XaaS Connection Overview
As of July 2025, the service name has been changed from SaaS Connection to XaaS Connection.
XaaS Connection provides private connectivity from the OCX closed network to designated XaaS※1 services, together with optional NAT functionality (SNAT) and IPsec tunnels as needed.
XaaS Connection is mainly used for the following purposes:
- To establish private connectivity to designated XaaS services without the need for customers to prepare their own NAT router.
- For the currently supported XaaS services, please refer to the list below.
| Category | Service Name | SLA Applicable |
|---|---|---|
| SaaS | Cybozu | Applicable |
| SaaS | Microsoft Azure Peering Service | Applicable |
| SaaS | Now Platform | Applicable |
| Security Service / SASE | Zscaler | Applicable |
| Security Service / SASE | Cisco Umbrella | Not Applicable |
| Security Service / SASE | Cato SASE Cloud Platform | Not Applicable |
| IaaS | Wasabi Hot Cloud Storage | Not Applicable |
Notes
- As of July 2025, XaaS Connection supports IPv4 only. IPv6 is not supported.
- BGP settings for XaaS Connection support eBGP only. iBGP is not supported.
Procedure for Creating an XaaS Connection
The required input information differs depending on the XaaS to be connected.
Please refer to the relevant creation procedure pages below.
SaaS
- Create XaaS Connection (Cybozu)
- Create XaaS Connection (Microsoft Azure Peering Service)
- Create XaaS Connection (Now Platform)
Security Service / SASE
- Create XaaS Connection (Zscaler)
- Create XaaS Connection (Cisco Umbrella)
- [Create XaaS Connection (Cato SASE Cloud Platform)]
IaaS
XaaS Connection Configuration Items
With XaaS Connection, you create the following XaaS Connection resources and attach them to a VC (Virtual Circuit) to realize private connectivity to XaaS services using NAT functionality.
When created by specifying a SaaS, private connectivity becomes available to all SaaS services provided by the same SaaS provider within the same AS.
When created by specifying a Security Service / SASE, private connectivity to the designated security service / SASE is enabled.
In addition, it is possible to add NAT IP addresses used for address translation by the NAT function.

| No. | Configuration Item | Description |
|---|---|---|
| 1 | XaaS Connection (Resource) | Creates an XaaS Connection resource on the OCX network. At creation, one NAT IP address used for NAT translation is provided. |
| 2 | NAT IP Address※2 | Additional IPv4 addresses used for NAT translation can be added to the created XaaS Connection resource. |
| 3 | BGP Parameter | Allows configuration of BGP settings for the created XaaS Connection. |
| 4 | IPsec Parameter※3 | Allows configuration of IPsec settings for the created XaaS Connection. |
※1: XaaS (X as a Service) is a general term for various external cloud services, such as software and platforms.
※2: NAT IP addresses are available only for certain XaaS services.
※3: IPsec parameters are available only for certain XaaS services.
For detailed operation methods, please refer to the creation, update, and deletion pages for each item.