All pages
Powered by GitBook
1 of 7

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Create a L2 VPN - Client session (on-premises site)

Overview

After configuring the networks of the NSX Autonomous Edge, by using On-Premises to Cloud Director Replication Appliance create the client side of the L2 VPN session, stretching one or more networks across the cloud site.

Procedure

1

Step 1: Log in to the management interface of the VMware Cloud Director Availability On-premises Appliance.

In a Web browser, go to https://On-Premises-Appliance-IP-address/ui/admin.

Log in as the root user.

2

Step 2: In the left pane, under the System section, click L2 Stretch.

3

Step 3: On the NSX Autonomous edges page, click L2 VPN Sessions > NEW

4

Step 4: If your user session is not currently extended to the cloud site, enter credentials to authenticate to the cloud site.

5

Step 5: Select the cloud site virtual data center and the edge gateway on the VDC and edge Gateway page.

6

Step 6: On the Settings and networks page, configure the L2 VPN and click Next.

  • In the Name text box, enter a name for this client L2 VPN session.

  • From the Server session drop-down menu, select the cloud side L2 VPN server session.

7

Step 7: On the Ready To Complete page, review and click FINISH.

>>> The client L2 VPN session on-premises is created and the L2 stretch across the cloud site is complete.

*** Test Connectivity

Ping to Gateway (on-prem) from HI GIO.

In the Local Address text box, enter the on-premises IP address at the client side of the L2 VPN session. The local IP address must be the same as the uplink port IP address of the NSX Autonomous Edge hosting the client L2 VPN session.

  • In the Remote Address text box, enter the HI GIO public IP address at the server side of the L2 VPN session.

  • Under the Client Network column, to create an L2 stretch across the networks select an on-premises VLAN network.

  • Ping to HI GIO’s VM (same VLAN\difference VLAN) from on-prem.

    Deploy NSX Autonomous Edge (on-premises site)

    Overview

    On-premises sites or the client’s L2 VPN require a specially configured VMware® NSX Edge™ appliance called autonomous edge. Deploy the NSX Autonomous Edge appliance using an OVF file on the ESXi host.

    The autonomous NSX Edge is straightforward to deploy and provides a high-performance VPN. The autonomous NSX Edge is deployed using an OVF file. You can also enable high availability (HA) for VPN redundancy by deploying primary and secondary autonomous Edge L2 VPN clients.

    Please request the HI GIO team to get the OVF file.

    Procedure

    1

    Step 1: Log in to the vCenter Server.

    2

    Step 2: Select Hosts and Clusters. To show the available hosts, expand the clusters.

    3

    Step 3: To deploy the NSX Edge, right-click the host where you want it and select Deploy OVF Template.

    • On the Select an OVF template page, to download and deploy the OVF file, paste the URL, or select a locally downloaded OVF file and click NEXT.

    On the Select a name and folder page, Enter Virtual machine name & select a location for its > click Next.

    • Select the destination compute resource > click Next on the Select a compute resource page.

    • On the Review details page, verify the OVF package template details > click Next.

    • On the Configuration page, select a deployment configuration size (detail as below) > click Next.

    Sizing for NSX Autonomous Edge VM

    • On the Select storage page: select a storage & select virtual disk format = Thin provision > click Next.

    • On the Select networks page, for all destination networks select the management network > click Next.

    • On the Customize template page, enter the following properties > click NEXT.

    + In the Application section, do the following:

    Set the System Root User Password.

    Set the CLI "admin" User Password.

    Select the Is Autonomous Edge checkbox.

    Leave the remaining fields empty.

    + In the Network Properties section, do the following:

    Set the Hostname.

    Set the Management Network IPv4 Address. This is the management IP for the autonomous edge.

    Set the Management Network Netmask. This is the management network prefix length.

    Set the Default IPv4 Gateway. This is the default gateway of the management network.

    + In the DNS section, do the following:

    In the DNS Server list field, enter the DNS server IP addresses separated by spaces.

    In the Domain Search List field, enter the domain name.

    + In the Services Configuration section, do the following:

    Enter the NTP Server List.

    Enter the NTP Servers, separated by spaces.

    Select the Enable SSH checkbox.

    Select the Allow Root SSH logins checkbox.

    + In the External section, do the following:

    Enter the External Port details in the following format: VLAN_ID,Exit Interface,IP,Prefix Length.

    For example: 138,eth2,192.168.138.77,24. Replace the following values:

    VLAN ID: VLAN ID of the uplink VLAN

    Exit Interface: interface ID reserved for uplink traffic

    IP: IP address reserved for the uplink interface

    Prefix Length: prefix length for the uplink network

    In the External Gateway field, enter the default gateway of the uplink network.

    + (Optional) In the HA section, do the following:

    Enter the HA Port details in the following format: VLAN_ID,Exit Interface,IP,Prefix Length.

    For example: 137,eth2,192.168.137.81,24. Replace the following values:

    VLAN ID: VLAN ID of the uplink VLAN

    Exit Interface: interface ID reserved for uplink traffic

    IP: IP address reserved for the uplink interface

    Prefix Length: prefix length for the uplink network

    In the HA Port Default Gateway field, enter the default gateway of the management network

    • Review the NSX Autonomous Edge settings > on the Ready to complete page> and click FINISH.

    After the deployment completes, power on the NSX Autonomous Edge virtual machine.

    Log in NSX autonomous via web browser:

    Medium size is suitable for normal use-case. If you don’t have special requirement, please use it.

    NSX Edge core services do not start unless you enter passwords meeting these requirements:

    At least 12 characters

    At least one uppercase letter

    At least one lowercase letter

    At least one digit

    At least one special character

    At least five different characters

    Register & configure the Networks of the NSX Autonomous Edge On-Premises

    Overview

    Once the NSX Autonomous Edge appliance is deployed in the on-premises site, the On-Premises to Cloud Director Replication Appliance starts managing the NSX Autonomous Edge after you register it on-premises.

    To complete the L2 stretch configuration entirely by using the management interface of the On-Premises to Cloud Director Replication Appliance, after deploying the NSX Autonomous Edge in the on-premises site, you register it by using the On-Premises to Cloud Director Replication Appliance.

    Procedure

    1

    Step 1: Log in to the management interface of the VMware Cloud Director Availability On-premises Appliance.

    In a Web browser, go to https://On-Premises-Appliance-IP-address/ui/admin.

    Log in as the root user.

    2

    Step 2: In the left pane, under the System section click L2 Stretch.

    3

    Step 3: On the NSX Autonomous edges page, click New.

    4

    Step 4: Register a New NSX Autonomous Edge window, register the new NSX Autonomous Edge with the On-Premises to Cloud Director Replication Appliance.

    • Enter a friendly name for the new NSX Autonomous Edge in the Name text box.

    • From the vCenter Server drop-down menu, select the vCenter Server instance hosting the NSX Autonomous Edge virtual machine.

    5

    Step 5: On the NSX Autonomous edges page, select deployed NSX Autonomous Edge instance & Click EDIT NETWORK

    Select the network adapters of the NSX Autonomous Edge > click Apply.

    6

    Step 6: On the NSX Autonomous edges page, select deployed NSX Autonomous Edge instance > Click Configure the uplink port.

    Enter the settings for the external network port > click Apply.

    Under NSX Autonomous Edge VMs, select the virtual machine of the newly deployed NSX Autonomous Edge.

  • In the Management Address text box, enter the URL for the NSX Autonomous Edge management.

  • In the User name and Password text boxes, enter the admin user credentials for the NSX Autonomous Edge management.

  • (Optional) In the Description text box, enter a description for this NSX Autonomous Edge.

    -To register the NSX Autonomous Edge for management, click REGISTER.

    NSX Autonomous Edge will show up once completed.

    Stretching layer 2 networks for HI GIO's DRaaS

    Overview

    During on-premises to the cloud migrations, stretch the on-premises networks across the HI GIO cloud site to allow network connectivity between already migrated and not yet migrated virtual machines in the same network segment.

    Layer 2 VPN (L2 VPN) stretches the L2 networks across the sites.

    Procedure

    1. Prerequisites: deployed VMware Cloud Director Availability On-premises Appliance

    On-premises VMs must connect to VLAN-backed networks configured on Distributed Switches

    (Standard Switch is NOT supported).

    1. Procedure: To complete the L2 stretch, we follow the steps:

    On-premises Site: fulfill VLAN, IP address, port groups, and Public IP.

    HI GIO site: Public IP, networks.

  • Create a L2 VPN - Client session (on-premises site).

  • (Optional) Deploy the secondary NSX Autonomous Edge in HA mode (on-premises site)

  • Guidelines

    Preparing the configure:
    Deploy NSX Autonomous Edge (on-premises site)
    Register & configure the Networks of the NSX Autonomous Edge On-Premises
    Create a L2 VPN - Server session (HI GIO cloud site).
    Preparing the configure
    Deploy NSX Autonomous Edge (on-premises site)
    Register & configure the Networks of the NSX Autonomous Edge On-Premises
    Create a L2 VPN - Client session (on-premises site).
    Create a L2 VPN server session (HI GIO site).

    Create a L2 VPN server session (HI GIO site).

    Overview

    By using the management interface in the HI GIO cloud site, organization administrators create the server side of the L2 VPN session, enabling the L2 stretch of one or more networks across the on-premises site.

    Procedure

    1

    Step 1: Log in to HI GIO Portal

    Select Network > Edge Gateways > VPC name

    2

    Step 2: Under Services, click L2 VPN > NEW to open L2 VPN Tunnel window.

    • On Choose Session Mode, select Server > click Next.

    • Enter a name and pre-shared key > NEXT

    • Enter the IP address for the Local IP, remote IP, Initiation Mode > NEXT

    - Select Networks > NEXT

    These networks were created in the preparation phase.

    • Review and click FINISH.

    Waiting some minutes.

    Once complete, we can see tunnel IDs (use it for manual configure on NSX autonomous edge)

    And copy Peer code (use it for manual configure on NSX autonomous edge)

    Preparing the configure

    Procedure

    1

    Step 1: Please fill in the formation in yellow cells.

    • VLAN & Port groups will be created on vDistributed Switch.

    #

    • Network settings for NSX Autonomous Edge.

    • Public IP address:

    2
    3
    • Tag VLAN:

    • Set security: enable Promiscuous mode and Forged transmits

    4
    • These networks are stretch layer 2 (same subnet as on-prem).

    • Select IP for gateway CIDR (It's must not duplicate IP address)

    5

    192.168.137.80

    2

    Network 1

    Uplink

    192.168.138.77

    –

    must to have access to internet

    3

    Network 2

    Trunk

    –

    –

    4

    Network 3

    – (HA, optional)

    192.168.137.81

    192.168.137.82

    Port Group

    VLAN

    Remark

    1

    Management

    137

    For NSX Autonomous Edge management

    2

    Uplink

    138

    For NSX Autonomous Edge uplink

    3

    Trunk

    140, 141, 142

    Stretch L2 network traffic

    #

    OVF Template Name

    Port Group

    Primary Node

    Second Node (optional)

    Remark

    1

    Network 0

    Management

    On-premises Public IP

    HI GIO's Public IP

    <IP Address>

    <IP Address>

    Step 2: Creating port groups (VLANs)on vCenter (if we don't have)

    Step 3: Configure VLAN & Security for TRUNK port

    Step 4: Creating Network on HI GIO (detail steps can check here)

    NSX Autonomous Interfaces

    192.168.137.79

    (Optional) Deploy the secondary NSX Autonomous Edge in HA mode (on-premises site)

    Overview

    Optionally, use the following steps to deploy a secondary NSX-T Autonomous Edge (Layer 2 VPN client) in HA mode in your on-premises environment:

    #

    OVF Template Name

    Port Group

    Primary Node

    Second Node (optional)

    Remark

    1

    Step 1: Follow the steps in until you reach the Customize template step.

    2

    Step 2: On the Customize template step, do the following instead:

    • In the

    Application
    section, do the following:
    • Set the System Root User Password.

    • Set the CLI "admin" User Password.

    • Select the Is Autonomous Edge checkbox.

    • Leave the remaining fields empty.

    • In the Network Properties section, do the following:

      • Set the Hostname.

      • Set the Management Network IPv4 Address. This is the management IP for the autonomous edge.

      • Set the Management Network Netmask. This is the management network prefix length.

      • Set the Default IPv4 Gateway. This is the default gateway of the management network.

    • In the DNS section, do the following:

      • In the DNS Server list field, enter the DNS server IP addresses separated by spaces.

      • In the Domain Search List field, enter the domain name.

    • In the Services Configuration section, do the following:

      • Enter the NTP Server List.

      • Enter the NTP Servers, separated by spaces.

    • Leave External section empty.

    • In the HA section, do the following:

    -Enter the HA Port details in the following format: VLAN_ID, Exit Interface, IP, Prefix Length.

    For example: 137,eth2,192.168.137.81,24. Replace the following values:

    VLAN ID: VLAN ID of the uplink VLAN

    Exit Interface: interface ID reserved for uplink traffic

    IP: IP address reserved for the uplink interface

    Prefix Length: prefix length for the uplink network

    -In the HA Port Default Gateway field, enter the default gateway of the management network

    -Select the Secondary API Node checkbox.

    -In the Primary Node Management IP field, enter the management IP address of the primary autonomous edge.

    -In the Primary Node Username field, enter the username of the primary autonomous edge (for example, "admin").

    -In the Primary Node Password field, enter the password of the primary autonomous edge.

    -In the Primary Node Management Thumbprint field, enter the API thumbprint of the primary autonomous edge.

    You can get this by connecting using SSH to the primary autonomous edge using admin credentials and running the command: “get certificate api thumbprint”

    3

    Step 3: Complete the remaining OVF template deployment steps to deploy the secondary autonomous edge (on-premises Layer 2 VPN client).

    PowerOn the second NSX autonomous edge

    4

    Step 4: Validate:

    It will take some minutes to sync.

    Log in to both NSX autonomous nodes, check High Availability, L2VPN\

    -Primary node:

    -Secondary node:

    -Port ID, Tunnel ID, exit interfaces are same on both nodes.

    5

    Step 5: Failover test:

    To test the NSX autonomous failover:

    -Ping from on-premises to HI GIO cloud.

    -Shutdown NSX autonomous primary node

    -Result:

    NSX autonomous secondary status will change to ACTIVE, L2 VPN = UP

    The connection drop ~ 5-10 seconds

    After powering on the NSX autonomous primary node, the HA status between the nodes was re-established. The secondary edge remains active, and the primary will become active only in case of additional failure.

    1

    Network 0

    Management

    192.168.137.79

    192.168.137.80

    2

    Network 1

    Uplink

    192.168.138.77

    –

    must to have access to internet

    3

    Network 2

    Trunk

    –

    –

    4

    Network 3

    – (HA, optional)

    192.168.137.81

    192.168.137.82

    Procedure

    Deploy NSX Autonomous Edge (on-premises site)

    NSX Edge core services do not start unless you enter passwords meeting these requirements:

    At least 12 characters

    At least one uppercase letter

    At least one lowercase letter

    Select the Enable SSH checkbox.
  • Select the Allow Root SSH logins checkbox.

  • At least one digit

    At least one special character

    At least five different characters