Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The VSG can be used to provide security group isolation.

Nexus 1000v + VNMC + ASA 1000v deployment model

Prereqs

...

Nexus 1000v appliance is setup and configured in CS (when adding Vmware cluster)
VNMC appliance is configured and added to CS (separate lifecycle commands will be provided for this)
ASA 1000v appliances are setup/configured outside of CS

Deployment limitation

In current CS there is a 1:1 mapping between Vmware cluster and Nexus 1000v. Now one or more ASAs can use this Nexus 1000v.

Isolated guest network will be associated with a single ASA appliance. Now if this network spans multiple clusters then some book-keeping needs to be done as to which Nexus 1000v VSM should be used for ASA's and guest VMs for doing required configuration. To simplify things I am currently making the assumption that there will be a single Vmware cluster in the zone where ASA support is required. This can be changed later on. Moreover the scenario where a guest network spans multiple clusters (with n1kv) is not a supported scenario currently.

Also the network can have guest VMs on the Vmware cluster only as n1kv is not available on other HVs.

ASA setup and configuration

...