Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

1. Objectives

In SDN solutions, some networking services are provided by the SDN itself, for example

  • Source NAT
  • Static NAT
  • Load Balancer
  • Port forwarding
  • Network ACL (VPC)
  • Firewall rules (Isolated network)

...

  • Dhcp (supported by some SDN providers)
  • Dns (supported by some SDN providers)
  • UserData (it is unsupported Not supported by SDN providers)
  • Vpn (S2S and user)

In this case, the CloudStack VR is used for to provide Dhcp/, Dns /and Userdata services to the vm instances. It is not in the path of the traffic, it acts VM instances, while remaining out of the data path, acting as a helper vmVM

The goal of this feature is to support VPNs in Cloudstack VRto support VPN access from the Cloudstack VR when its out of the data path, thus supporting:

  • Remote access VPN for SDN networks 
  • Site-to-Site VPN for SDN networks

Please note, this supports VPC only. Isolated networks is not supported

2. High Level Design

As the first stepa pre-requisite, the CloudStack VR needs to be provided with a public IP (via static natStatic NAT).

For Remote access vpn, the diagram is as below

...

For Site-to-Site VPN, the diagram is as below

In both cases, as the last step, static routes need to be create injected by cloudstack and configured in SDNCloudStack in the SND fabric.



3. Implementation

This described some details of the implementation

3.1 database change

...

  • A new column

...

  • has been added to the table user_ip_address for public ip address, which

...

  • indicates if the ip is

...

  • used for 1:1 NAT to the VPC VR.


  `for_router` tinyint(1) DEFAULT '0' COMMENT 'True if the ip address is used by Domain Router to expose services',tinyint(1) DEFAULT '0' COMMENT 'True if the ip address is used by Domain Router to expose services',


  • A new column has been added to the table static_routes , which saves the next hop of static routes.


`next_hop`varchar(50) COMMENT "next hop of the static route" AFTER `vpc_gateway_id`


3.2 ipsec configuration for Remote access VPN

...

To create a VPC, please refer to https://docs.cloudstack.apache.org/en/4.19.1.0/adminguide/networking_and_traffic.html#configuring-a-virtual-private-cloud

4.1 Remote Access VPN


Remote In SDN networks, remote access VPN is not supported by on the Source NAT for SDN networksIP. 


(1) acquire a Public IP

Please use an IP address which is not in the subnet of Source NAT of VPC VR (not Netris)VPN fabric.


(2) Enable Remote Access VPN

...

Please refer to https://docs.cloudstack.apache.org/en/4.19.1.0/adminguide/networking/using_remote_access.html#microsoft-windows-8


Remember Reminder, For for Windows clients,

...

If remote access VPN is enabled, it gets the  the same IP

Image Removed

Otherwise, public IP is used, otherwise CloudStack automatically assign assigns a Public IP.

Image Added



(2) Create customer gateway

...

(3) Create VPN connection


5. Test plan

Before testing

  • Create VPC offering
  • Create Network offering
  • Add Vpn Users

5.1 Create VPC, VPC tier and VM

...

Test VPC tier deletion (first tier)


  1. Expunge VM-1

  • Should succeed

  1. Remove VPC tier-1

  • Should succeed

  • Backend

    • Disable static NAT to guest NIC/IP of tier-1

    • Enable static NAT to guest NIC/IP of tier-2Delete Static routes for multiple CIDRs (next hop: guest IP of VR to guest NIC/IP of tier-1)2

    • Add Update Static routes for multiple CIDRs (next hop: guest IP of VR of tier-2)

  1. Check VPC VR

  • VPC VR:

    • use guest NIC of tier-2 as default route

    • l2tp.conf uses the guest IP of tier-2

    • vpn-xxxxxx uses the guest IP of tier-2

  1. Test Remote access VPN client to tier-2 and tier-3

  • Should work

    • from VPN client to tier-2 and tier-3

    • from tier-2 and tier-3 to VPN client

  1. Test Site-to-Site VPN to tier-2 and tier-3

  • Should work

    • from remote to tier-2 and tier-3

    • from tier-2 and tier-3 to remote

...

Test VPC tier deletion (from last tier)


  1. Expunge VM-3

  • Should succeed

  1. Remove VPC tier-3

  • Should succeed

  • Backend

    • No changes for static NAT.

    • Update Static routes for multiple CIDRs (next hop: guest IP of VR of tier-2)

  1. Expunge VM-2

  • Should succeed

  1. Remove VPC tier-2

  • Should succeed

  • Backend

    • Disable static NAT to guest NIC/IP of tier-2

    • Delete Static routes for multiple CIDRs (next hop: guest IP of VR of tier-2)

  1. Remove VPC

  • Should

fail
  • work

    • Disable Remote access VPN

  • Should work

  1. Remove VPC

Should fail
    • Remove VPN connection

Should work
    • Remove VPC

  • Should fail

Remove VPC
    • gateway

  • Should work

  1. Remove VPC

Should work