Granting Calix Access to gaiia

Nicolas Audet
Nicolas Audet
  • Updated

Guide: Connecting locally hosted services to gaiia

This article is part of a larger guide covering how gaiia reaches services you host on your own network, along with the vendor-specific steps required for each system.

Overview

This article outlines the steps required to grant Calix access to your gaiia environment. It covers Calix SMx, Calix Cloud access, and API configuration. You will need to complete several configuration steps on your side and provide specific information to gaiia.

To enable the Calix integration, you must:

  • Configure access to your Calix SMx system.
  • Grant Partner access to your Calix Cloud instance.
  • Allowlist gaiia public IP addresses
  • Create and configure a dedicated API user.

The gaiia public IP addresses to allowlist, and the SSL certificate requirements every locally hosted service must meet, are documented in gaiia Cloud Access and Firewall Rules. Complete those requirements alongside the Calix-specific steps below.

 

Configuring Calix SMx access

You must prepare your SMx environment so gaiia can securely connect.

A. Create credentials for gaiia

  1. Create a dedicated username and password for gaiia.

    The account should follow the principle of least privilege and grant only the access required for the integration.

B. Open required ports

  1. Open ports 18443 and 3443.
  2. Restrict access to the gaiia public IP addresses listed in gaiia Cloud Access and Firewall Rules.

C. Configure SSL

  1. Configure the system for SSL.
  2. Install a certificate issued by a publicly trusted certificate authority, presenting the full certificate chain.

    The full list of accepted certificate authorities, and the steps to build and verify a full certificate chain, are documented in gaiia Cloud Access and Firewall Rules.

To test the SSL connection to SMx, run:

openssl s_client -connect <smx_URL>:18443 -brief

Calix SMx certificate documentation: SMx certificate documentation

D. Provide required information to gaiia

You must provide:

  • The external DNS name of the SMx system.
  • A list of all ONT, RG, and mesh router models that must be certified.
  • Dedicated test devices in gaiia for each model.
  • The software version number running on SMx.

 

Granting federated Calix Cloud instance access

You must grant Partner access to your Calix Cloud instance.

  1. Follow the Calix documentation to allow Partner access to your cloud instance.
  2. Approve the Calix resident expert account with the following details:
    Name: Jared Naquin
    Email: jared@gaiia.com
    Phone: +1 581-814-7740
  3. After the request is processed by Calix, adjust the permissions to give gaiia access rights.

Allowlisting gaiia public IP addresses

You must allowlist the following IP addresses in your firewall.

  • 3.210.85.72
  • 3.81.237.51
  • 3.215.70.188
  • 3.228.90.246
  • 3.131.170.31
  • 3.14.2.120

Access should be restricted to these IP addresses only.

Configuring Calix Cloud API access

You must create and configure a dedicated API user for gaiia.

A. Create a dedicated email account

  1. Create a new email account on your domain.
  2. Set it to forward to integrations+<company-name>@gaiia.com.

Example:

integrations+my-isp@gaiia.com

gaiia will:

  • Set the password.
  • Configure 2FA.
  • Register the gaiia integration in the Calix Developer Portal.

B. Assign the correct role

  1. Add the newly created account to your Calix Cloud instance.
  2. Assign the API User role.

Reference: Calix best practice for API User role setup

Related to

Was this article helpful?

Have more questions? Submit a request