Table of Contents
- Overview
- Account Creation
- Forgotten Password
- VeeaHub Manager Mobile App
- Accessing SecureConnect
- Managing Sites (Locations)
- Individual Site Administration
- SecureConnect
- Insights
- Settings
Overview
Organization Admins can manage their SecureConnect deployment with:
- Administrative view and management
- Portal views
- Creating new Sites and Users
- Troubleshooting network issues
- Insights
- Devices, applications
- Performance
SecureConnect User Profiles
Account Creation
Your new SecureConnect Organization Admin account will be created on your behalf.
- First-time users will receive a welcome email asking to verify their email address which authorizes their account.
- Whitelist emails from @veea.co to avoid missing critical messages.
- You will receive a temporary password in this welcome email.
- Tap or click on the “Visit Control Center” link at the bottom of the email. https://controlcenter.veea.co/
- You will arrive at the Control Center login page.
- Enter your account email address and the temporary password from your welcome email.
- Tap or click the Login button.
You will arrive on a page where you can choose your new (permanent) password. Tap or click the Submit button when finished. To reset this password in the future, please visit the Settings section of Control Center, referenced in the “Settings” section of this Guide.
Forgotten Password
If you’ve forgotten your account password, simply select the “Forgot Password?” link.
You will be asked to provide your account email address, and then select Submit.
You will be taken to the “New Password” page to create a new permanent password.
VeeaHub Manager Mobile App
VeeaHub Manager (VHM for short) is a mobile app to keep Organization and Site admins connected and in control of the Veea Secure Connect environments. Please view the separate VHM SecureConnect Guide for more information.
Hub Enrollment
Using the VHM Mobile App, SecureConnect Hubs are enrolled into their respective Sites. Enrolling the Hub is essential in order for it to be properly set up for using SecureConnect. For more information, please review the separate Unboxing, Installation and Enrollment Guide.
Accessing SecureConnect
- Visit: controlcenter.veea.co
- Use your Organization Admin credentials.
After logging in, you will land on the home screen viewing a dashboard across all of the Sites (locations) in your Organization.
At the upper right, you will see links to view your account settings and active notifications (bell icon). Please reference the Settings section of this guide for more information.
Managing Sites (Locations)
Sites Home Page
On the Sites page, you have access to:
- View a list of all sites in your account
- Search for a site
- Add a new site
- Delete a site
- View, add and remove site administrators
- Change site names
To add a new site, select “Add Site” at the upper right of the page.
Site User Accounts
From the icons to the right of each Site, you can:
View the list of Site Admins
When viewing the Site Admins, you can also edit their profile or delete their account.
Add a Site Admin
Additional Site Management Features
Rename the Site
Delete a Site
*Note that when deleting a Site, as a precaution, you’ll first need to unenroll the network(s) and delete the Site Admins.
Select the Site to access administrative capabilities for that Site. You can also select individual Sites to administer at any time from the upper left Site dropdown menu as noted below.
Individual Site Administration
Site Home Page
On the Site page, you can view a dashboard of the overall heath and cellular data usage across the networks at that Site.
Networks Page
Clicking on the Networks tab on the left brings you to the Networks page where you can view a list of SecureConnect Hubs installed at that Site along with the health status of each Hub.
Click on the Network name (in blue) to access its Network home page.
Network Home Page
Buttons at the upper right give you options to change the network name or configure Wi-Fi.
Configure Wi-Fi
After selecting the “Configure Wi-Fi” button, you can modify the names and passwords of the built-in network profiles. Once modified, click the “Apply Changes” button at the upper right.
On the Network home page, you can see if there are software updates available (displayed center-page), and there are options for removing a VeeaHub, restarting or powering down a VeeaHub and as well as resetting the device.
*Please note that removing a VeeaHub should only be used if you plan to Unenroll the Hub and re-enroll it into another site/location.
Remove VeeaHub
Restart, Shutdown and Reset capabilities are availability when click on the righthand icon.
Restart, Shutdown and Reset
In the Power section, you will be presented with the options to restart (power-cycle) or shutdown (power-down) the Hub.
In the Reset menu, you will access Reset options
* Please note that while VeeaHub Resets completely clear the settings which are possibly preventing a hub from working properly, this should only be performed while on support calls with Veea and when prompted by a Veea customer service agent to do so. This will essentially “wipe” the Hub, making it non-operational until it is re-enrolled again.
Installed Firmware
On the Networks home page, you can see the current version of firmware running on the Hub. This can be important for Support escalations and troubleshooting.
Locations Page
It’s important to make sure a Site and its Hubs have Locations created so that the Hub status can be monitored from the central management network operations center.
Click on the “New Location” button at the upper right to get started.
Enter the Location name and street address or GPS Lat/Long coordinates and then click the “Create” button.
You will then arrive back at the Home Page for Locations. Click your new location name (in blue) to continue setting up your location.
At the upper right, click on the button “Add VeeaHubs”. This will assign the Hub at this site to the location you just created.
Your Hub should be listed – just check the box next to it and click on the “Add VeeaHub” button.
Location setup is now complete!
SecureConnect
All SecureConnect networking functionality, set up, operations, insights and dashboards are found here.
After clicking on the SecureConnect link on the lefthand pane, you will land on the home page and see a security dashboard of observed threats, phishing attempts and blocked web sites across the Organization.
Sites
The Sites page shows a list of Sites (locations) for that Organization and provides the ability to Edit or Remove the Site.
*Caution: removing the Site will remove network functionality for that location. This is only to be used in decommissioning a Site.
The Edit Site Option provides options for editing the Site name and adding/removing Site Administrators.
At the bottom of the page, you will see a list of Networks at that Site with the ability to Edit or Remove the Network.
*Caution: removing the Network will remove network functionality for that location. This is only to be used in decommissioning a Network.
All Networks
The All Networks section lists provides a real time view into networks in use across the Organization including:
- a network list
- online status
- version of SecureConnect software
- live network views
- editing network information
All Networks home page (below)
Select the Edit Network action icon on the righthand side to view the:
- organization name
- hub serial number
- network ID number
- control plane IP address
You can also select whether to enable or disable Insights for this Network.
Port Forwarding
Click the “Add Port Forward Rule” button to add port forwarding rules.
Select the “Live Network View” action icon on the righthand side to access a live view of the Conectividad control plane.
This view includes:
- devices authorized
- active profiles
- online status
- WAN IP
- host tunnels
Select the “Show Historical Data” tab in the upper right side to view charts on:
- data transfer
- blocked traffic
- latency
- packet loss
- jitter
- TCP health
Authorizing Devices onto the Network
Scrolling down the Live Network View page, you will find a list of devices and their authorization status.
Clicking on the device name brings you to the home page for that device where you can either Authorize or Block it from joining the network. Once authorized, you can visit this link again to Deauthorize the device at any time.
Be sure to click Save after making your selection.
All Endpoint Devices
The All Endpoint Devices tab displays a list of connected devices across the Organization. This includes each given device’s security profile as well as detailed connection information about each device. You can search for individual devices using the search bar at the upper right.
Selecting a device on the left hand side will show you a drop down with operating system and respective version number for that device.
Select the “Edit This Device” action button to personalize the device name and view more detailed device details including:
- IP Address
- Hostname
- MAC Address
- Connection Length (time)
- Authorization Status
Here, you can either Authorize or Block the device from joining the network. Once authorized, you can visit this page again to Deauthorize the device at any time.
Be sure to click Save after making your selection.
Security Policies
Content filtering and profile administration are found under the. Security Policies tab on the left-hand pane.
Content Filtering
On the Content Filtering page, you will find a list of existing content filtering policies, the ability to edit them and at the upper right of the page, a button to select to implement new policies.
The first tab under Content Filtering is “Categories”. Here, you simply click on the categories you want added or removed. The Categories marked red are filtered out.
The next tab is for managing security threats. The categories highlighted here will be blocked by this policy.
The third tab is the allowed list. Here, you can either manually add or import a .csv file of web sites that are allowed to be visited by users of SecureConnect.
The final tab is for managing blocked lists. Here you can manually add or import a .csv file of web sites to be blocked.
Profiles
This page allows you to edit the 3 default connectivity profiles: Guest, Common and Secure. When devices connect to the network, they’ll be assigned to one of these profiles.]
Selecting the action button to the right, allows you to set device authorization handling for each of the profiles.
SecureConnect Administration Menu
In the Administration menu, you can select Settings to make custom network configurations, and you can click Administrators to view a list of administrators in your organization.
SecureConnect Custom Network Configuration
Click on "Custom Network Settings" button to access the option to make custom changes to network settings, including LAN, DHCP, Subnet, MTU, and more.
Note: SecureConnect uses complex custom network settings to support the features provided. Changes to these settings can permanently disable your network.
Any changes will require a system reboot to properly update your network.
Here you will see the default Network Policy installed with SecureConnect. In the top right, you have the option to create additional network policies.
Select the "Edit this Network Policy" icon to access advanced network features that you can customize.
You'll arrive at the default Organization Policy page with options to:
- Manual adjustment of the MTU (Maximum Drive Unit)
- Change the LAN setting from Auto (default) to Custom (where changes can be made to DHCP).
Note: Make sure you've received proper networking training before making changes to this section. A full power-on cycle is required for changes to the LAN configuration to take effect.
Note: Be sure to click Save in the upper-right corner to save any changes you've made.
Selecting the Custom option for LAN configuration will present you with options to:
Broadcast Bridge
The broadcast bridge configuration allows endpoints on one LAN to discover endpoints on another LAN. The Secure and Common LANs are part of the same broadcast LAN, to allow, for example, a laptop in Segura to discover and print to a printer in Common.
An endpoint connected to the guest network (LAN3) is not part of the Broadcast Bridge.
The Broadcast Bridge subnet must be a subnet that contains all the Broadcast Bridge LAN subnets and must not overlap with the subnet of any other interface.
Careful subnet calculations must be performed to meet this requirement or the network will malfunction.
DHCP Interface Configuration
The three supported LANs are Common (LAN1), Secure (LAN2), and Guest (LAN3).
For each of the LANs the following can be configured:
Subnet/Mask
The subnet must be an RFC 1918 address. The subnet and its mask must be entered in valid CIDR notation where the IP is the LAN IP of the hub.
The subnet can be any RFC 1918 address, as long as it does not conflict with the hub's WAN subnet, i.e., the subnet that the hub is connected to for its Internet access. For example, if the WAN IP of the hub is 192.168.1.1, none of the LAN subnets can be 192.168.1.1/24, nor can the broadcast bridge overlap with the 192.168.1.1/24 subnet.
The chosen subnet or mask must not overlap with the subnet or mask on another LAN.
DHCP Lease Time
Any time can be chosen, but it is recommended that it be longer than 1 hour and less than 24 hours.
DHCP Range
The DHCP range, start and end, must be within (be part of) the configured subnet.
Static DHCP leases
Choose the endpoint device from the list and then enter the desired DHCP lease IP. The static DHCP lease IP must be within (be part of) the DHCP Range for the LAN segment being configured.
The endpoint device must be power-on to get this new IP and work properly on the network.
Note: Be sure to click Save in the upper-right corner to save any changes you've made.
SecureConnect Administrators
Selecting the action icon next to an individual Org Admin allows you to select for them to receive notifications and to view a list of sessions when they were logged into the system with their account.
Insights
Insights provides powerful views for SecureConnect Administrators
- Provides detailed views into bandwidth usage
- Devices and device bandwidth
- Protocols used
- Applications and bandwidth consumption
- Many other views network wide or site specific, that can be used for customer care and system management
You can access Insights from the lefthand pane from any menu within SecureConnect.
After selecting “Insights”, you will be prompted to choose a Site (location) from within your Organization.
If asked for a password, leave the field blank. You will arrive on the Site Analysis home page.
Site Panel (Main Dashboard)
On this Site Panel landing page, you’ll see Site-level dashboards for:
- Recent Events
- Recent Connected Devices
- Aggregate Bandwidth
- Top Known DNS Domains
- Top Device MACs
- Top Applications by Bandwidth
- Top Protocols Used
- Top Countries
- IP Reputation
- Encryption Audit
- Insecure Protocols
- Cryptocurrency Detection
- VPN Detection
- Tor Detection
- Unencrypted Password Use
You can also view Insights across all the Sites (locations) in an Organization. Please refer to the “Insights Organization View” section of this document for more information.
Each element can be clicked into for expanded reporting and its own dashboard view. For instance, here’s a view of the Geolocation Dashboard:
Events
In the Events section are two options – Event Log and Subscribe.
The Event Log shows a description of the event, the category it falls under, a timestamp for when it occurred and an Action button to the right to acknowledge the event.
The Subscribe Menu lets you enable logs and email and mobile notifications by category.
Device Discovery
The Device Discovery section provides all the relevant information on devices connected into the network – both local and external.
The Overview page shows a dashboard of device types and operating systems connected to the network, device events and a timeline of device activity.
The Timeline page shows time-based information around device discovery.
The Local and External Device pages show a discovery list of all connected devices including:
- Device type
- Device OS
- MAC address
- Recent IP address
- Last seen status
Clicking on the “Inventory Device” button to the right allows you to manually enter a device name and assign it to an owner, group and OS.
Risk and Reputation
The Risk and Reputation section allows you to dive into IP reputation, Cryptocurrency traffic, Encrypted traffic, Insecure protocols, Unencrypted passwords, and anomaly detection.
The IP Reputation page shows a dashboard of traffic deemed to be high risk.
The Cryptocurrency page identifies devices associated with known cryptocurrency nodes.
The Encryption Audit page shows a dashboard focused on encrypted traffic on the network.
The insecure protocols page shows a dashboard of insecure protocols in use over the network.
The Unencrypted Password page shows when unencrypted passwords are in use over the network.
Policy and Compliance
The Policy and Compliance section shows insight into the use of Servers, VPN and Tor over the network.
Server Discovery Page / Dashboard
VPN Detection Page / Dashboard
Tor Detection Page / Dashboard
Hostnames
In the Hostnames section, you will find dashboards and insights into the domains, DNS and DHCP information in use over the network.
Here is an example of the Overview page:
On the DNS page, you will see top known DNS domains as well as top DNS host names.
You can click into each entry for a detailed analysis card showing traffic and devices.
On the Local page, there is a Hostname scoring table, showing top traffic by device type.
On the Stream page, you will see Hostnames mapped to the protocol they connected over, the domain they connected to and the time at which they connected. Note that you will need to click on “Filters” in the upper right and set the time interval for 24 hours or less to generate data for this page.
Bandwidth
In the Bandwidth section, you can access insights into the top consumers of data across the network including the amount of data consumed by web site, service and application type.
On the Top Consumers page, you will see a dashboard showing data consumed by web sites and services used by devices connecting to the network. You can adjust the time range by clicking on the Filters icon at the upper right.
On the Scoreboard page, you’ll find charts showing listings of applications across upload and download consumption.
You can click into each entry to view a detailed card for that particular application.
On the Aggregate Page, you’ll see a bandwidth chart by day for uploaded and downloaded data. You can also see a breakout of data consumed and average network speed across the time period selected.
Network Metrics
The Network Metrics section provides insight into traffic by network protocol and by IP address.
On the Overview page, you find a dashboard showing network traffic by protocol over the time period selected. You will also see the IP addresses ranked by amount of data consumed.
On the Top Consumers page, you will see charts and tables showing the top data consumers by IP address over a period of time. You can adjust the time range by clicking on the Filters icon at the upper right.
The Scoreboard page shows upload and download tables of data use by IP address.
Device Metrics
The Device Metrics section provides device-level details for data used across the network.
On the Overview page, you will see a dashboard view with charts and tables showing traffic by device.
The Top Consumers page shows time-based data consumption broken out by uploading and downloading traffic.
The Scoreboard page shows a trending view of the amount of data uploaded and downloaded across the network.
Applications
The Applications section provides analysis into applications, web sites and services that traffic in the network is connecting to.
On the Overview page, there is a dashboard view of bandwidth by application and also by application category. You can adjust the time range by clicking on the Filters icon at the upper right.
On the Top Consumers page, you will find detailed views on data uploaded and downloaded by application / service.
The Scoreboard page shows table views and trends of data used by application.
Protocols
The Protocols section provides a detailed look into the protocols being used across device connections on the network.
The Overview page shows a dashboard view of data use by protocol and is also broken into both upload and download traffic.
The Top Consumers page shows graph and table views of top uploaders and downloaders by protocol type.
The Scoreboard page shows both a ranked view and trends of data consumption by protocol.
Geolocation
The Geolocation section shows network data consumption and flow by city, region and country.
The Overview page shows a global dashboard view with breakout tables by location.
The Top Consumers page shows both upload and download traffic and data consumed by country.
The Scoreboard page shows table views with trends for network data use by Country.
Flows
The Flows section shows traffic and data consumption by device ID.
The Overview page shows a dashboard view with consumption by device over time.
*Note that this data is available for time periods of 24 hours or less. To adjust the time period, click on the “Filters” link at the upper right.
The Scoreboard page shows trends and both upload and download traffic by device flow.
The Flows page shows a table view of device traffic on the network. This table includes Device ID, Device type, hostname, application connection, protocol, geolocation and time visited.
Settings
My Account Menu
After selecting the settings menu, you will arrive on the My Account Tab. Here, you can:
- Log out of your account
- Change your default language in Control Center
- Change your password
- View open sessions from your other devices
Password Reset
If you would like to update your password, select the “Change Password” link (as shown above). You will be asked to confirm your existing password and to enter your new password. Click on the Save button when finished.
Organization Admins Menu
In the Organization Admins tab, you can see a list of Administrator accounts.