Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The VSG can be used to provide security group isolation.

ASA deployment model

Prereqs for ASA

- Nexus 1000v appliance is setup and configured in CS (when adding Vmware cluster)
- VNMC appliance is configured and added to CS (separate lifecycle commands will be provided for this)

ASA setup and configuration

Spin up an ASA instance in standalone mode (do we need to support HA mode?)

Following configuration needs to be provided:

  • ESX host
  • Port profiles for mgmt. and ha n/w interfaces (some port profiles created on n1kv switch, can be same or different)
  • Specify some dummy port profiles for inside/outside n/w interfaces (dummy as these will be replaced with appropriate profiles while implementing guest n/w)
  • Mgmt. IP for ASA (from private IP range of the zone), specify g/w such that VNMC IP is reachable
  • Admin password
  • VNMC IP and other parameters

After the ASA instance is powered on the VNMC needs to be registered from ASA console
    - ASA1000V(config)# vnmc policy-agent
    - ASA1000V(config-vnmc-policy-agent)# registration host vnmc_ip_address
    - ASA1000V(config-vnmc-policy-agent)# shared-secret key where key is the shared secret for authentication of the ASA 1000V connection to the Cisco VNMC

Guest network implement logic

Guest n/w gets implement when 1st guest VM is deployed

a. Guest network implementation

- VirtualRouterElement creates the VR for DHCP, userdata and metadata, password server
- CiscoVNMCElement::implement() does the following:
    - Create tenant/edge_security_profile/logical_edge_firewall in VNMC. There will be helper methods in VnmcResource class for all these operations (currently assuming one VNMC appliance per zone. do we need to support multiple VNMCs per zone, in that case how to choose?)
        - Tenant creation
        - Edge security profile
        - Logical edge firewall

    - Create vservice_node, in_port_profile, out_port_profile for ASA in VSM for the Vmware cluster. This is done through VsmCommand class

            vservice_node (below commands for doing it on CLI)

            vservice node ASA%vlanid% type asa_
            ip address 10.1.1.1
            adjacency l2 vlan %vlanid%
            fail-mode close

            in_port_profile
            port-profile type vethernet ASA-Inside-%vlanid
            vmware port-group
            switchport mode access
            switchport access vlan %vlanid%
            no shutdown
            state enabled
            out_port_profile
            same as in_port_profile but with some vlan for public n/w

    - Reconfigure in/out n/w interfaces for ASA appliance with in_port_profile and out_port_profile respectively (need to check what all need to be stored name, cluster, ip address for getting hold of vCenter reference for this VM so that reconfigure can be done)
    - Associate ASA appliance with logical_edge_firewall (in VNMC). IP address of ASA is required for this. This is again done using VnmcResource

b. For guest VM the following change is required while creating the port profile in VSM

- Create port profile guest VM and associate logical_edge_firewall, edge_security_profile

            guest_port_profile
            port-profile type vethernet Guest-%vlanid%
            vmware port-group
            switchport mode access
            switchport access vlan %vlanid%

            org root/%tenant%
            vservice node ASA%vlanid% profile edge_security_profile_

            no shutdown
            state enabled

TODO:
- Currently ASA is manually setup and configured. Need to see if this can be automatically provisioned?