Guide: Connecting locally hosted services to gaiia
This article is part of a larger guide covering how gaiia reaches services you host on your own network, along with the vendor-specific steps required for each system.
Overview
This article outlines the steps required to grant Calix access to your gaiia environment. It covers Calix SMx, Calix Cloud access, and API configuration. You will need to complete several configuration steps on your side and provide specific information to gaiia.
To enable the Calix integration, you must:
- Configure access to your Calix SMx system.
- Grant Partner access to your Calix Cloud instance.
- Allowlist gaiia public IP addresses
- Create and configure a dedicated API user.
The gaiia public IP addresses to allowlist, and the SSL certificate requirements every locally hosted service must meet, are documented in gaiia Cloud Access and Firewall Rules. Complete those requirements alongside the Calix-specific steps below.
Configuring Calix SMx access
You must prepare your SMx environment so gaiia can securely connect.
A. Create credentials for gaiia
-
Create a dedicated username and password for gaiia.
The account should follow the principle of least privilege and grant only the access required for the integration.
B. Open required ports
- Open ports 18443 and 3443.
- Restrict access to the gaiia public IP addresses listed in gaiia Cloud Access and Firewall Rules.
C. Configure SSL
- Configure the system for SSL.
-
Install a certificate issued by a publicly trusted certificate authority, presenting the full certificate chain.
The full list of accepted certificate authorities, and the steps to build and verify a full certificate chain, are documented in gaiia Cloud Access and Firewall Rules.
To test the SSL connection to SMx, run:
openssl s_client -connect <smx_URL>:18443 -brief
Calix SMx certificate documentation: SMx certificate documentation
D. Provide required information to gaiia
You must provide:
- The external DNS name of the SMx system.
- A list of all ONT, RG, and mesh router models that must be certified.
- Dedicated test devices in gaiia for each model.
- The software version number running on SMx.
Granting federated Calix Cloud instance access
You must grant Partner access to your Calix Cloud instance.
- Follow the Calix documentation to allow Partner access to your cloud instance.
- Approve the Calix resident expert account with the following details:
Name: Jared Naquin
Email: jared@gaiia.com
Phone: +1 581-814-7740 - After the request is processed by Calix, adjust the permissions to give gaiia access rights.
Allowlisting gaiia public IP addresses
You must allowlist the following IP addresses in your firewall.
- 3.210.85.72
- 3.81.237.51
- 3.215.70.188
- 3.228.90.246
- 3.131.170.31
- 3.14.2.120
Access should be restricted to these IP addresses only.
Configuring Calix Cloud API access
You must create and configure a dedicated API user for gaiia.
A. Create a dedicated email account
- Create a new email account on your domain.
- Set it to forward to
integrations+<company-name>@gaiia.com.
Example:
integrations+my-isp@gaiia.com
gaiia will:
- Set the password.
- Configure 2FA.
- Register the gaiia integration in the Calix Developer Portal.
B. Assign the correct role
- Add the newly created account to your Calix Cloud instance.
- Assign the API User role.
Reference: Calix best practice for API User role setup
Related to