Cisco Virtual Network Management Center (VNMC) provides centralized multidevice and policy management for Cisco network virtual services.
When combined with the Cisco Nexus 1000V Switch, ASA 1000V Cloud Firewall, or the Cisco Virtual Security Gateway (VSG), it enables:
Currently the 1000v series and the VSG are supported on VMWare hypervisors.
This would be the deployment model with CloudStack: 
The VNMC controller is a VMWare appliance that presents an XML API to control the Cisco virtual appliance porfolio.
The GUI is a Flash-based web application that utilizes the XML API to interact with the controller. By enabling the flash debugger (see http://s.apache.org/v5) we can capture the precise XML commands required by CloudStack.
The resource translates abstract network configuration commands such as SetStaticNatRule into concrete XML api calls to the VNMC controller
The service is a pluggable service that allows the cloud operator to provision the VNMC controller URL and credentials into CloudStack
The manager implements the CiscoVnmcElementService. It also pre-creates and manages a pool of ASA1000v appliances. The pool is created with an initial capacity and is expanded as demand grows. As networks are de-provisioned, the appliances are returned to the pool.
The network element participates in L2 orchestration by extending NetworkElement. When a network is created, the element needs to
The Cisco ASA1000v can function as a DHCP server, however it cannot guarantee a specific ip<->mac address mapping. Therefore the CloudStack systemvm will be used for this purpose.
The CiscoVnmcElement also implement the IpDeployer and various service provider interfaces to satisfy the requirements of the network offering.
VXLAN isolation needs to be added as an isolation method, with a specific Guru managing allocation of the VXLAN network identifier (VNI)
h7. VSG interaction
The VSG can be used to provide security group isolation.