Mostrando entradas con la etiqueta vShield. Mostrar todas las entradas
Mostrando entradas con la etiqueta vShield. Mostrar todas las entradas

27 diciembre 2013

Understanding networks in vCloud Director - Part 2/2

Read first "Understanding networks in vCloud Director - Part 1/2"
http://virtualshocks.blogspot.com.es/2013/09/understanding-networks-in-vcloud.html

This part 2/2 is about the "vApp networks" on VMware vCloud Director. This vApp networks connect the virtual machines in a vApp, it´s like configure a router in front a vApp to separate the vm´s from the rest of the vApp or the Cloud enviroment.

What VMware says "vCloud Director coordinates with vCloud Networking and Security Manager to provide automated network security for a vCloud environment. vCloud Networking and Security Edge gateway devices are deployed during the provisioning of routed or private networks. Each vCloud Networking and Security Edge gateway runs a firewall service that allows or blocks inbound traffic to virtual machines that are connected to a public access organization virtual datacenter network.    The vCloud Director web console exposes the ability to create five-tuple firewall rules that are comprised of source address, destination address, source port, destination port, and protocol."


When creating a vApp netork the options are:

-Direct: vApps coonect directly to the organization virtual datacenter network.
-Routed: new network where the router provides NAT and FW functions.
-Isolated: no connections outside de vApp, only inside vApp VM machines can communicate.
-Fenced: Identical virtual machines can exist in different vApps, the virtual router provides isolation and proxy ARP.

Before see some examples, take care with the Network Pool options as defined above:


...Trough the wizard:


..Trough the vApp diagram tab in vCloud Director GUI. This view is one of the best way to review the networking configuration issues clicking on a VM the paths are highlighted:



...Trough the Networks tab you can sleect the network type ant the NAT or FW options:



Let´s check some examples:

CASE1: where 2 Organizations keep comunicated with a External Network: vShield Edge routing and statics routes are necessary

-CASE1: where 2 Organizations keep communicated without NAT but where vShield Edge is necessary.
.



LINK:  vCloud Networking

27 septiembre 2013

VMware vCloud: desplegar vShield App sobre ESXi nested



Antes de entrar en materia, conviene tener claro que es la "nested virtualization": un ESXi en formato nested es un ESXi instalado en una maquina virtual que a su vez esta creada en un ESXi fisico, es decir, "un virtualizador virtualizado":


Partimos de la base de que ya tenemos vShield Manager desplegado y conectado al vCenter.

Vamos al turrón. La forma mas sencilla de desplegar vShield App como parte de la instalación de vCloud Director de VMware, es hacerla en modo gráfico:

-Desde la pestaña vShield del host conectados por el vSphere Client
-Desde la consola de vShield Manager por https (el usuario por defecto es "admin" y la clave "default")

Recordemos que se debe desplegar una vShield App por cada host del entorno, al igual que de vShield Endpoint y de vShield Data Security; pero solo una instancia de vShield Manager por vCenter.

Desde vSphere Client: seleccionamos un host y desde la pestaña vShield marcamos las App a instalar y pulsamos en Install:


Configuramos las ip´s y la red y el Datastore donde queremos que se despliegue la App:
NOTA: tener cuidado con desplegar la App en un host en el que resida vCenter! Podeis hacer un vMotion y luego retomar la instalacio ya que el proceso podria causar cortes de red.

  
Durante le proceso de instalación puede quedarse colgado en este punto, aunque no llega a salir un mensaje de error, podemos ver la consola de la App:



Como vShield App es una maquina virtual desde la consola podemos ver el mensaje de error:


Es aquí donde tenemos el gap para poder hacer funcionar maquinas virtuales que requieran x86-64 CPU instaladas sobre un ESXi virtual (nested): debemos habilitar en las settings del ESXi nested la opción "Expose hardware assisted virtualization to the guest OS" como vemos en la imagen:


Este parámetro se debe cambiar con la mv apagada, reiniciamos el ESXi nested, relanzamos la instalación de la App. Puede que nos encontremos con un mensaje de erro de la instalación y que tengamos que hacer un "uninstall" de la App para limpiar los restos de la instalación fallida y luego lanzar de nuevo el "install"

En otro post veremos como desinstalar agentes de vCloud en los ESXi de forma manual.

Una vez relanzado el install vemos desde la consola como ha terminado la instalación correctamente y nos pide ya directamente el login:


Ya tenemos la App de vShield y de Endpoint desplegada, la App de vShield Data Security debe hacerse por separado. ...voila!



Documentacion, mas de 180 paginas en este pdf ...mucho que leer: 

vShield Administration Guide 5.1 http://www.vmware.com/pdf/vshield_51_admin.pdf :
Indice:
     -vShield Manager 5.1
     -vShield App 5.1
     -vShield Edge 5.1
     -vShield Endpoint 5.1



25 septiembre 2013

Understanding networks in vCloud Director - Part 1/2

To easily use the program, you must have clear concepts of network types that we have in vCloud Director.


We have basically three types:

External Network: a portgroup on a switch (distributed, standard or Nexus). It is the vlan and ip segment (public or private) allocated physically

Organization Network: created automatically when create the Provider VDC, it´s only for organization use and could be one of three types:
1-direct connected to an external network
2-routed connected with a vShield Edge wich have two ip´s: one on the External Network side and one on the Organization Network to share the traffic between the vApp and the External Network
3-no connected to external network

vApp network: this network is created automatically when the vApp is created. The two functions are:
-No connected to Organization Network
-Routed connected to Organization Network


....On next post Part-1/2 will review more concepts like Fencing, Isolating or Routed networks.