External Networking Connectivity for CEE Tenants in Single Server Deployment
Cloud Execution Environment

Contents

1Introduction

2

CEE on Single Server
2.1Prerequisites
2.1.1Required Hardware and Software
2.1.2Documents
2.1.3Conditions
2.2L2 Connection to BGW

1   Introduction

This document describes how to configure external tenant Border Gateway (BGW) and Firewall (FW) connections to the Cloud Execution Environment (CEE) region. This guideline provides a high-level overview, as the BGW or FW is not part of the CEE region, so the actual BGW present at the actual deployment is not known.

Note:  
For more information about the CEE region configuration, refer to the Configuration File Guide.

2   CEE on Single Server

The subsections of this section provide Layer 2 (L2) guidelines for the case where Neutron is configured to use the ericsson_user_spec deployment type.

2.1   Prerequisites

This section describes the prerequisites that must be fulfilled before external connectivity can be achieved.

2.1.1   Required Hardware and Software

For information on the BGW hardware and software, refer to the documentation of the BGW solution.

2.1.2   Documents

Before starting the configuration procedure, ensure that the following information and documents are available:

2.1.3   Conditions

The following conditions must apply before the configuration is performed:

2.2   L2 Connection to BGW

This section describes how to connect CEE to the BGW using an L2 network. For more information on Neutron, refer to the sections "Networking API v2.0" and "Networking API v2.0 extensions" in the OpenStack API Complete Reference.

Figure 0   L2 Connection to BGW

Figure 1   L2 Connection to BGW

Do the following:

  1. Configure the BGW to be able to handle incoming and outgoing traffic. For more information, refer to the DC Firewall Hardening Guide.
  2. Create VRs in the BGW as shown in fig-L2Singleeps Figure 1.
    Note:  
    There can be one or several VLANs connected to the VR, and one or several VRs can be connected to the applicable port towards CEE. There can also be one or several VLANs connected to the FW.

  3. Configure the VR with its applicable parameters. Both IPv4 and IPv6 can be used.
  4. After a VR is created, create applicable VLANs. It is recommended to choose VLAN names that reflect what they are used for. VLAN ports connected to CEE must be in the reserved range, specified in Section 2.1.3.
  5. To achieve redundancy on the VRs, configure VRRP v.3 on the VLANs interfacing CEE.
  6. Add VLANs to applicable ports connected to CEE.
  7. Add VLANs on the ports connected to the FWs and VRs.


Copyright

© Ericsson AB 2016. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    External Networking Connectivity for CEE Tenants in Single Server Deployment         Cloud Execution Environment