External Networking Connectivity for CEE Tenants in HP and Dell Multi-Server Deployment
Cloud Execution Environment

Contents

1Introduction

2

CEE Based on Extreme Switch
2.1Prerequisites
2.1.1Required Hardware and Software
2.1.2Documents
2.1.3Conditions
2.2L2 Connection to BGW
2.3L3 Connection to BGW Using Neutron Router

1   Introduction

This document describes how to configure external tenant Border Gateway (BGW) and Firewall (FW) connections to the Cloud Execution Environment (CEE) region. This guideline provides a high-level overview, as the BGW or FW is not part of the CEE region, so the actual BGW present at the actual deployment is not known.

Note:  
For more information about the CEE region configuration, refer to the Configuration File Guide.

2   CEE Based on Extreme Switch

This section provides Layer 2 (L2) and Layer 3 (L3) guidelines for the case where Neutron is configured to use an ML2 mechanism driver and an L3 service plug-in for Extreme switches.

2.1   Prerequisites

This section describes the prerequisites that must be fulfilled before external connectivity can be achieved.

2.1.1   Required Hardware and Software

The following hardware and software is required for the BGW:

2.1.2   Documents

Before starting the configuration procedure, ensure that the following information and documents are available:

2.1.3   Conditions

The following conditions must apply before the configuration is performed:

2.2   L2 Connection to BGW

This section describes how to connect CEE to the BGW using an L2 network. For more information on Neutron, refer to the sections "Networking API v2.0" and "Networking API v2.0 extensions" in the OpenStack API Complete Reference.

Figure 0   L2 Connection to BGW

Figure 1   L2 Connection to BGW

Do the following:

  1. Configure the BGW to be able to handle incoming and outgoing traffic. For more information, refer to the DC Firewall Hardening Guide.
  2. Create VRs in the BGWs as shown in fig-L2Multieps Figure 1.
    Note:  
    There can be one or several VLANs connected to the VR, and one or several VRs can be connected to the applicable port towards CEE. There can also be one or several VLANs connected to the FW.

    More than one CEE region can be connected to one BGW pair.

  3. Configure the VR with its applicable parameters. Both IPv4 and IPv6 can be used.
  4. After a VR is created, create applicable VLANs. It is recommended to choose VLAN names that reflect what they are used for. VLAN ports connected to CEE must be in the reserved range, specified in Section 2.1.3.
  5. To achieve redundancy on the VRs, configure VRRP v.3 on the VLANs interfacing CEE.
    Note:  
    Use the same VLAN ID in BGW-1 and BGW-2.

  6. Add VLANs to applicable ports connected to CEE.
  7. Add VLANs on the ports connected to the FWs and VRs.

2.3   L3 Connection to BGW Using Neutron Router

This section describes how to connect VMs via Neutron router to BGW on L3. For more information on Neutron, refer to the sections "Networking API v2.0" and "Networking API v2.0 extensions" in the OpenStack API Complete Reference. fig-L3eps Figure 2 shows the connection, without showing the VMs.

Figure 1   L3 Connection to BGW Using Neutron Router

Figure 2   L3 Connection to BGW Using Neutron Router

Do the following:

  1. Create VRs in the BGWs as shown in fig-L3eps Figure 2.
  2. Configure the VR with its applicable parameters. Only IPv4 is applicable.
  3. After a VR is created, create applicable VLANs in the VR.
  4. Create two VLANs to achieve redundancy, one for BGW-1 and one for BGW-2. The connections to the BGWs must be Layer 3 point-to-point links, that is, a /30 subnet. It is recommended to choose VLAN names that reflect what they are used for. The VLAN IDs used for the connectivity to CEE must be in the reserved range, specified in Section 2.1.3.
  5. Add the applicable ports to the VR.
  6. Add VLANs to applicable ports connected to CEE.
  7. Add VLANs on the ports connected to FWs and VRs.


Copyright

© Ericsson AB 2016. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    External Networking Connectivity for CEE Tenants in HP and Dell Multi-Server Deployment         Cloud Execution Environment