SlideShare a Scribd company logo
© 2014 VMware Inc. All rights reserved.
VMware vCloud Air:
Networking
Formerly known as vCloud Hybrid Service
2
What’s in It for You?
•  You will leave with:
–  An understanding of the VMware vCloud® Air™ networking building blocks
–  A strong networking foundation for building a complex hybrid cloud
–  An understanding of advanced networking use cases and security
3
Agenda
vCloud Air Networking
•  Services Overview
•  Key Components
•  Network Virtualization Services
•  Connectivity options to vCloud Air
•  IPsec VPN
•  L2 Stretching
•  Direct Connect
•  Advanced Use Cases
•  Three tier Networking
4
Hybrid Service Basic Networking Constructs
NAT
FW
Load Balancer
IPsec
DHCP
Static routing
Routed/Gateway
networks
(up to 9 networks)
Isolated networks
Customer’s virtual data
center on vCloud Air
5
vCloud Air Cloud Options and Gateway Choices
CONFIDENTIAL
§  Shared Cloud
•  Logically separated network,
compute and storage
§  5GHz CPU (burstable to 10GHz)
§  20GB RAM, 2TB storage
§  No virtual data center
segmentation
§  One Edge Gateway
§  Dedicated Cloud
•  Physically separated hosts
•  Logically separated network and
storage
§  30GHz CPU, 120GB RAM, 6TB
§  Segment virtual data centers
based on orgs
§  Multiple Edge Gateways
VDC1 VDC2
VDC3 VDC4
VDC
6
Configuration Access Options
CONFIDENTIAL
vCloud Air Management Web Portal –
for basic networking configurations
7
Configuration Access Options
CONFIDENTIAL
vCloud Air Management Web Portal –
for basic networking configurations
For Advanced
configurations
8
Configuration Access Options
CONFIDENTIAL
vCloud Air Management Portal –
for advanced networking configurations
9
vCloud Air Networking Services
•  IP Addressing
•  Network creation
•  Firewall
•  NAT
•  DHCP
•  Load Balancer
•  VPN
10
IP Address Assignment
•  IP Pool
–  Pool of IPs created by default
on auto generated isolated and
routed networks
–  Virtual machines attached to those
networks get IP addresses from that
default pool
•  Static IP
–  Fixed IP for a virtual machine
–  Change configuration in
VMware® vCloud Director®
•  DHCP
–  Part of Edge Gateway service
–  Change configuration in vCloud
Director
–  Basic DHCP service
Routed Network
11
Firewall Rules in vCloud Air
12
Firewall Rules: North-South and East-West Traffic
Routed Network 1 Routed Network 2 Routed Network 3
Firewall Rules:
-  By default: Deny all
-  Policies for traffic that
passes through the
gateway
Gateway
•  5-tuple firewall policies (Protocol, Source/Dest. IP, Source/Dest. Port )
•  Can have multiple policies across multiple networks
•  Ideal for enterprise grade application deployment
13
Network Address Translation (NAT)
•  Source NAT and Destination NAT rules
–  Supports multiple rules on multiple interfaces
•  Can use internal/private IP space
–  Bring your own internal IP space
–  Create/manage subnets within IP space
–  Multiple IP spaces under the same gateway
•  Need to create firewall rules to
allow traffic
•  IPv4 NAT
NAT rules:
-  SNAT & DNAT rules
-  Options include
protocol/port selection
Gateway
Public IPs
Internal IPs
10.x.x.x 172.16.x.x 192.168.x.x
Organization Net 1 Organization Net 2 Organization Net 3
14
Edge Gateway Services – Load Balancing
Pool Servers
Load Balanced
- Round Robin
- IP Hash
- URI
- Least Connected
Virtual Server –
- Virtual IP (Public IP)
- Frontend traffic
- Assigned to a server pool
Can have multiple virtual servers
and pools
Edge gateway
Load balancer
15
Load Balancer – Pool Servers
•  Pool Servers
–  HTTP/HTTPS/TCP
–  Load Balancing Methods
•  IP Hash
•  Round Robin
•  URI
•  Least Connected
–  Health Check
•  Each with +TCP as mode
•  Monitoring Ports
–  Add Servers
•  Ratio Weight
•  Change Ports/Services per Server
16
Load Balancer – Virtual Servers
•  Virtual Servers
–  Apply on outside network
–  Server Pool
–  Persistence Method
•  HTTP – Cookie
•  HTTPS – Session ID
Connecting to
vCloud Air
18
Options to Connect to vCloud Air
z
Customer Data Center vCloud Air
Private WAN /
Direct Connect /
Cross Connect
IPsec Tunnel
Public
INTERNET
Many Connectivity Choices
to Support
Many Use Cases
19
INTERNET
Connecting to vCloud Air
•  Over the Public Internet
–  With Public IPs
–  Use NAT for address translation
–  By default firewall set to deny all and NAT not configured
INTERNET
•  IPsec VPN
–  vCloud Air features include IPSEC VPN
–  Multiple VPN tunnels can terminate to Edge Gateway
–  Can connect to most of the major on-premises VPN
devices
20
Connecting via VPN
VMware vSphere® (On-Premises)
SharePoint-Routed Network
(10.0.10.0/24)
vCloud Air Edge
Gateway	

§  LEP – 69.194.137.230
§  Peer ID – 10.0.1.150
§  Peer IP – 68.108.102.47
10.0.1.150
10.0.10.1
Customer’s
edge Router	

10.0.1.1
68.108.102.47
SharePoint-Default Routed
Network (192.168.109/24)
192.168.109.1
Virtual
Machine 1
vCloud Air
Virtual
Machine 2
69.194.137.230
vSphere Edge Gateway	

§  LEP – 10.0.1.150
§  Peer ID – 69.194.137.230
§  Peer IP – 69.194.137.230
IP Protocol ID 50 (ESP)
IP Protocol ID 51 (AH)
UDP Port 500 (IKE)
UDP Port 4500
VPN Traffic
21
Stretching L2 to vCloud Air - Logical Architecture
(192.168.50.0/24)
184.61.71.155
74.204.180.41
VPN Traffic
INTERNET
Edge
Gateway
Edge
Gateway
Edge
Gateway
Corp
Firewall
(192.168.50.0/24)
Default Gateway =
192.168.50.10
50.34 50.35
50.34 50.35
50.33
100.33
(192.168.50.0/24)
50.10
100.10
22
vCloud Air Direct Connect
Customer Cage – in CoLo vCloud Air
Cross Connection
Direct Connect
Partner
Device
Customer Data Center vCloud Air
Private WAN connectivity
Direct Connect
Partner
Device
23
Direct Connect – vCloud Air Connectivity
1 or 10 Gbps Direct Connect Traffic
DMZ Network
(192.168.52.0/24)
Private Network
(192.168.50.0/24)
Private Network
(192.168.110.0/24)
Headquarters
Direct Connect Line
Edge
Gateway
INTERNET
24
Direct Connect – Connecting to Existing
Security
1 Gbps Direct Connect Traffic
DMZ Network
(192.168.52.0/24)
Internet
Private Network
(192.168.50.0/24)
Private Network
(192.168.110.0/24)
10.1.1.x/2410.1.1.x/24
On-Premises
Edge
Gateway
IDS
Existing Security Policies and Appliances
IGW
Direct Connect –
Private Line
IPS
25
Direct Connect – Cross Connect
1 or 10 Gbps Direct Connect Traffic
DMZ Network
(192.168.52.0/24)
Private Network
(192.168.50.0/24)
Private Network
(192.168.110.0/24)
CUSTOMER CAGE
Direct Connect Line
Edge
Gateway
Note:
Storage connection must be In-
Guest based connectivity with NFS
or Software iSCSI Initiator
26
User Level Rights and Security
Role Rights Cannot do Ideal for
Account
Administrator
Can add/edit users and
user rights
Virtual data center
resource management,
Network mgmt etc.
Account
management
Virtualization
Infrastructure
Administrator
Create virtual data centers
Add/edit compute and
storage resources
Cannot create users,
manage networking
Virtual infrastructure
admin
App admin
Network
Administrator
Create networks
Add gateways
Add gateway services
User management,
Virtual data center
resource management
Network admin
Read-only
Administrator
Read only rights for all
setups/configurations
Any adds/edits Supervisor
Subscription
Administrator
Access to myVMware.
Purchase resources, file
support tickets
No vCloud Air
management rights
For all personnel
with purchasing
rights and/or support
needs
27
Application Security – Access Rights
•  Administration rights
–  Clearly identify individuals, and
rights that the individuals get
–  An enterprise administrator
can have more than
one type of right
–  Rights help enforce secure
cloud usage
•  User rights
–  End user rights for virtual
machine owners
–  End user cannot do any
admin activity
–  Users have limited visibility to
cloud resources
28
Summary
•  You will leave with:
ü  An understanding of the vCloud Air networking building blocks
ü  A strong networking foundation for building a complex hybrid cloud
ü  An understanding of advanced networking use cases and security
•  Key Takeaways
–  Building blocks you are used to – vSphere, VXLAN, VMware vCloud®
Networking and Security Manager™vCNS, VMware® vCloud Director®
–  Flexible and Powerful
–  Supports all your complex networking
•  IPSEC VPN
•  Stretched Applications
•  Layer 2 Extension - BYOIP
–  Advanced application security
Go To VMware Cloud Academy
•  See a video of this presentation and
others to learn more about vCloud
Air
•  Condensed VMworld jump start
presentations delivered by technical
subject-matter experts
•  Free and ungated to learn at your
own pace
•  All videos under 15 mins!
•  Test your knowledge by taking a
quiz
•  Download vCloud Air eBook and
other assets and tools
29
http://vcloud.vmware.com/cloud-academy
Thank You

More Related Content

PDF
VMware vCloud Air Getting Started: Preparing Workloads for Migration
PDF
VMware vCloud Air Deep Dive into Hybrid Cloud Management
PPTX
vCloud Air - Infrastructure and Application Services for the Enterprise
PDF
VCloud Air Network Guide
PDF
VMware vCloud Air Availability Solutions – Data Protection
PDF
VMware vCloud Air: Security Infrastructure and Process Overview
PPTX
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
PPTX
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World
VMware vCloud Air Getting Started: Preparing Workloads for Migration
VMware vCloud Air Deep Dive into Hybrid Cloud Management
vCloud Air - Infrastructure and Application Services for the Enterprise
VCloud Air Network Guide
VMware vCloud Air Availability Solutions – Data Protection
VMware vCloud Air: Security Infrastructure and Process Overview
Accelerating Public Cloud Migration with Multi-Cloud Load Balancing
Delivering Applications with Full Lifecycle Automation in a Multi-Cloud World

What's hot (20)

PDF
Creating Microservices Application with IBM Cloud Private (ICP) - ICP Archite...
PPTX
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
PDF
VMWare and SoftLayer Hybrid IT
PPTX
What's New VMware NSX Advanced Load Balancer (Avi Networks)
PPTX
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
PPTX
CompTIA Cloud Plus Certification Bootcamp June 2017
PDF
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
PPTX
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
PPTX
Private Cloud with Microsoft Technologies
PPTX
Veeam: Cybersecurity protection solutions through Backup and Availability
PDF
Гибридное облако - эффективность в квадрате
PPTX
VMware 2015: Next Horizon for Cloud Networking and Security
PDF
Openstack - Enterprise cloud management platform
PDF
Kubernetes Basics - ICP Workshop Batch II
PPTX
VMware vCloud Director
PPTX
How to Eliminate Load Balancer Upgrade Disruptions
PDF
Creating Microservices Application with IBM Cloud Private (ICP) - Container a...
PDF
Private IaaS Cloud Provider
PPTX
Advanced Web Application Security with an Intelligent WAF
PPTX
Prevent threats With Analytics Driven Web Application Firewall
Creating Microservices Application with IBM Cloud Private (ICP) - ICP Archite...
Industry's Best Multi Cloud Application Services from Avi Networks, Now part ...
VMWare and SoftLayer Hybrid IT
What's New VMware NSX Advanced Load Balancer (Avi Networks)
Deep Dive on GSLB with VMware NSX Advanced Load Balancer (Avi Networks)
CompTIA Cloud Plus Certification Bootcamp June 2017
Bringing SaaS Simplicity to Proactive Support & Live Threat Updates
How Multi-Cloud Load Balancing Automates Application Delivery and Drives Oper...
Private Cloud with Microsoft Technologies
Veeam: Cybersecurity protection solutions through Backup and Availability
Гибридное облако - эффективность в квадрате
VMware 2015: Next Horizon for Cloud Networking and Security
Openstack - Enterprise cloud management platform
Kubernetes Basics - ICP Workshop Batch II
VMware vCloud Director
How to Eliminate Load Balancer Upgrade Disruptions
Creating Microservices Application with IBM Cloud Private (ICP) - Container a...
Private IaaS Cloud Provider
Advanced Web Application Security with an Intelligent WAF
Prevent threats With Analytics Driven Web Application Firewall
Ad

Viewers also liked (13)

PDF
GAMO VMware vCloud Air
PPSX
VMware vCloud® Air™
PDF
VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive
PDF
VMware Ready vRealize Automation Program
PDF
DRaaS at the museum, vCloud Air
PDF
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
PDF
Presentation v mware v-cloud director
PPTX
RUN: VMworld 2015 Keynote (Fathers, Raghuram, Li)
PDF
VMware vCloud NFV Reference Architecture
PPTX
VMworld 2015: vCloud Air 2015 – Getting Started with Hybrid Cloud
PDF
VMware vCloud Suite
PDF
AMER Webcast: Build Development and Testing Environments on VMware vCloud Air
PDF
VMware vCloud Air: Introduction
GAMO VMware vCloud Air
VMware vCloud® Air™
VMworld 2014: vCloud Hybrid Service Networking Technical Deep Dive
VMware Ready vRealize Automation Program
DRaaS at the museum, vCloud Air
VMworld 2013: Moving Beyond Infrastructure: Meeting Demands on App Lifecycle ...
Presentation v mware v-cloud director
RUN: VMworld 2015 Keynote (Fathers, Raghuram, Li)
VMware vCloud NFV Reference Architecture
VMworld 2015: vCloud Air 2015 – Getting Started with Hybrid Cloud
VMware vCloud Suite
AMER Webcast: Build Development and Testing Environments on VMware vCloud Air
VMware vCloud Air: Introduction
Ad

Similar to VMware vCloud Air: Networking (20)

PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
PDF
VMworld 2014: How to Build a Hybrid Cloud
PPTX
2014-09-15 cloud platform master class
PDF
Private cloud networking_cloudstack_days_austin
PDF
Presentation v mware v-cloud director technical overview
PPTX
Azure privatelink
PDF
VMworld 2013: vCloud Hybrid Service: Enterprise Applications on vCloud Hybrid...
PDF
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
PDF
Citirx Day 2013: Citrix Enterprise Mobility
PPTX
IBM Notes in the Cloud
PDF
Automated Deployment and Management of Edge Clouds
PDF
Presentation citrix cloud platform for infrastructure as a service
PDF
Azure F5 Solutions
PPTX
Securely Publishing Azure Services
PPTX
Hybrid Cloud Tutorial Linkedin 2
PPTX
Azure networking components - CLoud Network
PPTX
Infrastructure Migration from Windows Server 2003 to the Cloud: An Interoute ...
PPTX
Trust No-One Architecture For Services And Data
PDF
Presentation v mware v-cloud director overview
PPTX
Microsoft Server Virtualization and Private Cloud
VMworld 2013: vCloud Hybrid Service Jump Start Part Two of Five: vCloud Hybri...
VMworld 2014: How to Build a Hybrid Cloud
2014-09-15 cloud platform master class
Private cloud networking_cloudstack_days_austin
Presentation v mware v-cloud director technical overview
Azure privatelink
VMworld 2013: vCloud Hybrid Service: Enterprise Applications on vCloud Hybrid...
VMworld 2013: vCloud Hybrid Service Jump Start Part Three of Five: vCloud Hyb...
Citirx Day 2013: Citrix Enterprise Mobility
IBM Notes in the Cloud
Automated Deployment and Management of Edge Clouds
Presentation citrix cloud platform for infrastructure as a service
Azure F5 Solutions
Securely Publishing Azure Services
Hybrid Cloud Tutorial Linkedin 2
Azure networking components - CLoud Network
Infrastructure Migration from Windows Server 2003 to the Cloud: An Interoute ...
Trust No-One Architecture For Services And Data
Presentation v mware v-cloud director overview
Microsoft Server Virtualization and Private Cloud

More from VMware (20)

PPTX
vRealize Network Insight 3.9
PPTX
VMware vRealize Network Insight 3.5 - Whats New
PPTX
VMware vRealize Network Insight 3.4 whats new
PDF
What's New in vRealize Business for Cloud 7.3
PDF
How Secure Is Your Business?
PPTX
vRealize Network Insight 3.3
PDF
VMWare on VMWare - How VMware IT Implemented Micro-Segmentation and Deployed ...
PDF
Case Study: EVO SDDC Powered Private Cloud
PDF
vRealize Operations 6.4: Supercharge your SDDC Intelligent Operations
PDF
Running and Managing Your Network Just Got Easier
PDF
Modern Security for the Modern Data Center
PDF
Infographic: Why Businesses are Adopting Network Virtualization
PDF
Infographic: Supercharge your Networking Career
PDF
Leverage Micro-Segmentation to Build a Zero Trust Network (Forrester)
PDF
Moving Forward with Network Virtualization (VMware NSX)
PDF
4 Ways IT Can Drive Innovation
PDF
Level Up to a Seamless End-User Experience
PDF
New Model for IT: Cloud Service Provider
PDF
Higher Efficiency and IT Empowerment with VMware vSphere with Operations Mana...
PDF
Virtualization Journey
vRealize Network Insight 3.9
VMware vRealize Network Insight 3.5 - Whats New
VMware vRealize Network Insight 3.4 whats new
What's New in vRealize Business for Cloud 7.3
How Secure Is Your Business?
vRealize Network Insight 3.3
VMWare on VMWare - How VMware IT Implemented Micro-Segmentation and Deployed ...
Case Study: EVO SDDC Powered Private Cloud
vRealize Operations 6.4: Supercharge your SDDC Intelligent Operations
Running and Managing Your Network Just Got Easier
Modern Security for the Modern Data Center
Infographic: Why Businesses are Adopting Network Virtualization
Infographic: Supercharge your Networking Career
Leverage Micro-Segmentation to Build a Zero Trust Network (Forrester)
Moving Forward with Network Virtualization (VMware NSX)
4 Ways IT Can Drive Innovation
Level Up to a Seamless End-User Experience
New Model for IT: Cloud Service Provider
Higher Efficiency and IT Empowerment with VMware vSphere with Operations Mana...
Virtualization Journey

Recently uploaded (20)

PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PPTX
L1 - Introduction to python Backend.pptx
PPTX
Odoo POS Development Services by CandidRoot Solutions
PPTX
Introduction to Artificial Intelligence
PDF
top salesforce developer skills in 2025.pdf
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPT
Introduction Database Management System for Course Database
PDF
PTS Company Brochure 2025 (1).pdf.......
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
Digital Strategies for Manufacturing Companies
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PDF
AI in Product Development-omnex systems
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
L1 - Introduction to python Backend.pptx
Odoo POS Development Services by CandidRoot Solutions
Introduction to Artificial Intelligence
top salesforce developer skills in 2025.pdf
ISO 45001 Occupational Health and Safety Management System
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
Which alternative to Crystal Reports is best for small or large businesses.pdf
Introduction Database Management System for Course Database
PTS Company Brochure 2025 (1).pdf.......
Odoo Companies in India – Driving Business Transformation.pdf
Design an Analysis of Algorithms II-SECS-1021-03
How to Choose the Right IT Partner for Your Business in Malaysia
Digital Strategies for Manufacturing Companies
VVF-Customer-Presentation2025-Ver1.9.pptx
AI in Product Development-omnex systems
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises

VMware vCloud Air: Networking

  • 1. © 2014 VMware Inc. All rights reserved. VMware vCloud Air: Networking Formerly known as vCloud Hybrid Service
  • 2. 2 What’s in It for You? •  You will leave with: –  An understanding of the VMware vCloud® Air™ networking building blocks –  A strong networking foundation for building a complex hybrid cloud –  An understanding of advanced networking use cases and security
  • 3. 3 Agenda vCloud Air Networking •  Services Overview •  Key Components •  Network Virtualization Services •  Connectivity options to vCloud Air •  IPsec VPN •  L2 Stretching •  Direct Connect •  Advanced Use Cases •  Three tier Networking
  • 4. 4 Hybrid Service Basic Networking Constructs NAT FW Load Balancer IPsec DHCP Static routing Routed/Gateway networks (up to 9 networks) Isolated networks Customer’s virtual data center on vCloud Air
  • 5. 5 vCloud Air Cloud Options and Gateway Choices CONFIDENTIAL §  Shared Cloud •  Logically separated network, compute and storage §  5GHz CPU (burstable to 10GHz) §  20GB RAM, 2TB storage §  No virtual data center segmentation §  One Edge Gateway §  Dedicated Cloud •  Physically separated hosts •  Logically separated network and storage §  30GHz CPU, 120GB RAM, 6TB §  Segment virtual data centers based on orgs §  Multiple Edge Gateways VDC1 VDC2 VDC3 VDC4 VDC
  • 6. 6 Configuration Access Options CONFIDENTIAL vCloud Air Management Web Portal – for basic networking configurations
  • 7. 7 Configuration Access Options CONFIDENTIAL vCloud Air Management Web Portal – for basic networking configurations For Advanced configurations
  • 8. 8 Configuration Access Options CONFIDENTIAL vCloud Air Management Portal – for advanced networking configurations
  • 9. 9 vCloud Air Networking Services •  IP Addressing •  Network creation •  Firewall •  NAT •  DHCP •  Load Balancer •  VPN
  • 10. 10 IP Address Assignment •  IP Pool –  Pool of IPs created by default on auto generated isolated and routed networks –  Virtual machines attached to those networks get IP addresses from that default pool •  Static IP –  Fixed IP for a virtual machine –  Change configuration in VMware® vCloud Director® •  DHCP –  Part of Edge Gateway service –  Change configuration in vCloud Director –  Basic DHCP service Routed Network
  • 11. 11 Firewall Rules in vCloud Air
  • 12. 12 Firewall Rules: North-South and East-West Traffic Routed Network 1 Routed Network 2 Routed Network 3 Firewall Rules: -  By default: Deny all -  Policies for traffic that passes through the gateway Gateway •  5-tuple firewall policies (Protocol, Source/Dest. IP, Source/Dest. Port ) •  Can have multiple policies across multiple networks •  Ideal for enterprise grade application deployment
  • 13. 13 Network Address Translation (NAT) •  Source NAT and Destination NAT rules –  Supports multiple rules on multiple interfaces •  Can use internal/private IP space –  Bring your own internal IP space –  Create/manage subnets within IP space –  Multiple IP spaces under the same gateway •  Need to create firewall rules to allow traffic •  IPv4 NAT NAT rules: -  SNAT & DNAT rules -  Options include protocol/port selection Gateway Public IPs Internal IPs 10.x.x.x 172.16.x.x 192.168.x.x Organization Net 1 Organization Net 2 Organization Net 3
  • 14. 14 Edge Gateway Services – Load Balancing Pool Servers Load Balanced - Round Robin - IP Hash - URI - Least Connected Virtual Server – - Virtual IP (Public IP) - Frontend traffic - Assigned to a server pool Can have multiple virtual servers and pools Edge gateway Load balancer
  • 15. 15 Load Balancer – Pool Servers •  Pool Servers –  HTTP/HTTPS/TCP –  Load Balancing Methods •  IP Hash •  Round Robin •  URI •  Least Connected –  Health Check •  Each with +TCP as mode •  Monitoring Ports –  Add Servers •  Ratio Weight •  Change Ports/Services per Server
  • 16. 16 Load Balancer – Virtual Servers •  Virtual Servers –  Apply on outside network –  Server Pool –  Persistence Method •  HTTP – Cookie •  HTTPS – Session ID
  • 18. 18 Options to Connect to vCloud Air z Customer Data Center vCloud Air Private WAN / Direct Connect / Cross Connect IPsec Tunnel Public INTERNET Many Connectivity Choices to Support Many Use Cases
  • 19. 19 INTERNET Connecting to vCloud Air •  Over the Public Internet –  With Public IPs –  Use NAT for address translation –  By default firewall set to deny all and NAT not configured INTERNET •  IPsec VPN –  vCloud Air features include IPSEC VPN –  Multiple VPN tunnels can terminate to Edge Gateway –  Can connect to most of the major on-premises VPN devices
  • 20. 20 Connecting via VPN VMware vSphere® (On-Premises) SharePoint-Routed Network (10.0.10.0/24) vCloud Air Edge Gateway §  LEP – 69.194.137.230 §  Peer ID – 10.0.1.150 §  Peer IP – 68.108.102.47 10.0.1.150 10.0.10.1 Customer’s edge Router 10.0.1.1 68.108.102.47 SharePoint-Default Routed Network (192.168.109/24) 192.168.109.1 Virtual Machine 1 vCloud Air Virtual Machine 2 69.194.137.230 vSphere Edge Gateway §  LEP – 10.0.1.150 §  Peer ID – 69.194.137.230 §  Peer IP – 69.194.137.230 IP Protocol ID 50 (ESP) IP Protocol ID 51 (AH) UDP Port 500 (IKE) UDP Port 4500 VPN Traffic
  • 21. 21 Stretching L2 to vCloud Air - Logical Architecture (192.168.50.0/24) 184.61.71.155 74.204.180.41 VPN Traffic INTERNET Edge Gateway Edge Gateway Edge Gateway Corp Firewall (192.168.50.0/24) Default Gateway = 192.168.50.10 50.34 50.35 50.34 50.35 50.33 100.33 (192.168.50.0/24) 50.10 100.10
  • 22. 22 vCloud Air Direct Connect Customer Cage – in CoLo vCloud Air Cross Connection Direct Connect Partner Device Customer Data Center vCloud Air Private WAN connectivity Direct Connect Partner Device
  • 23. 23 Direct Connect – vCloud Air Connectivity 1 or 10 Gbps Direct Connect Traffic DMZ Network (192.168.52.0/24) Private Network (192.168.50.0/24) Private Network (192.168.110.0/24) Headquarters Direct Connect Line Edge Gateway INTERNET
  • 24. 24 Direct Connect – Connecting to Existing Security 1 Gbps Direct Connect Traffic DMZ Network (192.168.52.0/24) Internet Private Network (192.168.50.0/24) Private Network (192.168.110.0/24) 10.1.1.x/2410.1.1.x/24 On-Premises Edge Gateway IDS Existing Security Policies and Appliances IGW Direct Connect – Private Line IPS
  • 25. 25 Direct Connect – Cross Connect 1 or 10 Gbps Direct Connect Traffic DMZ Network (192.168.52.0/24) Private Network (192.168.50.0/24) Private Network (192.168.110.0/24) CUSTOMER CAGE Direct Connect Line Edge Gateway Note: Storage connection must be In- Guest based connectivity with NFS or Software iSCSI Initiator
  • 26. 26 User Level Rights and Security Role Rights Cannot do Ideal for Account Administrator Can add/edit users and user rights Virtual data center resource management, Network mgmt etc. Account management Virtualization Infrastructure Administrator Create virtual data centers Add/edit compute and storage resources Cannot create users, manage networking Virtual infrastructure admin App admin Network Administrator Create networks Add gateways Add gateway services User management, Virtual data center resource management Network admin Read-only Administrator Read only rights for all setups/configurations Any adds/edits Supervisor Subscription Administrator Access to myVMware. Purchase resources, file support tickets No vCloud Air management rights For all personnel with purchasing rights and/or support needs
  • 27. 27 Application Security – Access Rights •  Administration rights –  Clearly identify individuals, and rights that the individuals get –  An enterprise administrator can have more than one type of right –  Rights help enforce secure cloud usage •  User rights –  End user rights for virtual machine owners –  End user cannot do any admin activity –  Users have limited visibility to cloud resources
  • 28. 28 Summary •  You will leave with: ü  An understanding of the vCloud Air networking building blocks ü  A strong networking foundation for building a complex hybrid cloud ü  An understanding of advanced networking use cases and security •  Key Takeaways –  Building blocks you are used to – vSphere, VXLAN, VMware vCloud® Networking and Security Manager™vCNS, VMware® vCloud Director® –  Flexible and Powerful –  Supports all your complex networking •  IPSEC VPN •  Stretched Applications •  Layer 2 Extension - BYOIP –  Advanced application security
  • 29. Go To VMware Cloud Academy •  See a video of this presentation and others to learn more about vCloud Air •  Condensed VMworld jump start presentations delivered by technical subject-matter experts •  Free and ungated to learn at your own pace •  All videos under 15 mins! •  Test your knowledge by taking a quiz •  Download vCloud Air eBook and other assets and tools 29 http://vcloud.vmware.com/cloud-academy