCE |  |  |  |
| --- | --- | --- | --- |
| Deployment Targets: | AWS | Azure | VMware |
| Tunnel Throughput to/from NetCloud Exchange: | 300 Mbps | 300 Mbps | 2 Gbps |
| Instance: | m5.large | Standard_D2s_v5 | VMware ESXi 6.7 U3 hypervisor or newer |
| vCPUs: | 2 | 2 | 2 |
| Memory: | 8 GB | 8 GB | 8 GB |
| Minimum Disk Space: | 2 GB | 2 GB | 2 GB |
| vNICs: | 2 | 2 | 2 |

## NetCloud Exchange Service Gateway (Virtual Appliance)

*(customer-hosted deployment model only)*

**NetCloud Exchange Service Gateway** is a service delivery platform (or headend) that can reside standalone or in an active/standby configuration in a customer’s data center or hosted cloud. The service gateway aggregates traffic from IoT, vehicle, site, and remote work environments, enforces policy, and provides visibility into every flow.

| PERFORMANCE |  |  |
| --- | --- | --- |
| Licensed Capacities † : | 250 Mbps 500 Mbps 1 Gbps 2 Gbps 4 Gbps |  |
| SYSTEM REQUIREMENTS (ALL CAPACITIES) |  |  |
| Deployment: | AWS | Azure |
| Instance: | c5.2xlarge | Standard_D8S_v3 |
| vCPUs: | 8 | 8 |
| Memory: | 16 GB | 32 GB |
| Minimum Disk Space: | 16 GB | 16 GB |
| vNICs: | 3 | 3 |
| Minimum NetCloud Exchange Service Gateway Release: | 7.23.80 | 7.23.80 |
| Concurrent Tunnels: | Up to 4,000 | Up to 4,000 |

| PERFORMANCE |  |  |
| --- | --- | --- |
| Licensed Capacities † : | 250 Mbps 500 Mbps 1 Gbps 2 Gbps 4 Gbps |  |
| SYSTEM REQUIREMENTS (ALL CAPACITIES) |  |  |
| Deployment: | KVM | VMware |
| VM Manager Version: | Proxmox 8.3.x | ESXi 6.7 or newer vCenter 7.03.00500 or newer |
| Instance: | N/A | N/A |
| vCPUs: | 8 | 8 |
| Memory: | 16 GB | 16 GB |
| Minimum Disk Space: | 16 GB | 16 GB |
| vNICs: | 3 | 3 |
| Minimum NetCloud Exchange Service Gateway Release: | 7.23.80 | 7.23.80 |
| Concurrent Tunnels: | Up to 4,000 | Up to 4,000 |

Performance testing was conducted based on requirements as defined in RFC2544 using fixed-frame 1518-byte packets. Throughput results reflect unidirectional. UDP traffic with less than 1% packet loss as tested with wired connections. At the time of release, the number of supported sites and tunnels is a 1:1 ratio. Ericsson Cradlepoint routers support multiple WAN interfaces simultaneously in SD-WAN mode.
Performance testing was conducted based on requirements as defined in RFC2544 using fixed-frame 1518-byte packets. Throughput results reflect unidirectional. UDP traffic with less than 1% packet loss as tested with wired connections. At the time of release, the number of supported sites and tunnels is a 1:1 ratio. Each Ericsson Cradelpoint router only supports one tunnel on one active WAN interface at a time.

## NetCloud Exchange Service Gateway Hardware Appliance (SG4000)

The **NetCloud Exchange Service Gateway Hardware Appliance** delivers the full capabilities of the software service gateway in a low-touch, on-premises form factor—ideal for public sector and other organizations that must keep data off public clouds or have limited IT resources.

| PERFORMANCE |  |
| --- | --- |
| Licensed Capacities † : | 500 Mbps 1 Gbps 2 Gbps 4 Gbps |
| SYSTEM CAPACITIES |  |
| Deployment: | Rack mount, 1 RU |
| Minimum NetCloud Exchange Service Gateway Release: | 7.26.20 |
| Concurrent Tunnels: | Up to 4,000 |
| INTERFACES |  |
| Processor: | Intel® 13th Gen Core™ i7-13700E |
| Memory: | 64 GB DDR5 non-ECC UDIMM |
| Ethernet: | 2 x 10GbE SFP+ Intel XL710 1 x 2.5GbE RJ45 MGMT Intel i226-LM 1 x GbE RJ45 IPMI Intel i210 |
| ENVIRONMENTAL |  |
| Temperature: | Operating: 0 °C to 40 °C (32 °F to 104 °F) Storage: -40 °C to 70 °C (-40 °F to 158 °F) |
| Humidity: | Operating: 5% to 90% Storage: 5% to 95% |
| POWER |  |
| Required: | AC Input Rated 100-120V~ / 200-240V~, 6A, 50-60Hz (each) |
| Consumption: | Idle: 79.9 W Typical: 133.9 W Heavy: 162.3 W |
| PHYSICAL |  |
| Size: | 438 x 350 x 44 mm (17.2 x 13.8 x 1.7 in) |
| Weight: | 5 kg (11 lb) |
| RELIABILITY |  |
| Calculated MTBF: | 86,919 hours (Telcordia SR332 Issue 4) |
| CERTIFICATIONS |  |
| Safety: | UL/cUL CB Scheme |
| Substance Compliance: | RoHS |
| Regulatory: | FCC (U.S.) ISED (Canada) CE (European Union) UKCA (UK) |
| LEDs |  |
|  | Refer to the SG4000 NetCloud Exchange Service Gateway Setup and Deployment Guide . |

### Physical Measurements & Features

†Performance testing was conducted based on requirements as defined in RFC2544 using fixed-frame 1518-byte packets. Throughput results reflect unidirectional. UDP traffic with less than 1% packet loss as tested with wired connections. At the time of release, the number of supported sites and tunnels is a 1:1 ratio. Ericsson Cradlepoint routers support multiple WAN interfaces simultaneously in SD-WAN mode.

### Ordering Guidelines

- **Step 1 (required): **Select the **deployment model** cloud delivered or customer hosted.
- **Step 2 ****(required):** Select the **NetCloud Service plan(s)** for the compatible router(s).
- **Step 3 ****(customer hosted only)****:** Select the NetCloud Service Gateway **capacity** for entire solution. **NOTE**: Separate part numbers for high availability.
- **Step 4 ****(required)****:** Select the Secure Connect or SD-WAN **site (router-based) license(s)** in either Standard or Premium for each router. **NOTE**: Each NetCloud Exchange cloud-delivered license for mobile or branch routers includes 500 GB for a shared data pool. IoT routers have unlimited data.
- **Step 5 (optional):** Select the number of ZTNA user licenses.
- **Step 6 (optional): **Select the NetCloud Virtual Edge in either Standard or Premium per each additional data center or private cloud environment beyond where the NetCloud Service Gateway is located (selection of Standard or Premium must match Step 4). **NOTE**: Each NetCloud cloud-delivered license includes 500 GB for a shared data pool.
- **Step 7 (optional cloud delivered only for mobile and branch deployments):** Select additional 500 GB data credits to add to the shared data pool.

| REGION | NetCloud PACKAGE | DESCRIPTION | PART NUMBER |
| --- | --- | --- | --- |
| All Regions: | NetCloud Exchange Secure Connect (cloud delivered) | Standard Premium Premium Add-On | NCS-0K0x-SCDC NCS-0KPx-SCDC NCS-0NPx-HMFAI |
|  | NetCloud Exchange Secure Connect | Standard Premium Premium Add-On | NCX-0K0x-SC NCX-0KPx-SC NCX-0NPx-HMFAI |
|  | NetCloud Exchange SD-WAN (cloud delivered) | Standard Premium Premium Add-On | NCS-0L0x-SCDCSD NCS-0LPx-SCDCSD NCS-0B0x-SDWAN |
|  | NetCloud Exchange SD-WAN | Standard Premium Premium Add-On | NCX-0L0x-SCSD NCX-0LPx-SCSD NCX-0B0x-SDWAN |
|  | NetCloud Exchange ZTNA (cloud delivered) | Standard (Per User) | NCS-0E0x-ZTNA |
|  | NetCloud Exchange ZTNA | Standard (Per User) | NCX-0E0x-ZTNA |
|  | NetCloud Exchange Virtual Edge (cloud delivered) | NetCloud Standard for Virtual Edge with Secure Connect NetCloud Premium for Virtual Edge with Secure Connect | NCS-0M0x-VESCDC NCS-0MPx-VESCDC |
|  | NetCloud Exchange Virtual Edge | NetCloud Standard for Virtual Edge with Secure Connect NetCloud Premium for Virtual Edge with Secure Connect | NCX-0M0x-VESC NCX-0MPx-VESC |
|  | NetCloud Exchange Data Credit (cloud delivered) | 500 GB | NCS-0D0x-DC |
|  | NetCloud Exchange Service Gateway Virtual Appliance | 250 Mbps 500 Mbps 1 Gbps 2 Gbps 4 Gbps | NCX-000x-SG250MBPS NCX-000x-SG500MBPS NCX-000x-SG1GBPS NCX-000x-SG2GBPS NCX-000x-SG4GBPS |
|  | NetCloud Exchange Service Gateway Virtual Appliance High Availability | Active + Standby 250 Mbps Active + Standby 500 Mbps Active + Standby 1 Gbps Active + Standby 2 Gbps Active + Standby 4 Gbps | NCX-002x-SGAS250MBPS NCX-002x-SGAS500MBPS NCX-002x-SGAS1GBPS NCX-002x-SGAS2GBPS NCX-002x-SGAS4GBPS |
|  | NetCloud Exchange Service Gateway Hardware Appliance (SG4000) | 500 Mbps 1 Gbps 2 Gbps 4 Gbps | NCXSG4000-xSG-500MBPSN NCXSG4000-xSG-1GBPSN NCXSG4000-xSG-2GBPSN NCXSG4000-xSG-4GBPSN |
|  | NetCloud Exchange Service Gateway Hardware Appliance (SG4000) High Availability | Active + Standby 500 Mbps Active + Standby 1 Gbps Active + Standby 2 Gbps Active + Standby 4 Gbps | NCXSG4000-xSGAS-500MBPSN NCXSG4000-xSGAS-1GBPSN NCXSG4000-xSGAS-2GBPSN NCXSG4000-xSGAS-4GBPSN |
| All Regions — Renewal: | NetCloud Exchange Secure Connect (cloud delivered) | Renewal — Standard Renewal — Premium Renewal — Premium Add-On | NCS-0K0x-SCDC-R NCS-0KPx-SCDC-R NCS-0NPx-HMFAI-R |
|  | NetCloud Exchange Secure Connect | Renewal — Standard Renewal — Premium Renewal — Premium Add-On | NCX-0K0x-SC-R NCX-0KPx-SC-R NCX-0NPx-HMFAI-R |
|  | NetCloud Exchange SD-WAN (cloud delivered) | Renewal — Standard Renewal — Premium Renewal — Premium Add-On | NCS-0L0x-SCDCSD-R NCS-0LPx-SCDCSD-R NCS-0B0x-SDWAN-R |
|  | NetCloud Exchange SD-WAN | Renewal — Standard Renewal — Premium Renewal — Premium Add-On | NCX-0L0x-SCSD-R NCX-0LPx-SCSD-R NCS-0B0x-SDWAN-R |
|  | NetCloud Exchange ZTNA (cloud delivered) | Renewal — Standard (Per User) | NCS-0E0x-ZTNA-R |
|  | NetCloud Exchange ZTNA | Renewal — Standard (Per User) | NCX-0E0x-ZTNA-R |
|  | NetCloud Exchange Virtual Edge (cloud delivered) | Renewal NetCloud Standard for Virtual Edge — Per Self-Hosted Virtual Appliance Renewal NetCloud Premium for Virtual Edge — Per Self-Hosted Virtual Appliance | NCS-0M0x-VESCDC-R NCS-0MPx-VESCDC-R |
|  | NetCloud Exchange Virtual Edge | Renewal NetCloud Standard for Virtual Edge — Per Self-Hosted Virtual Appliance Renewal NetCloud Premium for Virtual Edge — Per Self-Hosted Virtual Appliance | NCX-000x-VESC-R NCX-0MPx-VESC-R |
|  | NetCloud Exchange Data Credit (cloud delivered) | Renewal — 500 GB | NCS-0D0x-DC-R |
|  | Service Gateway | Renewal — 250 Mbps Renewal — 500 Mbps Renewal — 1 Gbps Renewal — 2 Gbps Renewal — 4 Gbps Renewal Active + Standby — 250 Mbps Renewal Active + Standby — 500 Mbps Renewal Active + Standby — 1 Gbps Renewal Active + Standby — 2 Gbps Renewal Active + Standby — 4 Gbps | NCX-000x-SG250MBPS-R NCX-000x-SG500MBPS-R NCX-000x-SG1GBPS-R NCX-000x-SG2GBPS-R NCX-000x-SG4GBPS-R NCX-002x-SGAS250MBPS-R NCX-002x-SGAS500MBPS-R NCX-002x-SGAS1GBPS-R NCX-002x-SGAS2GBPS-R NCX-002x-SGAS4GBPS-R |
x = 1, 3, or 5 years
