CloudStack Networking
Paul Angus Cloud Architect ShapeBlue paul.angus@shapeblue.com @CloudyAngus @ShapeBlue
CloudStack Networking Paul Angus Cloud Architect ShapeBlue - - PowerPoint PPT Presentation
CloudStack Networking Paul Angus Cloud Architect ShapeBlue paul.angus@shapeblue.com @CloudyAngus @ShapeBlue About Me Cloud Architect with ShapeBlue Worked with CloudStack since 2.2.13 Specialising in deployment of CloudStack and
Paul Angus Cloud Architect ShapeBlue paul.angus@shapeblue.com @CloudyAngus @ShapeBlue
@ShapeBlue #CloudStack #CCCNA14
Cloud Architect with ShapeBlue Worked with CloudStack since 2.2.13 Specialising in deployment of CloudStack
Orange, TomTom, PaddyPower, Ascenty,
I view CloudStack from a ‘What can cloud
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
NaaS
@ShapeBlue #CloudStack #CCCNA14
Logical Networking Models
Basic Advanced
@ShapeBlue #CloudStack #CCCNA14
AWS Style L3 isolation – Massive Scale Simple Flat Network Each POD has a unique CIDR Optional Guest Isolation via Security Groups Optional NetScaler Integration ‐ Elastic IPs and Elastic LB Optional Nicira NVP Integration
@ShapeBlue #CloudStack #CCCNA14
Isolate traffic between VMs Available for both Basic and Advanced Networking XenServer must use Linux Bridge and not Open vSwitch
xe‐switch‐network‐backend bridge Edit sysctl to enable net.bridge.bridge‐nf‐call‐iptables and
Must be implemented before adding to CloudStack
@ShapeBlue #CloudStack #CCCNA14
Rules can be mapped to CIDR or another Account/Security Group
@ShapeBlue #CloudStack #CCCNA14
This network model provides the most flexibility in defining
Guest isolation is provided through layer‐2 means such as VLANs
@ShapeBlue #CloudStack #CCCNA14
Private and Shared Guest Networks Multiple Physical Networks Virtual Router for each Network providing:
DNS & DHCP Firewall Client VPN Load Balancing Source / Static NAT Port Forwarding
@ShapeBlue #CloudStack #CCCNA14
Effectively enables the deployment of multiple ‘Basic’ style
@ShapeBlue #CloudStack #CCCNA14
Traffic between CloudStack Management Servers and the various cloud components (Hosts, System VMs, Storage*, vCenter etc)
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
CPVM, SSVM & VRs have a connection to the Public Network *VRs only have public connection in Advanced Network
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
A Hardware or Virtual Appliance that provide Network Services
Virtual Router VPC Virtual Router Internal LBVM Citrix NetScaler F5 Load Balancer Juniper SRX Firewall Nicira Nvp Midokura Midonet BigSwitch Vns Cisco VNMC Baremetal DHCP* Baremetal PXE* Palo Alto* Ovs (GRE/VXLAN)
*new in 4.3
@ShapeBlue #CloudStack #CCCNA14
Private multi‐tiered Virtual Networks ACLs to control traffic isolation Inter VLAN Routing Site‐2‐Site VPN Private Gateway VPC‐2‐VPC VPN* User VPN*
*new in 4.3
@ShapeBlue #CloudStack #CCCNA14
Virtual Router – Connects all the VPC Components Network Tiers – Isolated Networks, each with unique VLAN and CIDR
@ShapeBlue #CloudStack #CCCNA14
Public Gateway
@ShapeBlue #CloudStack #CCCNA14
Site‐2‐Site VPN Linked to Public Gateway
@ShapeBlue #CloudStack #CCCNA14
User VPN Linked to Public Gateway
@ShapeBlue #CloudStack #CCCNA14
VPC‐2‐VPC VPN Linked to Public Gateway
@ShapeBlue #CloudStack #CCCNA14
Private Gateway Created by Root Admins Configured by Users (Static Routes)
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14
@ShapeBlue #CloudStack #CCCNA14