> For the complete documentation index, see [llms.txt](https://docs.gxc.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gxc.io/docs/network-configuration-and-operations-guides/4g-onyx-portal-4.x-operations/manage-equipment/manage-onyx-edge.md).

# Manage Onyx Edge

The Onyx Edge is the Evolved Packet Core (EPC) function of the Onyx network. It provides the backhaul connectivity to the APs and Mesh Nodes. The Onyx Edge terminates the Control Plane traffic from the APs and most of the management plane traffic from the Onyx Portal. It also enforces traffic policies on the user plane traffic from the subscribers.

### View Onyx Edge Details

This section describes how to:

* [*View Summary Details of All Onyx Edge*](#view-summary-details-of-all-onyx-edge)
* [*View an Onyx Edge's Details*](#view-an-onyx-edges-details)

#### View Summary Details of All Onyx Edge

**To view the summary details of all Onyx Edge in the network:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.

* **Onyx Edge (n)** – (n) indicates the number of Onyx Edge in the network.
* Status of services running on the Onyx Edge.

  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FJk145EQJhFMBGoE9Be8P%2Fimage.png?alt=media&amp;token=f9524954-2fd5-435b-8208-0f52b36bc1d0" alt="" data-size="line"> Green – Indicates all critical services are up and running, none of the critical services were restarted in the last five minutes, and the Onyx Edge's Interface Status is green.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FfhxCDUkPjJ2edzMDaivI%2Fimage.png?alt=media&amp;token=2c120687-5e98-452b-a601-82ca85c65069" alt="" data-size="line"> Amber – Indicates all critical services are up and running, but critical services have restarted up to three times in the last five minutes, and the Onyx Edge's Interface Status is green or amber.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FITWEpzVeyeTRAwHr8Qs8%2Fimage.png?alt=media&amp;token=d082fddb-f3a4-4185-9772-575126e4869e" alt="" data-size="line"> Red – Indicates some critical service has gone down in the last five minutes, or critical services have restarted up to three times in the last five minutes, or the Onyx Edge's Interface Status is red.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FD8AgwtIGO4ByUfmRAX8F%2Fimage.png?alt=media&amp;token=66ef4597-48ec-436b-b834-4aee0ca0b828" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline, or data is not available.

  Hovering your cursor over the "Service Status" icon displays the list of services that are up/down/restarted.
* **Name** – The Onyx Edge's name.
* **Venue / VM** – The name of the venue or the VM hosting the Onyx Edge.
* **Access Point** – The number of APs that are MME-connected to the Onyx Edge is displayed in green, and those that are MME-disconnected in red.

  To view the AP names, hover your cursor over the counts.
* **Subs** – The number of subscribers connected to the Onyx Edge.
* **Online** – The Onyx Edge's online status indicating its reachability from the Onyx Portal.

  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FJrrXZRCv8frKxIyPw27n%2Fimage.png?alt=media&amp;token=6db051a8-1c11-4b4b-ae63-697c44206561" alt="" data-size="line"> Green – Indicates the Onyx Edge has checked-in with Onyx Portal in the last five minutes.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FJIyyoPtdtRE1pShsX94j%2Fimage.png?alt=media&amp;token=9196e717-4de4-4b29-80d6-0e118ecd7839" alt="" data-size="line"> Red – Indicates the Onyx Edge has not checked-in with the Onyx Portal in the last five minutes.

  Hovering your cursor over the "Online Status" icon displays the last synced at (last check-in) timestamp.
* **Interface Status** – Indicates connection status of SGi and RAN (S1) interfaces.

  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FlSrOl3ImFUYkJAl8RTXg%2Fimage.png?alt=media&amp;token=283c9750-a5bb-49d0-822d-e54f0bd3f8cc" alt="" data-size="line"> Green – Indicates all APs are MME-connected to the Onyx Edge, the SGi interface is up and has IP, and SGi link is active (periodic ICMP checks every five minutes).
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVl5llwzMaZ6PtNBPyJqa%2Fimage.png?alt=media&amp;token=691b8159-7333-4bfd-b823-52824fa66b6e" alt="" data-size="line"> Amber – Indicates at least one AP is MME-connected, but some are not, the SGi interface is UP and has IP (SGi link is active).
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FdmWLnG8LCLimSlB4F2zn%2Fimage.png?alt=media&amp;token=0d795c0a-3a33-4057-821b-9fb3b3b053a3" alt="" data-size="line"> Red – Indicates none of the APs are MME-connected (that is all APs are MME-disconnected or management-disconnected (MME status is unknown)), or the SGi interface is not up or is not active (SGi link activity check through ICMP).
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FEVOqxkDfvCjWy6rKynoe%2Fimage.png?alt=media&amp;token=3d87cfed-fa64-4914-abf9-0a7b3ee53693" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline.

  Hovering your cursor over the "Interface Status" icon displays the following details:

  * **MME Connected APs** – Number of MME-connected APs.
  * **MME Disconnected APs** – Number of MME-disconnected APs.
  * **Offline APs** – Number of APs whose MME connection status is unknown.
  * **SGI Info (IP address)** – SGi interface's IP address.
  * **Reporting Time** – SGi health last reported timestamp.
* **Compute Resource** – Indicates utilization of the Onyx Edge's computing resources – CPU percentage, Memory percentage, and Disk Utilization percentage.

  * &#x20;<img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FmyRM32iQMzeWDREI5xUL%2Fimage.png?alt=media&amp;token=4af47e72-e734-4b6a-87ae-1be84b166536" alt="" data-size="line"> Green – Indicates all parameters are below 50%.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F8MvfMWKoIPuaOglaTK3J%2Fimage.png?alt=media&amp;token=41d02fc1-d704-4e3d-b700-36cc4ea3079d" alt="" data-size="line"> Amber – Indicates at least one parameter is above 50% and below 70%.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FchmcDIYbMR39WRtpGeYG%2Fimage.png?alt=media&amp;token=b460b6f9-2245-48a1-92e8-f6a512fdf012" alt="" data-size="line"> Red – Indicates at least one parameter is above 70%.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVzSdxIOcnbyolzZBsKOh%2Fimage.png?alt=media&amp;token=1224cb7c-d366-4828-8260-9f27c56f3106" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline.

  Hovering your cursor over the "Compute Resource Status" icon displays the following details:

  * **Disk Utilization** – Percentage of disk space used for the volume mounted at root.
  * **CPU Utilization** – System-wide CPU utilization as percentage over one second.
  * **Memory Utilization** – Percentage of memory used.
* **IPSec** – Indicates the Onyx Edge's IPSec status.

  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FlGQGBv1PrKpN72zovej5%2Fimage.png?alt=media&amp;token=d6d9f794-bb83-485d-be7a-3cce2f490dd0" alt="" data-size="line"> Green – The Onyx Edge is IPSec-enabled, and all IPSec-enabled APs have active IPSec tunnels with the Onyx Edge.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVuNfRzdbN4nYpKwh0ohh%2Fimage.png?alt=media&amp;token=58bff764-94d8-4e83-8a68-15e276195313" alt="" data-size="line"> Amber – The Onyx Edge is IPSec-enabled, and while at least one IPSec-enabled AP has an active IPSec tunnel with the Onyx Edge, other IPSec-enabled APs are unreported or have bad IPSec status.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FTMJH5opeIfzMyHLKUlUJ%2Fimage.png?alt=media&amp;token=3067dc9c-d5b3-4a70-ad1c-e31e33e55e6a" alt="" data-size="line"> Red – The Onyx Edge has bad IPSec status, and/or all IPSec-enabled APs are unreported or have bad IPSec status.
  * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FbTJrHTldNLM8OPUWZFBr%2Fimage.png?alt=media&amp;token=399e42cb-48a1-4826-9cc5-e63aec55ca4a" alt="" data-size="line"> Grey – The Onyx Edge is offline, is IPSec-disabled, and/or all the APs are IPSec-disabled.

  Hovering your cursor over the "IPSec Status" icon displays the counts of IPSec-connected and IPSec-not-connected APs.
* **Actions** – Options to view details, edit, and delete the Onyx Edge.
* **Upgrade Onyx Edge** – (GXC Administrators only.) To upgrade the Onyx Edge software on the Onyx Edge AGWs in the network. For information on managing Onyx Edge upgrades, see [*Manage Onyx Edge Software Upgrades*](#manage-onyx-edge-software-upgrades).
* **UE Throughput** – Trend chart of the throughput of all UE for the selected Onyx Edge, direction, and duration. The chart represents downlink throughput in blue and uplink throughput in green color. This graph excludes Mesh UE traffic.
* **Onyx Edge Pool** – The list of Onyx Edge pools in the network and their details. For information on Onyx Edge pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
  * Status – The Onyx Edge pool's HA connectivity status.

    * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FC3xMdnY44R6TK46VUkyw%2Fimage.png?alt=media&amp;token=07d44f3f-6b55-4926-91b7-580b5d495e48" alt="" data-size="line"> Green – One Onyx Edge is functioning as the Primary ACS, and the others as Standby ACS.
    * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FOeMqVEVSjf6b1RHSnoSv%2Fimage.png?alt=media&amp;token=5bdbd573-b4c5-46a4-a6cc-27f084ad3b0b" alt="" data-size="line"> Amber – One Onyx Edge is functioning as the Primary ACS, but one or more of the other Onyx Edge are non-functional.
    * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F4vDwy1hze0L8vmwXcXuT%2Fimage.png?alt=media&amp;token=af612f63-6dea-4284-b14b-4e20a9bb5d6e" alt="" data-size="line"> Red – All Onyx Edge are non-functional, or their status is not available.
    * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F1gErlJz5JZkar9OYjry1%2Fimage.png?alt=media&amp;token=929318c5-4c3f-4fab-bc51-a2ec22b34c89" alt="" data-size="line"> Grey – All Onyx Edge are offline.

    Hovering your cursor over the "HA Connectivity Status" icon displays which Onyx Edge are designated as the Primary and Standby ACS.
  * **Name** – The Onyx Edge pool's name.
  * **HA IP Address** – The virtual management IP address used to anchor TR069 endpoint in the Primary ACS Onyx Edge.
  * **Associated Onyx Edge** – The number of Onyx Edge associated with the pool.
  * **Associated Access Points** – The number of APs associated with the pool.
  * **Actions** – Options to view details, edit, and delete the Onyx Edge pool.
  * **Add Pool** – (GXC Administrators, Customer Administrators, or Administrators only.) To add an Onyx Edge pool. For information on managing Onyx Edge Pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
* **Onyx Edge Connected with Onyx Portal** – Trend chart of the number of Onyx Edge connected with the Onyx Portal in the selected duration.
* **UE Attach Status** – Plot of control plane transaction outcomes for all or a selected Onyx Edge, transaction type, and duration. Success count is displayed in green, and failure count in red color. Select the event type from the following:
  * **Attach Request** – Initial requests from a UE to connect to the network.
  * **Auth Request** – Authentication requests to verify UE/subscriber identity.
  * **Create Session Request** – Requests to establish a data session for user-plane traffic.
  * **Service Request** – Requests for specific network services.
  * **Handovers** – Requests to transfer an active connection between cells.
    {% endstep %}
    {% endstepper %}

#### View an Onyx Edge's Details

**To view the details of an Onyx Edge in a 4G network:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
To view the details of a particular Onyx Edge, in the **Onyx Edge (n)** panel, click its name.

The Onyx Edge details page > **Overview** tab displays the following details:

* **Overview** tab:
  * **Onyx Edge Details**:
    * **Type** – The Onyx Edge's deployment type.
    * **Name** – The Onyx Edge's name.
    * **Pool Name** – If the Onyx Edge is associated with an Onyx Edge pool, the pool's name. For information on Onyx Edge Pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
    * **Host Name** – The Onyx Edge's hostname.
    * **Description** – The Onyx Edge's description.
    * **SGi Interface (Eth0)** – The SGi interface's eth0 IP address.
    * **S1 Interface (Eth1)** – The S1 interface's eth1 IP address.
    * **Version** – The Onyx Edge's software version.
    * **Upgrade Status** – Status of the previous Onyx Edge software upgrade. Note that the **Upgrade Status** parameter is displayed only during and for one hour after an upgrade.

      To view details, click the status.

      The **Upgrade Status** dialog box displays the following details:

      * **Description** – Description of the last upgrade's status.
      * **Old Version** – The Onyx Edge software version before the upgrade.
      * **New Version** – The new Onyx Edge software version.
      * **Updated At** – The timestamp at which the last upgrade completed.
      * **Start Time** – The timestamp at which the last upgrade started.
    * **Up Time** – The duration for which the Onyx Edge has been operational without any downtime or interruptions.
    * **Venue** – The name of the venue hosting the Onyx Edge. To view the venue's details, click its name.
    * **Hardware Address** – (Displayed only for Onyx Edge On-Premises) The Onyx Edge's eth0 hardware address.
    * **More Info >>** – Click to view the following additional details. The **More Details** dialog box is displayed.
      * **Hardware UUID** – The Onyx Edge's Hardware Universally Unique Identifier (UUID) used for device authentication to ensure secure communication. To copy the hardware UUID to the clipboard, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FG2vCKbjlEPNGUitTE1wu%2Fimage.png?alt=media&amp;token=7e9f9a79-2b22-4eaa-a5ab-77923b4b227c" alt="" data-size="line">.
      * **Challenge Key** – The Onyx Edge's Challenge Key used in challenge-response authentication mechanism. To copy the challenge key to the clipboard, click <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FxkDHBK1JSir9lUMUov4t%2Fimage.png?alt=media&amp;token=ca8aa6ac-130c-483b-9ae3-ebe74fb94cde" alt="" data-size="line">.
      * **AGW User Configuration** – The AGW User account's password, displayed only if it has been set. If the AGW User account's password has not been changed from the default value, a warning message is displayed.
      * **SSH Keys** – The AGW User account's SSH key used for secure, password-less access to the system using public-private key authentication; displayed only if it has been added. If a key has not been added, the default key is used.
    * The Onyx Edge's health status.
      * **Online** – The Onyx Edge's online status indicating its reachability from the Onyx Portal.

        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FgTuDyEtZ51Zdlp6QjuAO%2Fimage.png?alt=media&amp;token=9703211d-ce34-481a-b848-1893ebbd4909" alt="" data-size="line"> Green – Indicates the Onyx Edge has checked-in with Onyx Portal in the last five minutes.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FnPTK8nEsUjWcnakpT3Pj%2Fimage.png?alt=media&amp;token=fc8a7ef0-0c45-4164-adef-583e970bbc49" alt="" data-size="line"> Red – Indicates the Onyx Edge has not checked-in with the Onyx Portal in the last five minutes.

        Hovering your cursor over the "Online Status" icon displays the last check-in timestamp.
      * **Interface Status** – The Onyx Edge's interface status indicating the connection status of SGi and RAN (S1) interfaces.

        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FdmMzGVlqVy5KYRttt8CG%2Fimage.png?alt=media&amp;token=221dff5c-185d-4585-89cb-741244a79e35" alt="" data-size="line"> Green – Indicates all APs are MME-connected to the Onyx Edge, the SGi interface is up and has IP, and SGi link is active (periodic ICMP checks every five minutes).
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FQS01x07XeSWeO5eWIlPf%2Fimage.png?alt=media&amp;token=bd6b640b-9293-4729-9b73-32a7e7a9d98c" alt="" data-size="line"> Amber – Indicates at least one AP is MME-connected, but some are not, the SGi interface is UP and has IP (SGi link is active).
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FeK6IWH3t64mEHynCRalK%2Fimage.png?alt=media&amp;token=0f564326-772e-4c10-ba88-02d5ba1d86cf" alt="" data-size="line"> Red – Indicates none of the APs are MME-connected (that is all APs are MME-disconnected or management-disconnected (MME status is unknown)), or the SGi interface is not up or is not active (SGi link activity check through ICMP).
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fjr5PiVg2ZIcCPI5wQtqq%2Fimage.png?alt=media&amp;token=f1889c90-615b-4902-a16b-fe1028e0e875" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline, or data is not available.

        Hovering your cursor over the "Interface Status" icon displays the following details:

        * **MME Connected APs**
        * **MME Disconnected APs**
        * **Offline APs**
        * **SGi Info (IP Address)**
        * **Reporting Time**
      * **Compute Resource** – Status of the Onyx Edge's computing resources.

        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Ffwp1bF5mav9yqAG9PZ8M%2Fimage.png?alt=media&amp;token=0b5cac9c-27bd-433a-ad39-eb5537a9148c" alt="" data-size="line"> Green – Indicates all parameters are below 50%.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FqnEOrFP4EW7V414l1p5r%2Fimage.png?alt=media&amp;token=c9545663-0c5c-4a89-b744-aa2a860c4fe5" alt="" data-size="line"> Amber – Indicates at least one parameter is above 50% and below 70%.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FdbH1Ss1NFE90tyj7ytIg%2Fimage.png?alt=media&amp;token=3a10dc73-a85c-4a74-bf30-d2b9bd9faecb" alt="" data-size="line"> Red – Indicates at least one parameter is above 70%.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FPSOZp0GbiOlZQ9hfqyFu%2Fimage.png?alt=media&amp;token=055fe363-e478-4c12-8011-df8a527b3581" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline.

        Hovering your cursor over the "Compute Resource Status" icon displays the following details:

        * **Disk Utilization** – Percentage of disk space used for the volume mounted at root.
        * **CPU Utilization** – System-wide CPU utilization as percentage over one second.
        * **Memory Utilization** – Percentage of memory used.
      * **Service Status** – Status of the Onyx Edge's services.

        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fe2iqdRoFk8Peg9jPROLT%2Fimage.png?alt=media&amp;token=542043e3-3272-4f14-8f51-81822cd0e8d3" alt="" data-size="line"> Green – Indicates all critical services are up and running, none of the critical services were restarted in the last five minutes, and the Onyx Edge's Interface Status is green.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVyOy9GqBgf9vlCaQ5JBF%2Fimage.png?alt=media&amp;token=f8e8108e-6fad-4679-952c-4fa552c43fed" alt="" data-size="line"> Amber – Indicates all critical services are up and running, but critical services have restarted up to three times in the last five minutes, and the Onyx Edge's Interface Status is green or amber.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F5vyNarBe595BHfvYslau%2Fimage.png?alt=media&amp;token=8f582a8b-3f23-4d01-9cf2-8523512fed1a" alt="" data-size="line"> Red – Indicates some critical service has gone down in the last five minutes, or critical services have restarted up to three times in the last five minutes, or the Onyx Edge's Interface Status is red.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FwPKWO0K84HpQCuhaMkr2%2Fimage.png?alt=media&amp;token=f763c28d-1816-4b9f-99d2-2b29b0920a44" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline, or data is not available.

        Hovering your cursor over the "Service Status" icon displays the list of services that are up/down/restarted.
      * **IPSec Status** – The Onyx Edge's IPSec status.

        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F0cCkQ7P8A2bwFrkmKYxA%2Fimage.png?alt=media&amp;token=6d91bfee-daee-40bd-a76c-728688cf91e2" alt="" data-size="line"> Green – The Onyx Edge is IPSec-enabled, and all IPSec-enabled APs have active IPSec tunnels with the Onyx Edge.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FRtcdcmELpNFasE2hUp8h%2Fimage.png?alt=media&amp;token=1a8345ed-39af-43d9-9008-b8a6d3c52890" alt="" data-size="line"> Amber – The Onyx Edge is IPSec-enabled, and while at least one IPSec-enabled AP has an active IPSec tunnel with the Onyx Edge, other IPSec-enabled APs are unreported or have bad IPSec status.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F1yssOwC0JuS1Pz2Y2YSu%2Fimage.png?alt=media&amp;token=855f92b9-a0c1-4859-908d-56a7a70a51cf" alt="" data-size="line"> Red – The Onyx Edge has a bad IPSec status, and/or all IPSec-enabled APs are unreported or have bad IPSec status.
        * <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F5lDaFqMR0va9GKpD8ZkN%2Fimage.png?alt=media&amp;token=8c221668-2a07-4433-9bdf-01ba3fd6e4bd" alt="" data-size="line"> Grey – Indicates the Onyx Edge is offline, is IPSec-disabled, and/or all the APs are IPSec-disabled.

        Hovering your cursor over the "IPSec Status" icon displays the counts of IPSec-connected and IPSec-not-connected APs.
* **Core**:
  * **UE IP Configuration**:
    * **IP Block** – The IP pool from which the Onyx Edge allocates IP addresses to UE.
    * **IP Retention Time (sec)** – The duration (in seconds) for which a UE's IP address is retained/leased after it disconnects.
  * **DNS Server for UE**:
    * **Onyx Edge-as-DNS-Server** – Indicates if the Onyx Edge functions as the DNS server—Enabled or Disabled.
    * **DNS Secondary Server** – (Displayed only when **Onyx Edge-as-DNS-Server** is enabled.) Enabled or Disabled. When enabled, if the Onyx-Edge is unavailable, or if it fails to resolve domain name, the UE will contact the DNS secondary server for domain name resolution.
    * **DNS Primary** – The primary DNS server's IP address.
    * **DNS Secondary** – The secondary DNS server's IP address.
  * **SGI Interface**:
    * **SGI Interface** – The UE IP address allocation mode—Static or DHCP.
    * **IP Subnet** – (Displayed only if UE IP allocation mode is Static.) The management IP address for Onyx Edge to reach corporate network/internet.
    * **Gateway** – (Displayed only if UE IP allocation mode is Static.) The corporate gateway router IP address.
    * **DNS Primary** – (Displayed only if UE IP allocation mode is Static.) The primary DNS server's IP address.
    * **DNS Secondary** – (Displayed only if UE IP allocation mode is Static.) The secondary DNS server's IP address.
    * **SGI Management VLAN** – (Displayed only in VLAN mode if UE IP allocation mode is Static.) The SGi Management VLAN ID.
  * **Mesh Node Management**:
    * **Onyx Edge-Tunnel-Anchoring Subnet** – The Onyx Edge subnet used to set up tunnels with Mesh Nodes.
    * **Mesh Node Assignment Subnet** – The subnet used to assign IP addresses to APs behind Mesh Nodes.
    * **Mesh Node UE Assignment Subnet** – (Displayed only in VLAN mode.) The subnet to assign IP addresses for CPEs to attach to the Onyx Edge.
    * **Mesh Node VLAN** – (Displayed only in VLAN mode.) The VLAN ID used for APN to VLAN mapping.
  * **Per APN Details** – (Displayed only in VLAN mode.) For each APN, the following details are displayed. Note that APNs are common to all Onyx Edge in the network.
    * **APN Name** – The APN's name. To view the APN's details, click its name.
    * **VLAN ID** – The VLAN ID.
    * **Local IP** – The local IP address / subnet of the Onyx Edge on the VLAN.
    * **Default GW IP** – The Onyx Edge's IP address.
    * **Default GW MAC** – The Onyx Edge's MAC address.
* **NAS Security Algorithms**
  * **Integrity Algorithm** — The NAS integrity protection algorithm in use.
  * **Encryption Algorithm** — The NAS encryption algorithm in use.
* **DHCP Server Monitoring** — (Displayed only in VLAN mode) Indicates whether DHCP Server Monitoring is active for this Onyx Edge — **Enabled**, **Disabled**.
  * **Frequency** — (Displayed only in VLAN mode if **DHCP Server Monitoring** is enabled) How often the system checks DHCP server availability, in minutes.
  * **MAC** — (Displayed only in VLAN mode if **DHCP Server Monitoring** is enabled) The MAC address used by the monitoring probe when sending DHCP requests.
  * **VLAN** — (Displayed only in VLAN mode if **DHCP Server Monitoring** is enabled) The VLAN on which the monitoring probe sends DHCP requests, ensuring the check targets the correct network segment.
* **Backhaul Speedtest** – Prioritized list of iPerf-compatible speedtest servers used to measure backhaul link performance. The following details are shown for each entry:
  * **Priority** – The priority order in which speedtest servers are tried.
  * **URL** – The hostname/URL of the speedtest server.
  * **Port Range** – The port range used for the speedtest.
* **Dynamic Services** – Status of the Onyx Edge's dynamic services.
  * **Event Aggregation** – Indicates the status of event aggregation for Onyx Edge services. Aggregated events are displayed in event lists and charts in the Onyx Portal interface. This feature is always enabled and cannot be disabled.
  * **Log Aggregation** – Indicates the status of log aggregation from gateway services. Aggregated logs are displayed in log lists and charts in the Onyx Portal interface. This feature is always enabled and cannot be disabled.
  * **CPE Monitoring** – The status of the CPE Monitoring service—Enabled or Disabled. When enabled, the Onyx Edge sends ICMP pings every minute to each connected UE. The measured round-trip time (RTT) latency is reported in the per-subscriber details. See **Subscribers** > subscriber details > **UE Latency** parameter.
* **Data Usage** – The Onyx Edge's data usage for the selected duration.
  * **Download** – The download data usage for the selected duration.
  * **Upload** – The upload data usage for the selected duration.
* **Mesh Node** – Details of Mesh Nodes connected to the Onyx Edge.
  * The Mesh AP's RF Tx status.
  * **Name** – The Mesh Node's name.
  * **Serial No.** – The Mesh Node's serial number.
  * **RSSI (dBm)** – The Mesh Node's Received Signal Strength Indicator (RSSI) level in dBm.
  * **Online** – The Mesh Node's online status.

    To view the last check-in timestamp, hover your cursor over the "Online Status" icon. To view details of all Mesh Nodes, click **View All**. The **Mesh Nodes** page is displayed.
* **RAN**:
  * **S1 Interface**:
    * **S1 Interface** – If enabled, Static or DHCP. Static indicates the Onyx Edge serves as the DHCP server for static IP address allocation to directly connected APs. DHCP indicates DHCP is enabled for IP address allocation to the Onyx Edge's S1 interface.
    * **IP/Subnet** – (Displayed only if S1 interface is enabled in Static mode.) The subnet from which the first IP address is used for the S1 interface. In the case of AP DHCP Service, the rest are for IP address allocation to APs to connect to the Onyx Edge.
    * **Access Point DHCP Service** – (Displayed only if S1 interface is enabled in Static mode.) Indicates the AP DHCP service status—Enabled or Disabled. When enabled, the Onyx Edge serves as a DHCP server for IP address allocation to directly connected APs.
    * **Start IP** – (Displayed only when the AP DHCP service is enabled.) The DHCP pool's start IP address.
    * **No. of IP** – (Displayed only when the AP DHCP service is enabled. Required.) The number of IP addresses.
  * **Onyx Edge IPSec Configuration**:
    * **IPSec** – The Onyx Edge's IPSec configuration status—Enabled or Disabled.
      * **Advanced Config** – (Displayed only when **IPSec** is enabled.) To view the advanced configuration parameters, click the <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FfapjNdQNxwrV9DegQ5yO%2Fimage.png?alt=media&amp;token=dc69221b-9fb3-41d5-9fac-8670c7190a4c" alt="" data-size="line"> (view details) icon:
      * **Ike Rekey Time (seconds)** – Time in seconds for renewing Internet Key Exchange (IKE) Security Association.
      * **Child SA Rekey Time (seconds)** – Time in seconds for renewing IPSec Security Association.
      * **DPD Time (seconds)** – Time in seconds to do Dead Peer Detection (DPD) for idle peers.
      * **MTU Overhead (bytes)** – IPSec overhead to each packet in bytes to assume for MTU calculation of actual UE packets.
      * **Allow Non-IPSec Direct APs** – Specifies whether all directly connected APs are expected over IPSec. If set to **False**, all direct-APs must be coming over IPSec, the Onyx Edge will reject any clear-text connection attempts. If there is a mix of both IPSec and non-IPSec APs, set to **True**. Note that Mesh-APs are always non-IPSec. This setting only deals with direct-APs.
      * **MME Local IP** – The inner IP address on which the MME service is available within the IPSec tunnel.
      * **AP Assignment Subnet** – Whenever IPSec is established, the Onyx Edge runs the DHCP service to provide IP address for the AP to use from this subnet.
* **Connected Access Point** – Details of APs connected to the Onyx Edge:
  * The AP's RF Tx status.
  * **Name** – The AP's name.
  * **Serial No.** – The AP equipment's vendor-assigned serial number.
  * **IP Address** – The AP's IP address.
  * **VIP Address** – For IPSec-enabled APs, the Virtual IP address (inner IP address) used for MME connection.
  * **Online** – The AP's online status. To view the last check-in timestamp, hover your cursor over the "Online Status" icon.
  * **Interface Status** – The AP's interface status. To view the following details, hover your cursor over the "Interface Status" icon:
    * **MME Status**
    * **Last Synced At**
  * **IPSec Status** – The status of the IPSec tunnels with the Onyx Edge and the IPSec certificate's validity. Note that the certificate status is that of the generated certificate, and not of the one uploaded to the AP. To view the status details, hover your cursor over the "IPSec Status" icon.
* **Subscribers** – Details of subscribers connected to the Onyx Edge.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE</strong>: For non-GXC Administrator users this list excludes MeshBackhaul subscriber data.</p></div>

  * **Status** – The subscriber account's status.
  * **Name** – The subscriber account's name.
  * **IMSI** – The subscriber's IMSI. To view the subscriber account's details, click the IMSI.
  * **Subscriber Group ID** – The subscriber group that the subscriber account is associated with. To view the subscriber group's details, click its name. For information on subscriber groups, see *Manage Subscriber Groups*.
  * **View All Subscribers** – Click to view details of all subscriber accounts in the network. The **Subscribers** page is displayed.
    {% endstep %}

{% step %}
Click the **Events & Alerts** tab.

* **Events & Alerts** tab:
  * **Alerts** – Details of Onyx Edge related alerts for the selected severity level.

    Select the alert severity level from **All**, **Major**, **Minor**, **Critical**, or **Others**.

    * **Date** – The alert's creation timestamp.
    * **Status** – The alert's status.
    * **Alert Name** – The alert's name.
    * **Severity** – The alert's severity.

    To view an alert's details, click the corresponding row.
  * **Events** – Details of Onyx Edge related events for the selected duration:

    * **Timestamp** – The event's creation timestamp.
    * **Module** – The specific module or source from which the event originated. To filter the events based on module, click the **Module** column header and select one or more modules.
    * **Event Type** – The event's type. To filter the events based on the event type, click the **Event Type** header and select one or more event types.
    * **Entity** – The associated entity's name.
    * **Event Description** – The event's description.

    To view more details for a particular event, click the corresponding ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FiAIHX23TmbavcG8VNCvy%2Fimage.png?alt=media\&token=0e5589c2-9d38-4ad3-96d7-85911d2a9bd3) (view details) icon.
    {% endstep %}

{% step %}
Click the **Logs** tab.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FDpZZX9BLorOmk8KhjQtg%2Fimage.png?alt=media&amp;token=af5cd052-ec8e-4909-8d8f-2e9471d733c4" alt=""><figcaption></figcaption></figure>

* **Logs (n)** – The number of logs for the Onyx Edge in the selected date and time range.
  * Download Logs – To download the logs in .csv format, in the <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FioD8wNf4nYeUcI0UXKeT%2Fimage.png?alt=media&amp;token=dd70e970-1c87-4908-90f4-4a514a40713d" alt="" data-size="line"> field enter the number of logs to be included in the .csv file, then click the <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FJAoMUAVryUVMrGcApZrU%2Fimage.png?alt=media&amp;token=5b902c9a-e118-4849-9145-7a1d0d80ffb7" alt="" data-size="line"> icon. Default value: 5000. The downloaded .csv file includes details such as the timestamp, service, tag, type, and log text.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> You can download a maximum 5000 logs.</p></div>
  * Date and Time Range – To view logs in a specific date and time range, select the required timestamps in the <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FTgcLUaNcjArjGIV25nRO%2Fimage.png?alt=media&amp;token=7b8222a6-55f6-4939-b6bf-0891f218ba0e" alt="" data-size="line"> date/time fields. The logs list automatically updates to display the corresponding logs.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> Your selections must fall within a seven-day range.</p></div>
  * Search Logs – To search for a log, enter your search term in the <img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FgjUILIcy8ujZCS0dCnoU%2Fimage.png?alt=media&amp;token=0b36959f-e979-4f38-82bf-93a1f13aec76" alt="" data-size="line"> search field. The logs list updates automatically to display matching logs.
    * **Timestamp** – The date and time at which the log was created.
    * **Service** – The specific service associated with the log.
    * **Tag** – The event's tag—a label associated with the log entry.
    * **Type** – The log's type.
    * **Output** – The log's message.
      {% endstep %}

{% step %}
In the upper-right corner of the page, click the **Actions** button to access the following options.

{% hint style="info" %}
Note that the **Actions** button is enabled only when the Onyx Edge is online.
{% endhint %}

* **Upgrade** – (GXC Administrators, Super Administrators, and Administrators only.) Upgrade the Onyx Edge's software version, move the Onyx Edge to the required target upgrade group. For more information, see [*Move an Onyx Edge from one Upgrade Group to Another*](#move-an-onyx-edge-from-one-upgrade-group-to-another).
* **Reboot Onyx Edge** – (GXC Administrators, Super Administrators, and Administrators only.) Reboot the Onyx Edge. Services will be down while the equipment reboots.
* **Restart Services on Onyx Edge** – (GXC Administrators, Super Administrators, and Administrators only.) Restart the Onyx Edge's core services. Connectivity will be down until the services resume.
* **Ping** – (GXC Administrators, Super Administrators, and Administrators only.) Ping the Onyx Edge's host. Enter the following details, then click **Ping**.
  * **Host** – (Required) The host's IP address.
  * **Packets (default 4)** – (Optional) The number of packets to send. Default: 4.
* **Reboot AP** – (GXC Administrators, Super Administrators, and Administrators only.) Reboot all or a specific AP. Enter the following details, then click **Execute**.
  * **Reboot AP** – Select to reboot a specific AP in the network.

    In the **Select an AP** dropdown, select the AP's serial number.
  * **Reboot All APs** – Select to reboot all APs in the network.
* **Reboot Neighbor Updated AP** – (GXC Administrators, Super Administrators, and Administrators only.) Schedule reboots for APs with pending neighbor changes:

  <div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FwwE0pYTAmdW1ZHgI85pm%2Fimage.png?alt=media&amp;token=74d5c842-0076-44ca-8916-f4e36fa283a9" alt="" width="563"><figcaption></figcaption></figure></div>

  * Reboot all APs with reboot pending at a chosen time, including immediately.
  * Reboot a specific AP by serial number, if it has a reboot pending, at a chosen time including immediately.
* **Detach Subscriber** – (GXC Administrators, Super Administrators, and Administrators only.) Forcibly detach an active subscriber/UE. Enter the following details, then click **Execute**.
  * **Subscriber IMSI** – The subscriber's IMSI.
* **Force Config Sync** – (GXC Administrators, Super Administrators, and Administrators only.) Trigger a full configuration synchronization.
* **Force Status Sync from Onyx Edge** – (GXC Administrators, Super Administrators, and Administrators only.) Trigger Onyx Edge state synchronization. This action control is useful when investigating stale status displays or validating a change without waiting for the next periodic sync.
* **Force Subscriber Config Sync** – (GXC Administrators, Super Administrators, and Administrators only.) Trigger a configuration synchronization for a specific subscriber.
* **Trigger Debug Information Collection** – (GXC Administrators, Super Administrators, and Administrators only.) Collect logs and telemetry from Onyx Edge.
* **List Debug Information Files in OE** – (GXC Administrators, Super Administrators, and Administrators only.) View downloadable debug files available on the Onyx Edge.
* **Generic Command** – (GXC Administrators only.) Run generic commands on the Onyx Edge.

  The **Run Onyx Edge Command** dialog box is displayed.

  Enter the following details, then click **Execute**:

  * **Command** – (Required) The command to run.
  * **Parameters** – (Optional) The command's parameters/values.
    {% endstep %}
    {% endstepper %}

### Add Onyx Edge

This section describes how to add an Onyx Edge to 4G networks.

* [*Add Onyx Edge to 4G Network in NAT Mode*](#add-onyx-edge-to-4g-network-in-nat-mode)
* [*Add Onyx Edge to 4G Network in VLAN Mode*](#add-onyx-edge-to-4g-network-in-vlan-mode)

#### Add Onyx Edge to 4G Network in NAT Mode

{% hint style="info" %}
**NOTE:** You can add an Onyx Edge only if you are a GXC Administrator, Partner Administrator, Super Administrator, or an Administrator.
{% endhint %}

{% hint style="info" %}
**NOTE:** Before adding an Onyx Edge On-Premises, make sure that the customer account, required network, and venue exist.
{% endhint %}

{% hint style="info" %}
**NOTE:** Onyx Edge can be deployed either as standalone or as a pool to enable MME/Onyx Edge High Availability. For information on High Availability and Onyx Edge Pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
{% endhint %}

{% hint style="info" %}
**NOTE:** To add Onyx Edge in NAT mode, you must disable VLAN mode at the network level.
{% endhint %}

{% hint style="info" %}
**NOTE**: For detailed information on the networking modes supported by the GXC 4G Onyx Platform, refer to the *4G & 5G Networking Modes Application Note*. The document covers NAT and Bridge (APN-on-VLAN) modes — including Classic and Flat variants for 4G — detailing their architectures, traffic flows, isolation characteristics, and trade-offs. It also provides step-by-step configuration guidance for each mode via the Onyx Portal.
{% endhint %}

**To add an Onyx Edge to a 4G network in NAT mode:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
In the upper-right corner of the page, click **Add Node** > **Add Onyx Edge**.

The **Create Onyx Edge** page > **Onyx Edge** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fg11UcTCZbs1OwoSVIxjE%2F4g-nat-mode-oe-add-onyx-edge-tab.png?alt=media&amp;token=ad4a7ec5-dd5c-4bb5-be6c-91ef76ab3439" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **On Premises** – Select to add an Onyx Edge On-Premises.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> For information on Onyx Edge Cloud, contact GXC Technical Support.</p></div>
* **Venue** – (Required) Click to select the venue hosting the Onyx Edge.
* **Onyx Edge Name** – (Required) The Onyx Edge's name.
* **Host Name** – (Optional) The Onyx Edge's host name to be displayed in the Onyx Edge equipment's interface. The hostname must be an alphanumeric string of 5–64 characters, and can contain uppercase, lowercase, and numeric characters. It cannot contain white spaces or special characters.
* **Description** – (Required) The Onyx Edge's description.
* **Provisioning** – The Provisioning Server uses the Onyx Edge's eth0 hardware address to generate and provision the keys required for it to operate with the Onyx Portal.
  * **Onyx Edge HW Address** – (Required) The Onyx Edge's eth0 hardware address.

    To obtain the eth0 hardware address:

    * Towards the end of the Onyx Edge ISO software installation, the screen displays the Onyx Edge's eth0 hardware address.
    * If you have management access to the Onyx Edge, run the show\_gateway\_info.py command. From the command's output get the eth0 hardware address displayed against the OnyxEdge ID parameter.
    * If you do not have management access to the Onyx Edge, contact GXC Technical Support.
* **Enable Onyx Edge Pool** – (Enabled only if at least one Onyx Edge pool exists in the network.) To associate the Onyx Edge with an Onyx Edge pool, turn on the toggle button.
* **MME Pool** – (Required) Click to select the Onyx Edge pool. \
  Onyx Edge can be deployed as a pool for MME/Onyx Edge High Availability. For information on High Availability and managing Onyx Edge pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
  {% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure Core**.

The **Create Onyx Edge** page > **Core** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FxI6TwQipEEHuKLn5Kwj4%2F4g-nat-mode-oe-add-core-tab.png?alt=media&amp;token=a1a54bab-e72b-442e-9d15-bdab597e2443" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **UE IP Configuration** – IP pool configuration for the Onyx Edge to assign IP addresses to UE.
  * **IP Block** – (Required) The IP address pool from which the Onyx Edge will allocate IP addresses to UE. Default value: 192.168.128.0/24.
  * **IP Retention Time** – (Required) The duration (in seconds) for which a UE's IP address is retained/leased after it disconnects. Default value: 604800 sec (7 days).
* **DNS Server for UE**
  * **Onyx Edge-as-DNS-Server** – Enable or disable the Onyx Edge functioning as the DNS server for UE. Default setting: enabled.
  * **DNS Primary** – (Displayed only when **Onyx Edge-as-DNS-Server** is disabled. Required.) The primary DNS server IP address. Default value: 8.8.8.8.
  * **DNS Secondary** – (Displayed only when **Onyx Edge-as-DNS-Server** is disabled. Required.) The secondary DNS server IP address. Default value: 8.8.4.4.
  * **Second Server** – (Displayed only when **Onyx Edge-as-DNS-Server** is enabled.) If the Onyx Edge is unavailable, or if it fails to resolve domain names, the UE will contact this Second DNS Server for domain name resolution.
    * **DNS Server IP** – (Displayed only when **Second Server** is enabled. Or, if **Onyx Edge-as-DNS-Server** is disabled. Required.) IP address of the second DNS server.
* **SGI Interface**:
  * **Static** – (Optional) Select to configure the management network parameters.
    * **IP/Subnet** – (Displayed only when the **Static** option is selected. Required.) The management IP address for Onyx Edge to reach corporate network/Internet. Default value: 1.1.1.1/24.
    * **Gateway** – (Displayed only when the **Static** option is selected. Required.) The corporate gateway router IP address. Default value: 1.1.1.0.
    * **DNS Primary** – (Displayed only when the **Static** option is selected. Required.) The primary DNS server IP address. Default value: 8.8.8.8.
    * **DNS Secondary** – (Displayed only when the **Static** option is selected. Required.) The secondary DNS server IP address. Default value: 8.8.4.4.
  * **DHCP** – Select to enable DHCP for management interface, to get IP address for the management interface. Default setting: enabled.
* **Mesh Node Management**:
  * **Onyx Edge Tunnel Anchoring Subnet** – (Required) The Onyx Edge subnet used to set up tunnels with Mesh Nodes. Default value: 192.168.133.0/28. If the default value must be changed, contact GXC Technical Support.
  * **Mesh Node Assignment Subnet** – (Required) The subnet used to assign IP addresses to APs behind Mesh Nodes. Default value: 10.0.3.0/24. If the default value must be changed, contact GXC Technical Support.
* **NAS Security Algorithms** – Configure the security algorithms used for Non-Access Stratum (NAS) signaling — the control plane protocol between UE and the 4G Core.
  * **Integrity Algorithm** – (Required) Algorithm used to ensure NAS message integrity.
    * **EIA1** – 128-SNOW 3G integrity protection
    * **EIA2** – (Default) 128-bit AES-based integrity protection (standard 5G/LTE algorithm)
  * **Encryption Algorithm** – (Required) Algorithm used to encrypt NAS messages.
    * **EEA2** – (Default) 128-bit AES-based ciphering
    * **EEA0** – Null encryption
      {% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure RAN**.

The **Create Onyx Edge** page > **RAN** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FcPVoMF4FOf9GNotOfqRF%2F4g-nat-mode-oe-add-ran-tab.png?alt=media&amp;token=94598c10-fe65-46c8-921d-64e307f90d6f" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **S1 Interface**:
  * **Static** – Select Static mode for deployments where the APs are directly connected to the Onyx Edge and are in an L2 network of their own. When the **Access Point DHCP Service** option is also enabled, the Onyx Edge serves as a DHCP server for IP address allocation to directly connected APs. Default setting: enabled.
    * **IP/Subnet** – (Applicable only when **Static** mode is selected. Required.) The subnet from which the first IP address is used for the S1 interface. In the case of AP DHCP Service, the rest are for allocating IP addresses to APs to connect to the Onyx Edge. Default value: 10.0.2.1/24.
    * **Access Point DHCP Service** – (Applicable only when **Static** mode is selected. Required.) Enable or disable the AP DHCP service. When enabled, the Onyx Edge serves as a DHCP server for IP address allocation to directly connected APs.
      * **Start IP** – (Applicable only when **Access Point DHCP Service** is selected. Required.) The start IP address for the DHCP pool. This IP address must be in the same subnet as the static IP address. Default value: 10.0.2.240.
      * **No. of IPs** – (Applicable only when **Access Point DHCP Service** is selected. Required.) The number of IP addresses. This value must not exceed the maximum number of IP addresses of the subnet from **Start IP**. Default value: 15.
  * **DHCP** – Select to enable DHCP for IP address allocation for S1 interface of the Onyx Edge. Default setting: disabled.
  * **Same as SGI** – Select for deployments where the Onyx Edge and AP are not on the same L2 network (private network). Or, where there is no separate L2 network, and the Onyx Edge and AP are directly in the customer's corporate network. The APs get their IP addresses from the customer's network DHCP service. Default setting: disabled.
* **Associated Access Point** – (Optional) Select the APs to directly associate with the Onyx Edge. For information on adding and configuring APs, see [*Manage APs*](#manage-aps).

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> An AP can be associated with any one Onyx Edge or Onyx Edge pool at any time. Only APs that are not associated with any Onyx Edge or Onyx Edge pool are available for association.</p></div>
* **Onyx Edge IPSec Configuration** – Enable or disable IPSec, which, when enabled, establishes a tunnel between the Onyx Edge and associated IPSec-enabled APs for secure communications. Default setting: disabled.
  * **MME Local IP** – (Applicable only when the **Onyx Edge IPSec Configuration** toggle is turned on. Required.) The inner IP address on which the MME service is available is within the IPSec tunnel. Default value: 10.0.10.1. If the default value must be changed, contact GXC Technical Support.
  * **Access Point Assignment Subnet** – (Applicable only when the **Onyx Edge IPSec Configuration** toggle is turned on. Required.) Whenever IPSec is established, the Onyx Edge runs DHCP service to provide IP address for the AP to use from this subnet. Default value: 10.0.30.0/24. If the default value must be changed, contact GXC Technical Support.
  * **Show Advanced Configs** – Click to configure advanced IPSec parameters:

    * **IKE Rekey Time (seconds)** – (Required) Time in seconds for renewing Internet Key Exchange (IKE) Security Association. Default value: 14400 seconds.
    * **Child SA Rekey Time (seconds)** – (Required) Time in seconds for renewing IPSec Security Association. Default value: 3600 seconds.
    * **DPD Time (seconds)** – (Required) Time in seconds for Dead Peer Detection (DPD) of idle peers. Default value: 60 seconds.
    * **MTU Overhead (bytes)** – (Required) IPSec overhead to each packet in bytes to assume for MTU calculation of actual UE packets. Default value: 100.
    * **Allow Non-IPSec Direct APs** – Specify whether all directly-connected APs are expected over IPSec. If all direct-APs must be coming over IPSec, set to **False**. The AGW will reject any clear-text connection attempts. If there is a mix of both IPSec and non-IPSec APs, set to **True**. Note that Mesh-APs are always non-IPSec. This setting only deals with direct-APs. Default setting: False.

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> If IPSec is disabled on Onyx Edge On-Premises, you can only associate IPSec-disabled APs with it.</p></div>

    <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> IPSec is not supported in conjunction with HA/Onyx Edge pools. IPSec-enabled Onyx Edge must not be associated with an Onyx Edge pool. IPSec must not be enabled on Onyx Edge already associated with a pool. For more information, see <a href="#manage-onyx-edge-high-availability"><em>Manage Onyx Edge High Availability</em></a>.</p></div>

{% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure Others**.

The **Create Onyx Edge** page > **Others** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FfEc6awdaaidAa0279yd1%2F4g-nat-mode-oe-add-others-tab.png?alt=media&amp;token=f4b25200-c56c-4512-96b5-8f10b9ef6068" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **CPE Monitoring** – (Optional) Enable or disable data-path latency monitoring for UE connected to the Onyx Edge. Default: Disabled. When enabled, the Onyx Edge sends ICMP pings every one minute to each connected UE. The ping RTT latency is measured and reported in the per subscriber details. See **Subscribers** > Subscriber details > **UE Latency** parameter.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> It is recommended to enable CPE Monitoring only when required as the Onyx Edge keeps sending ICMP pings every one minute to each connected UE and keeps the radio interface busy.</p></div>

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> Some commercially available UE have ICMP ping responses disabled. In such cases, CPE monitoring for the UE fails. In this case, in the subscriber details, the <strong>Last Reported Time</strong> parameter is blank, displayed as \–.</p></div>
* **AGW User Configuration** – (Optional) Onyx Edge *agw\_user* configuration. Allows partners and customers to log on to the Onyx Edge to collect basic debug information, reset Onyx Edge parameters to factory settings, etc. For more information, see the *Onyx Edge On-Premises Installation and Operations Guide*.
  * **Add Keys** –&#x20;
    1. Click to add SSH keys for *agw\_user*.

       The **Add SSH Key** dialog box is displayed.
    2. Enter the SSH key, then click **Save**.

       You can add a maximum of 10 SSH keys.
  * **Change Password** –&#x20;
    1. Click to change the *agw\_user* password.

       The **Change Password** dialog box is displayed.
    2. Enter the following details:

       * **Password** — (Required) Password for *agw\_user*.
       * **Confirm Password** — (Required) Reenter the password to confirm.

       The list of SSH keys is updated.
    3. You have the option to view details, edit, and delete SSH keys.
* **Backhaul Speedtest** — Prioritized list of iPerf-compatible speedtest servers used to measure backhaul link performance. Four servers are pre-configured. The following details are displayed:

  * ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FwA2Au3Dcc1Lcm4zFYam4%2Ficon-drag-handle.png?alt=media\&token=e70342c5-bd26-444f-ad7d-eec7ef1cc7df) (Drag Handle) icon — Drag-and-drop to reorder a speedtest server's priority.
  * **Priority** — The order in which servers are tried (1 being highest).
  * **URL** — The speedtest server's hostname/URL.
  * **Start Port** — The beginning of the port range used for the test.
  * **End Port** — The end of the port range.
  * **Actions** — Allows deleting a server entry.

  Add and manage Backhaul Speedtest servers.

  * **Add Server**
    1. Click to add a speedtest server.\
       A new blank row is added.
    2. Enter the following details:
       * **Server Hostname/URL** — The speedtest server's hostname/URL.
       * **Start Port** — The beginning of the port range used for the test.
       * **End Port** — The end of the port range.
       * Drag and drop to set the server's priority.
  * Delete Server — To delete a server, in the **Actions** column, click the corresponding ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F1oTYgD6vbQgPuwfZ3d3G%2Fspeedtest-server-delete-icon.png?alt=media\&token=7c0fe181-0dbc-4908-bd26-c93ab0ed914b) (delete) icon.
    {% endstep %}

{% step %}
To save the Onyx Edge, in the upper-right corner of the page, click **Save Onyx Edge**.
{% endstep %}
{% endstepper %}

#### Add Onyx Edge in VLAN Mode

{% hint style="info" %}
**NOTE:** You can add an Onyx Edge only if you are a GXC Administrator, Partner Administrator, Super Administrator, or an Administrator.
{% endhint %}

{% hint style="info" %}
**NOTE:** Before you add an Onyx Edge, make sure the customer account, and the required network and venue exist.
{% endhint %}

{% hint style="info" %}
**NOTE:** Onyx Edge can be deployed either standalone or as a pool to enable MME/Onyx Edge High Availability. For information on High Availability and Onyx Edge Pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
{% endhint %}

{% hint style="info" %}
**NOTE:** To add Onyx Edge in VLAN mode, VLAN mode must be enabled at the network level.
{% endhint %}

{% hint style="info" %}
**NOTE**: For detailed information on the networking modes supported by the GXC 4G Onyx Platform, refer to the *4G & 5G Networking Modes Application Note*. The document covers NAT and Bridge (APN-on-VLAN) modes — including Classic and Flat variants for 4G — detailing their architectures, traffic flows, isolation characteristics, and trade-offs. It also provides step-by-step configuration guidance for each mode via the Onyx Portal.
{% endhint %}

**To add an Onyx Edge to a 4G network in VLAN Mode:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
In the upper-right corner of the page, click **Add Node** > **Add Onyx Edge**.

The **Create Onyx Edge** page > **Onyx Edge** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F9e4fnPf0jFVelDFZ0cWv%2F4g-vlan-mode-oe-add-onyx-edge-tab.png?alt=media&amp;token=550840c8-e108-42b0-88fa-1483220eeecc" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

* **On Premises** – Select to add an Onyx Edge On-Premises.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> For information on Onyx Edge Cloud contact GXC Technical Support.</p></div>
* **Venue** – (Required) Select the venue hosting the Onyx Edge.
* **Onyx Edge Name** – (Required) The Onyx Edge's name.
* **Host Name** – (Optional) The Onyx Edge's host name to be displayed in the Onyx Edge equipment's interface. The hostname must be an alphanumeric string of 5–64 characters, and can contain uppercase, lowercase, and numeric characters. It cannot contain white spaces or special characters.
* **Description** – (Required) The Onyx Edge's description.
* **Provisioning** – The Provisioning Server uses the Onyx Edge's eth0 hardware address to generate and provision the keys required for it to operate with the Onyx Portal.
  * **Onyx Edge HW Address** – (Required) The Onyx Edge's eth0 hardware address.

    To obtain the eth0 hardware address:

    * Towards the end of the Onyx Edge ISO software installation, the screen displays the Onyx Edge's eth0 hardware address.
    * If you have management access to the Onyx Edge, run the `show_gateway_info.py` command. From the command's output get the eth0 hardware address displayed against the OnyxEdge ID parameter.
    * If you do not have management access to the Onyx Edge, contact GXC Technical Support.
* **Enable Onyx Edge Pool** – (Enabled only if at least one Onyx Edge pool exists in the network.) To associate the Onyx Edge with an Onyx Edge pool, turn on the toggle button.
  * **MME Pool** – (Required) Click to select the Onyx Edge pool.

    Onyx Edge can be deployed as a pool for MME/Onyx Edge High Availability. For information on High Availability and managing Onyx Edge pools, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
    {% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure Core**.

The **Create Onyx Edge** page > **Core** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FC3Ya3b1Dj8dXhrofBTaU%2F4g-vlan-mode-oe-add-core-tab.png?alt=media&amp;token=533b9619-1878-4f43-a008-d66e15544bf4" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **UE IP Configuration**
  * **IP Retention Time** — (Required) The duration (in seconds) for which a UE's IP address is retained/leased after it disconnects. Default value: 604800 sec (7 days).
* **DNS Server for UE**
  * **Onyx Edge-as-DNS-Server** – Enable or disable the Onyx Edge functioning as the primary DNS server for UE. Default setting: enabled.
    * **DNS Primary** – (Required) The primary DNS server's IP address. Default value: 8.8.8.8.
    * **DNS Secondary** – (Required) The secondary DNS server's IP address. Default value: 8.8.4.4.
    * **Second Server** – If the Onyx Edge is unavailable, or if it fails to resolve the domain name, the UE will contact this Second DNS Server for domain name resolution.
      * **DNS Server IP** – (Displayed only when **Second Server** is enabled. Required.) IP address of the second DNS server.
* **SGI Interface**:
  * **Static** – Select to configure the management network parameters.
    * **IP/Subnet** – (Displayed only when the **Static** option is selected. Required.) The management IP address for Onyx Edge to reach corporate network/Internet. Default value: 1.1.1.1/24.
    * **Gateway** – (Displayed only when the **Static** option is selected. Required.) The corporate gateway router IP address. Default value: 1.1.1.0.
    * **DNS Primary** – (Displayed only when the **Static** option is selected. Required.) The primary DNS server IP address. Default value: 8.8.8.8.
    * **DNS Secondary** – (Displayed only when the **Static** option is selected. Required.) The secondary DNS server IP address. Default value: 8.8.4.4.
    * **SGI Management VLAN** – (Displayed only when **Static** option is selected. Required.) The SGi Management VLAN ID. Default value: 0.
* **Mesh Node Management**:
  * **Onyx Edge Tunnel Anchoring Subnet** – (Required) The Onyx Edge subnet used to set up tunnels with Mesh Nodes. Default value: 192.168.133.0/28. If the default value must be changed, contact GXC Technical Support.
  * **Mesh Node Assignment Subnet** – (Required) The subnet used to assign IP addresses to APs behind Mesh Nodes. Default value: 10.0.3.0/24. If the default value must be changed, contact GXC Technical Support.
  * **Mesh Node UE Assignment Subnet** – (Required) The subnet to assign IP addresses for CPEs to attach to the Onyx Edge. Default value: 192.168.129.0/24.
  * **Mesh Node VLAN** – (Required) The VLAN ID for APN to VLAN mapping. Default value: 2.
* **NAS Security Algorithms** – Configure the security algorithms used for Non-Access Stratum (NAS) signaling — the control plane protocol between UE and the 4G Core.
  * **Integrity Algorithm** – (Required) Algorithm used to ensure NAS message integrity.
    * **EIA1** – 128-bit SNOW 3G-based integrity protection
    * **EIA2** – (Default) 128-bit AES-based integrity protection (standard 5G/LTE algorithm)
  * **Encryption Algorithm** – (Required) Algorithm used to encrypt NAS messages.
    * **EEA2** – (Default) 128-bit AES-based ciphering
    * **EEA0** – Null encryption
* **DHCP Server Monitoring** – Toggle to enable or disable DHCP Server Monitoring for this Onyx Edge. To enable DHCP Server Monitoring, at least one APN with a VLAN must be configured.
  * **MAC** — (Displayed only when **DHCP Server Monitoring** is **Enabled**.) The MAC address used by the monitoring probe when sending DHCP requests — **Random**, **Explicit**. Random, which generates a random MAC address for each probe request. Explicit, which allows a specific MAC address to be entered. Default: Random.
    * **MAC Address** — (Displayed only when **MAC** is set to **Explicit**) The specific MAC address for the monitoring probe.
  * **Frequency (Minutes)** — (Displayed only when **DHCP Server Monitoring** is **Enabled**. Required.) How often the system sends a DHCP probe to check server availability, in minutes. Default: 30.
  * **VLAN** — (Displayed only when **DHCP Server Monitoring** is **Enabled**. Required.) The VLAN on which the monitoring probe sends DHCP requests.
    {% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure RAN**.

The **Create Onyx Edge** page > **RAN** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FcEeVggzjJ4C9jrg2uK4c%2F4g-vlan-mode-oe-add-ran-tab.png?alt=media&amp;token=ba13cd77-569b-419b-aa40-5e7bdbaf74c0" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **S1 Interface**:
  * **Static** – Select Static mode for deployments where the APs are directly connected to the Onyx Edge and are in an L2 network of their own. When the **AP DHCP Service** option is also enabled, the Onyx Edge serves as a DHCP server for IP address allocation to directly connected APs. Default setting: enabled.
    * **IP/Subnet** – (Applicable only when Static mode is enabled. Required.) The subnet from which the first IP address is used for the S1 interface. In the case of AP DHCP Service, the rest are for allocating IP addresses to APs to connect to the Onyx Edge. Default value: 10.0.2.1/24.
    * **Access Point DHCP Service** – (Applicable only when Static mode is enabled. Required.) Enable or disable the AP DHCP service. When enabled, the Onyx Edge serves as a DHCP server for IP address allocation to directly connected APs.
      * **Start IP** – (Applicable only when AP DHCP service is enabled. Required.) The start IP address for the DHCP pool. This IP address must be in the same subnet as the static IP address. Default value: 10.0.2.240.
      * **No. of IPs** – (Applicable only when AP DHCP service is enabled. Required.) The number of IP addresses. This value must not exceed the maximum number of IP addresses of the subnet from **Start IP**. Default value: 15.
  * **DHCP** – Select to enable DHCP for IP address allocation for S1 interface of the Onyx Edge. Default setting: disabled.
  * **Same as SGI** – Select for deployments where the Onyx Edge and AP are not on the same L2 network (private network). Or, where there is no separate L2 network, and the Onyx Edge and AP are directly in the customer's corporate network. The APs get their IP addresses from the customer's network DHCP service. Default setting: disabled.
* **Associated Access Point** – (Optional) Select the APs to directly associate with the Onyx Edge.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> An AP can only be associated with one Onyx Edge or Onyx Edge pool at any time. Only APs that are not associated with any Onyx Edge or Onyx Edge pool are available for association. For information on adding and configuring APs, see <a href="#manage-aps"><em>Manage APs</em></a>.</p></div>
* **Onyx Edge IPSec Configuration** – Enable or disable IPSec. When enabled, establishes a tunnel between the Onyx Edge and associated IPSec-enabled APs for secure communications. Default setting: disabled.
  * **MME Local IP** – (Applicable only when the **Onyx Edge IPSec Configuration** toggle is turned on. Required.) The inner IP address on which the MME service is available is within the IPSec tunnel. Default value: 10.0.10.1. If the default value must be changed, contact GXC Technical Support.
  * **Access Point Assignment Subnet** – (Applicable only when the **Onyx Edge IPSec Configuration** toggle is turned on. Required.) Whenever IPSec is established, the Onyx Edge runs DHCP service to provide IP address for the AP to use from this subnet. Default value: 10.0.30.0/24. If the default value must be changed, contact GXC Technical Support.
  * **Show Advanced Config** – Click to configure advanced IPSec parameters:
    * **IKE Rekey Time (seconds)** – (Required) Time in seconds for renewing Internet Key Exchange (IKE) Security Association. Default value: 14400 seconds.
    * **Child SA Rekey Time (seconds)** – (Required) Time in seconds for renewing IPSec Security Association. Default value: 3600 seconds.
    * **DPD Time (seconds)** – (Required) Time in seconds for Dead Peer Detection (DPD) of idle peers. Default value: 60 seconds.
    * **MTU Overhead (bytes)** – (Required) IPSec overhead to each packet in bytes to assume for MTU calculation of actual UE packets. Default value: 100.
    * **Allow Non-IPSec Direct APs** – Specify whether all directly-connected APs are expected over IPSec. If all direct-APs must be coming over IPSec, set to **False**. The AGW will reject any clear-text connection attempts. If there is a mix of both IPSec and non-IPSec APs, set to **True**. Note that Mesh-APs are always non-IPSec. This setting only deals with direct-APs. Default setting: False.

{% hint style="info" %}
**NOTE:** If IPSec is disabled on Onyx Edge On-Premises, you can only associate IPSec-disabled APs with it.
{% endhint %}

{% hint style="info" %}
**NOTE:** IPSec is not supported in conjunction with HA/Onyx Edge pools. IPSec-enabled Onyx Edge must not be associated with an Onyx Edge pool. IPSec must not be enabled on Onyx Edge already associated with a pool. For more information, see [*Manage Onyx Edge High Availability*](#manage-onyx-edge-high-availability).
{% endhint %}
{% endstep %}

{% step %}
In the lower-right corner of the page, click **Per APN Per Onyx Edge Config**.

The **Create Onyx Edge** page > **APN-VLAN** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FQ3O78b55uoEhcpNJueHu%2F4g-vlan-mode-oe-add-apn-vlan-tab.png?alt=media&amp;token=a60da37d-3696-43fa-ad62-f7ad2ca967d3" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details:

The **APN-VLAN** tab displays the following parameters for the "Internet" APN and any other APNs configured in the network. Verify/update these details for each APN.

* **APN ID** – (Read only) The APN's ID.
* **Local IP / Subnet** – (Required) The local IP address / subnet of the Onyx Edge on the VLAN. It must be unique across all APNs. It must be configured if the VLAN is different from the Management-VLAN.
* **Default GW IP** – (Required) The Onyx Edge's IP address.
* **VLAN** – (Required) The VLAN ID. Each APN must be on a different VLAN. Only one APN can share the Management VLAN at a time. The VLAN ID must be unique across all APNs and can be 0 or 2–4095.
* **Default GW MAC** – (Optional) The Onyx Edge's MAC address.
* **UE-IP-Block**
  * **Enable** – Enables static UE IP block allocation for this APN instead of dynamic assignment.
  * **Start** – (Active only when **Enable** is on.) First IP address in the static block assigned to UE on this APN.
  * **End** – (Active only when **Enable** is on.) Last IP address in the static block assigned to UE on this APN (active only when Enable is on).
    {% endstep %}

{% step %}
In the lower-right corner of the page, click **Configure Others**.

The **Create Onyx Edge** page > **Others** tab is displayed.

<div data-with-frame="true"><figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FYtU6fAmlRE7Arvzma203%2F4g-vlan-mode-oe-add-others-tab.png?alt=media&amp;token=8809e332-3d9b-4e95-87cb-6123196f0d78" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}
Enter the following details.

* **CPE Monitoring** – (Optional) Enable or disable data-path latency monitoring for UE connected to the Onyx Edge. When enabled, the Onyx Edge sends ICMP pings every one minute to each connected UE. The ping RTT latency is measured and reported in the per subscriber details. See **Subscribers** > Subscriber details > **UE Latency** parameter.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> It is recommended to enable CPE Monitoring only when required as the Onyx Edge keeps sending ICMP pings every one minute to each connected UE and keeps the radio interface busy.</p></div>

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>NOTE:</strong> Some commercially available UE have ICMP ping responses disabled. In such cases, CPE monitoring for the UE fails. In the subscriber details, the <strong>Last Reported Time</strong> parameter is displayed as blank \–.</p></div>
* **AGW User Configuration** – (Optional) Onyx Edge *agw\_user* configuration. Allows partners and customers to log on to the Onyx Edge to collect basic debug information, reset Onyx Edge parameters to factory settings, etc. For more information, see *Onyx Edge On-Premises Installation and Operations Guide*.
  * **Add Keys** –&#x20;
    1. Click to add SSH keys for *agw\_user*.

       The **Add SSH Key** dialog box is displayed.
    2. Enter the SSH key, then click **Save**.

       You can add a maximum of 10 SSH keys.
  * **View All Keys** –&#x20;
    1. Click to view existing SSH keys.

       The list of SSH keys is displayed.
    2. You have the option to view details, edit, and delete SSH keys.
  * **Change Password** –&#x20;
    1. Click to change the *agw\_user* password.

       The **Change Password** dialog box is displayed.
    2. Enter the following details:
       * **Password** – (Required) Password for *agw\_user*.
       * **Confirm Password** – (Required) Reenter the password to confirm.
* **Backhaul Speedtest** — Prioritized list of iPerf-compatible speedtest servers used to measure backhaul link performance. Four servers are pre-configured. The following details are displayed:

  * ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FvB8rOrZHGtkQy8Sf3bgQ%2Ficon-drag-handle.png?alt=media\&token=e23d66e0-e3a6-4080-91cd-1331dd53b393) (Drag Handle) icon – Drag-and-drop to reorder speedtest server priority.
  * **Priority** — The order in which servers are tried (1 being highest).
  * **URL** — The speedtest server's hostname/URL.
  * **Start Port** — The beginning of the port range used for the test.
  * **End Port** — The end of the port range.
  * **Actions** — Allows deleting a server entry.

  Add and manage Backhaul Speedtest servers.

  * **Add Server** —&#x20;
    1. Click to add a speedtest server.\
       A new blank row is added.
    2. Enter the following details:
       * **Server Hostname/URL** — The speedtest server's hostname/URL.
       * **Start Port** — The beginning of the port range used for the test.
       * **End Port** — The end of the port range.
       * Drag and drop to set the server's priority.
  * Delete Server — To delete a server, in the **Actions** column, click the corresponding ![](https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2F1oTYgD6vbQgPuwfZ3d3G%2Fspeedtest-server-delete-icon.png?alt=media\&token=7c0fe181-0dbc-4908-bd26-c93ab0ed914b) (delete) icon.
    {% endstep %}

{% step %}
To save the Onyx Edge, in the upper-right corner of the page, click **Save Onyx Edge**.
{% endstep %}
{% endstepper %}

### Edit Onyx Edge

{% hint style="info" %}
**NOTE:** You can edit Onyx Edge details only if you are a GXC Administrator, Partner Administrator, Super Administrator, or an Administrator.
{% endhint %}

**To edit the details of an Onyx Edge's in a 4G network:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
For the Onyx Edge that you want to edit, in the **Onyx Edge (n)** panel > **Actions** column, click the corresponding ⋮ (options) icon, then click **Edit**.

The **Edit Onyx Edge** page displays the equipment's details.
{% endstep %}

{% step %}
Edit the Onyx Edge's details as required.

For parameter descriptions, see the respective sections:

* [*Add Onyx Edge to 4G Network in NAT Mode*](#add-onyx-edge-to-4g-network-in-nat-mode)
* [*Add Onyx Edge to 4G Network in VLAN Mode*](#add-onyx-edge-to-4g-network-in-vlan-mode)
  {% endstep %}

{% step %}
To save your edits, in the upper-right corner of the page, click **Save Onyx Edge**.
{% endstep %}
{% endstepper %}

### Configure Onyx Edge agw\_user Account

The Onyx Edge *agw\_user* account allows GXC partners and customers to log on to their Onyx Edge AGW to gather basic debug information, restart Onyx Edge services, and reset their Onyx Edge back to factory settings.

SSH- and password-based access are both supported for the *agw\_user*.

For password-based access, the Onyx Edge is provisioned with a factory-default password, which partners and customers can change in the Onyx Portal. Note that password access is restricted to the console and can be used only if the networking is hosed, or if the user has physical access to the ONYX-ES.

For SSH access, in the Onyx Portal, partners and customers can add authentication keys for other devices on the same network.

For more information, see *Onyx Edge On-Premises Installation and Operations Guide*.

To configure the Onyx Edge *agw\_user* account on an operational Onyx Edge:

{% hint style="info" %}
**NOTE:** You can configure the Onyx Edge *agw\_user* account only if you are a GXC Administrator, Partner Administrator, Super Administrator, or an Administrator.
{% endhint %}

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
For the Onyx Edge on which you want to configure the *agw\_user* account, in the **Onyx Edge (n)** panel > **Actions** column, click the corresponding ⋮ (options) icon, then click **Edit**.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FsFgKbSGMm7g6K8el9qln%2Fimage.png?alt=media&amp;token=763be2cb-3cc5-4079-a006-02b61d74e6ed" alt="" width="110"><figcaption></figcaption></figure>

The **Edit Onyx Edge (*****\<onyx edge name>*****)** page is displayed.
{% endstep %}

{% step %}
Click the **Others** tab and move to the **AGW User Configuration** section.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FbU0bZ3JFEVBT6lprgeLR%2Fimage.png?alt=media&amp;token=64363f6b-55bb-4489-ad34-2b59f1d673d6" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To add an SSH key:

1. Click **Add Keys**.

   The **Add SSH Key** dialog box is displayed.

   <figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FVnrBlogSF42DPqpWiQXu%2Fimage.png?alt=media&amp;token=a0de6739-ed41-457d-886d-f3df0fd6b0f3" alt=""><figcaption></figcaption></figure>
2. Enter the SSH key, then click **Save**.

   The SSH key is added.

   You can add a maximum of 10 SSH keys.
3. To view existing SSH keys, click **View All Keys**.

   The list of SSH keys is displayed.

   You can view details, edit, and delete SSH keys here.
4. To change the password for *agw\_user*, click **Change Password**.

   The **Change Password** dialog box is displayed.

   1. **Password** – (Required) Password for *agw\_user*.
   2. **Confirm Password** – (Required) Reenter the password to confirm.

   The password must be at least eight characters in length.

   <figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2Fwq1KKadOyA6zKlbixK1K%2Fimage.png?alt=media&amp;token=b968ccf6-ee32-48e1-91ee-a8ea54ddbc78" alt=""><figcaption></figcaption></figure>

{% endstep %}
{% endstepper %}

### Delete Onyx Edge

{% hint style="info" %}
**NOTE:** You can delete an Onyx Edge only if you are a GXC Administrator, Partner Administrator, Super Administrator, or an Administrator.
{% endhint %}

{% hint style="info" %}
**NOTE:** You cannot delete an Onyx Edge if there are any APs associated with it. If there are APs associated with the Onyx Edge that you want to delete, you must first remove the APs.
{% endhint %}

**To delete an Onyx Edge:**

{% stepper %}
{% step %}
In the navigation pane, click **Equipment**.

The **Equipment** page > **Onyx Edge** tab displays the summary details of all Onyx Edge configured in the network.
{% endstep %}

{% step %}
For the Onyx Edge that you want to delete, in the **Onyx Edge (n)** panel > **Actions** column, click the corresponding ⋮ (options) icon, then click **Delete**.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FakL7iZjCXCMLGyQxy471%2Fimage.png?alt=media&amp;token=c9b8d1d8-e4c9-4575-bba8-0e093be5c823" alt="" width="110"><figcaption></figcaption></figure>

A confirmation dialog box is displayed.

<figure><img src="https://4071075005-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZc9hpHmiTCrh1sn4mWXn%2Fuploads%2FWgrjhWrXoKCvPt14N6S1%2Fimage.png?alt=media&amp;token=c2a6ebc4-84f0-47d0-9c5e-87b19d9fd320" alt="" width="419"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
To confirm, click **Yes**.
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.gxc.io/docs/network-configuration-and-operations-guides/4g-onyx-portal-4.x-operations/manage-equipment/manage-onyx-edge.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
