vCloud – ORG vDC Network Management

Network Appliances – Edge Gateway vs. Cisco ASAv

GreenCloud IaaS environments are deployed with either an Edge Gateway router or a Cisco ASAv firewall. An Edge Gateway is a virtual router embedded in vCloud, whereas a Cisco ASAv is a different virtual router which is created outside of vCloud and imported. Both types of virtual routers manage external-facing connections, as well as internally-defined subnets and networks. The practical differences as they pertain to Org VDC networks are as follows:

  • Edge Gateways use the vCloud interface to directly change network interfaces and NAT/Firewall rules
    • Cisco ASAv’s use direct SSH login or ASDM management to change those components
  • Edge Gateways use Routed networks to directly interface with external networks
    • Cisco ASAv’s use Isolated networks to connect to VLAN-backed external networks

For further information, see the Edge Gateway and Cisco ASAv index articles.

 

View Org VDC Networks

To view the Org VDC networks on a VDC, log in to vCloud, select the Administration tab, double-click on a vDC, and select the Org VDC Networks tab.

 

Types of Org VDC Networks

There are three types of Org VDC networks in vCloud:

  • Isolated networks are for private IP subnets.
    • These networks can be used to allow vApps to communicate with one another, and can be used to create IP pools on which VMs can be addressed.
    • These can be used to allow internal communication to the external internet through a Cisco ASAv. For more information on Cisco ASAvs, please see the Cisco ASAv Reference Guide.
  • Routed networks are connected directly to an Edge Gateway.
    • They can be used to allow internal communication to the external internet.
    • These should be used in place of isolated networks when an Edge Gateway is present in the vDC. For more information on Edge Gateways, please see the Edge Gateway Reference Guide.
  • External network direct connections are only used to connect a private VLAN to a customer environment.
    • Please do not connect directly to an external network without instruction to do so. It will not work.
    • More information on Org VDC external network connections can be retrieved by contacting GreenCloud Support.

 


Click Here for vCloud 8.20 (Flash/Legacy Interface)…

Org VDC Network Creation

To create a new Org VDC Network, select the green plus symbol from the Org VDC Networks tab. In the dialog, select the type of network to be created.

If an Edge Gateway is present, create a routed network and select the existing Edge Gateway as shown above, then select Next. Otherwise a new isolated network can be created.

At the next page, enter the relevant network information. To allocate IPs to the Static IP Pool, enter a range in the box and select “Add”. The example below includes a subnet on 192.168.5.0/24, and allocates 192.168.5.100-192.168.5.199.

Select “Next” when the IP configuration is correct. At the following screen, enter the name of the new Org VDC network and select “Finish”. Verify that all information is correct.

At this point the Org VDC network is complete. If you reach the network quota for a vDC you will not be able to create any more networks, but there will be no error until this point in the process. The network quota can be increased by contacting GreenCloud support.

Connecting a VM to an Org VDC Network

In order to reach the internet, each VM must be connected to an Org VDC network with internet access. This will be either a Routed network with access to an Edge Gateway, or an Isolated network with access to an ASAv. Right-click on a VM and select Properties, then go to the Hardware tab. Scroll down to the NICs section. See VM Management for more details.

Select the Network dropdown and click on “Add Network…” to open the dialog.

 

Select “Organization VDC network” at the next screen as shown:

Select the appropriate Org VDC network, and select Finish.

The VM will now have connectivity to that Org VDC network, and will have the ability to use IPs from that network. If the Org VDC network is routed to an Edge Gateway or connected to a Cisco ASAv, the VM should be able to communicate with the internet. Please note that the proper NAT and Firewall rules will need to be configured in order to allow communication.


 

Network Creation

To create a new Network, click the blue “Add” in the Networks view as shown above. In the dialog, select the type of network to be created.

If an Edge Gateway is present, create a routed network , otherwise a new isolated network can be created.

At the next page, enter the network’s display name and Gateway address in CIDR format. In this example we use 192.168.50.1 as our Gateway.

If you are creating a Routed network, you will see an Edge Connection screen next. Select the relevant Edge Gateway and which type of Interface you wish to use, then select Next.

There are two types of Interfaces through which a Routed Network can connect to an Edge Gateway: Internal or Distributed.

  • Use ‘internal interface’ when you want to connect to one of the edge gateway’s internal interfaces
  • Use ‘distributed’ when you want fast and efficient East-West routing. The network will be connected to an internal interface of a distributed router that is exclusively associated with this gateway

At the next screen, allocate internal IP pools for the subnet. Enter a range in the box and select “Add”. The example below includes a subnet on 192.168.50.0/24, with a Gateway on 192.168.50.1 as defined above, and allocates 192.168.50.2-192.168.5.100.

Select “Next” when the IP configuration is correct. You have the option of defining DNS servers at the penultimate screen but this step is not mandatory. At the final screen, verify that all information is correct, then click “Finish”.

At this point the Network is complete. If you reach the network quota for a vDC you will not be able to create any more networks, but there will be no error until this point in the process. The network quota can be increased by contacting GreenCloud support.

Connecting a VM to a Network

In order to reach the internet, each VM must be connected to an Org VDC network with internet access. This will be either a Routed network with access to an Edge Gateway, or an Isolated network with access to an ASAv. To connect a VM to a Network, first go to that VM’s vApp container. Select “Actions” to find the “Add Network” option.

Select the “Org VDC Network” option, then select the relevant network that VM should land on.

Once this Network has been added to the vApp, go to the “Virtual Machines” section from the left-hand navigation bar. Select “Details” for the relevant VM, then go to the NICs subsection of the Hardware section.

Under “Network”, select the Network that you added to the vApp, then make sure the IP mode is correct for that Network. In this example, we are allowing the Network to automatically assign a Static IP to the VM from an IP pool.

The VM will now have connectivity to that Org VDC network, and will have the ability to use IPs from that network. If the Org VDC network is routed to an Edge Gateway or connected to a Cisco ASAv, the VM should be able to communicate with the internet. Please note that the proper NAT and Firewall rules will need to be configured in order to allow communication.

Was this article helpful?

Related Articles

string(11) "live search"