Die Dokumentation ist derzeit nur auf Englisch verfügbar.

Adding Meshes and Gates

With your Core running, the next step is connecting infrastructure: a Mesh to relay traffic between locations, and Gates inside each location. Both follow the same two-part flow — create the device in Cansole and receive an enrollment token, then enroll the appliance with that token on its rollout page.

You need the Infrastructure Administrator role for this chapter, and the new appliance must meet the requirements.

Part 1 — Create the device in Cansole

Open the Infrastructure app. In the bottom-right corner sits a round + button — it opens the creation menu with the available device types (Mesh, Gate, HA Core, Location).

Creating a Mesh

Choose Mesh and fill in the panel:

  • Identity — the Mesh Name (e.g. primary-mesh), a unique name for this Mesh.
  • Location — pick the physical location from the dropdown. If none exist yet, a New Location form appears inline (name and address) — create it right there.
  • Network — the Hostname (e.g. mesh-01) and the FQDN, the public name the Mesh will be reachable at.
    • If the FQDN is inside your platform's DNS zone, a Public IP field appears and is required: CanMe creates and manages the DNS record for you, pointing at that IP. You can edit the IP later if it changes.
    • If the FQDN is outside your zone, you manage its DNS record yourself at your provider — no Public IP is needed here.
  • Inventory — an optional Serial Number for your records.

Click Create.

Creating a Gate

Choose Gate — the form is shorter: Name, Hostname, and the location. Gates have no public name; they only connect outward.

Save the enrollment token

Right after creation, a dialog shows the device's Enrollment Token:

This enrollment token is displayed only once and cannot be retrieved later. Use Copy or Download to save it now — you'll paste it into the device's rollout page in a moment.

If you lose the token before enrolling, delete the device in Cansole and create it again to get a new one.

Part 2 — Enroll the appliance

Boot the new appliance and configure its network in the device console, exactly as you did for the Core (login admin, first-boot password network, System Configuration → Network Configuration).

Then open the appliance's rollout page in a browser:

https://<appliance-ip>:8443

Accept the self-signed-certificate warning, choose Gate/Mesh, paste your enrollment token into the Rollout Token field, and click Start Gate/Mesh Rollout.

The progress page follows the enrollment; when it completes, the rollout page shuts itself down shortly afterwards. The new device appears in the Infrastructure app — on the map and in the device cards — and shows as online once it has connected.

Notes for Gates

  • A Gate must be able to reach every local device it should make available — check routes if a device sits in a different subnet than the Gate.
  • Which IP ranges may reach the Gate on each of its network interfaces is enforced automatically and survives reboots.

If enrollment fails

The rollout page shows an error page with a Download Logs button — download the bundle and send it to CanMe support. A common cause is the token: if it was truncated when copying, recreate the device in Cansole and use the fresh token.

Next: High Availability

Eingesetzt in den sichersten Umgebungen.

Bereit, ohne Firewalls voranzukommen?

Buchen Sie eine 30-minütige Demo. Sehen Sie, wie CanMe Ihre Netzwerksicherheit transformiert – ohne Rip-and-Replace.

Demo buchen →

Oder schreiben Sie uns an hello@canme.cloud