Microsoft Storsimple Configuration with Expressroute
Total Page:16
File Type:pdf, Size:1020Kb
MICROSOFT STORSIMPLE CONFIGURATION WITH EXPRESSROUTE Version: 1.0 Copyright This document is provided "as-is". Information and views expressed in this document, including URL and other Internet Web site references, may change without notice. Some examples depicted herein are provided for illustration only and are fictitious. No real association or connection is intended or should be inferred. This document does not provide you with any legal rights to any intellectual property in any Microsoft product. You may copy, use and modify this document for your internal, reference purposes. © 2016 Microsoft Corporation. All rights reserved. Microsoft, Windows Azure, StorSimple, Hyper-V, Internet Explorer, Silverlight, SQL Server, Windows, Windows PowerShell, and Windows Server are trademarks of the Microsoft group of companies. All other trademarks are property of their respective owners. Table of contents Introduction .............................................................................................................................................................................................. 4 Physical Appliance High Level Solution Architecture................................................................................................................... 5 Virtual Appliance High Level Solution Architecture ..................................................................................................................... 6 Physical Appliance Detailed Traffic Matrix ...................................................................................................................................... 7 Virtual Appliance Detailed Traffic Matrix ........................................................................................................................................ 11 StorSimple Appliance Registration Process .................................................................................................................................. 16 ExpressRoute Supported Configuration for StorSimple............................................................................................................ 17 Routing with Expressroute ................................................................................................................................................................. 18 Introduction This document is intended to describe the required configuration/considerations when StorSimple is being used over ExpressRoute network. Physical Appliance High Level Solution Architecture The below diagram show high level solution architecture with different types of traffic flow Virtual Appliance High Level Solution Architecture The below diagram show high level solution architecture with different types of traffic flow Physical Appliance Detailed Traffic Matrix The below table show the traffic matrix with destinations required for StorSimple appliance Component/ URL pattern Device specific URLs [Device specific Source Destination Port Inbound/ Traffic flow Functionality means these urls are related to test device IPs IPs Outbound and will vary between different appliances] ACS https://*.accesscontrol.windows.net/* wuspod01rp1users.accesscontrol.wind Cloud Azure TCP 443 OUT Initially WAN if ows.net enabled Datacenter (HTTPS) ExpressRoute is NICs IP ranges not in West US Appliances will always try to reach Required geo, otherwise One Stop Authenticator “the above EXPRESSROUTE URL” which is located in West US datacenter first time and then it will acquire the respective URL according to the SS registration GEO StorSimple https://*.storsimple.windowsazure.com pod01- Cloud Azure TCP 443 OUT ExpressRoute Service /* cis1.wus.storsimple.windowsazure.com enabled Datacenter (HTTPS) NICs IP ranges This is dynamically generated URL for Required each appliance and passed thru the initial registration process [The above URL is related to our testing lab appliance only] Azure Service https://*.servicebus.windows.net/* wuspod01cis1sbns95jfo.servicebus.win Cloud Azure TCP 9354 OUT ExpressRoute Bus dows.net enabled Datacenter TCP 443 NICs IP ranges (HTTPS) This is dynamically generated URL for each appliance and passed thru the initial registration process [The above URL is related to our testing lab appliance only] Azure https://*.core.windows.net/* Cloud Azure TCP 443 OUT ExpressRoute Storage enabled Datacenter (HTTPS) Accounts NICs IP ranges Monitoring https://*.core.windows.net/* Cloud Azure TCP 443 OUT ExpressRoute Storage enabled Datacenter (HTTPS) Accounts NICs IP ranges Registration https://*.backup.windowsazure.co Cloud Azure TCP 443 OUT Initially WAN if services m enabled Datacenter (HTTPS) ExpressRoute is NICs IP ranges not in West US Required geo, otherwise EXPRESSROUTE Microsoft http://*.windowsupdate.microsoft.com Controller Public TCP 80 OUT Internet Update https://*.update.microsoft.com Fixed IPs Internet (HTTP) Servers http://*.windowsupdate.com only none azure TCP 443 http://download.microsoft.com hosted IPs (HTTPS) http://wustat.windows.com http://ntservicepack.microsoft.com Certificate http://crl.microsoft.com/pki/* Controller Public TCP 80 OUT Internet Revocation http://pki.microsoft.com/pki/* Fixed IPs Internet (HTTP) Lists only none azure TCP 443 hosted IPs (HTTPS) Akamai CDN http://*.deploy.akamaitechnologies.co Controller NA TCP 80 OUT Internet (for updates) m Fixed IPs (HTTP) only Microsoft http://*.msftncsi.com Controller NA TCP 80 OUT Internet network Fixed IPs (HTTP) connectivit only y status DNS Server - Cloud Internet UDP 53 OUT Internet or enabled based DNS (DNS) – If Internal DNS NICs server external servers with DNS is forwarders configure d NTP Server - Cloud Internet UDP 123 OUT Internet enabled based NTP (NTP) - If NICs server external NTP is configure d Support https://*.partners.extranet.microsoft.co Cloud NA 443 OUT Internet package m/* enabled HTTPS NICs Remote - All 5985 IN LAN PowerShell enabled HTTP NICs Remote - All 5986 IN LAN PowerShell enabled HTTPS NICs iSCSI - iSCSI 3260 IN LAN enabled (iSCSI) NICs Snapshot - All 5985 IN LAN Manager enabled NICs Virtual Appliance Detailed Traffic Matrix The below table show the traffic matrix with destinations required for StorSimple appliance Component/ URL pattern Device specific URLs [Device specific Source Destination Port Inbound/ Traffic flow Functionality means these urls are related to test device IPs IPs Outbound and will vary between different appliances] ACS https://*.accesscontrol.windows.net/* wuspod01rp1users.accesscontrol.wind Cloud Azure TCP 443 OUT Initially WAN if ows.net enabled Datacenter (HTTPS) ExpressRoute is NICs IP ranges not in West US Appliances will always try to reach Required geo, otherwise One Stop Authenticator “the above EXPRESSROUTE URL” which is located in West US datacenter first time and then it will acquire the respective URL according to the SS registration GEO StorSimple https://*.storsimple.windowsazure.com pod01- Cloud Azure TCP 443 OUT ExpressRoute Service /* cis1.wus.storsimple.windowsazure.com enabled Datacenter (HTTPS) NICs IP ranges This is dynamically generated URL for Required each appliance and passed thru the initial registration process [The above URL is related to our testing lab appliance only] Azure Service https://*.servicebus.windows.net/* wuspod01cis1sbns95jfo.servicebus.win Cloud Azure TCP 9354 OUT ExpressRoute Bus dows.net enabled Datacenter TCP 443 NICs IP ranges (HTTPS) This is dynamically generated URL for each appliance and passed thru the initial registration process [The above URL is related to our testing lab appliance only] Azure https://*.core.windows.net/* Cloud Azure TCP 443 OUT ExpressRoute Storage enabled Datacenter (HTTPS) Accounts NICs IP ranges Monitoring https://*.core.windows.net/* Cloud Azure TCP 443 OUT ExpressRoute Storage enabled Datacenter (HTTPS) Accounts NICs IP ranges Registration https://*.backup.windowsazure.co Cloud Azure TCP 443 OUT Initially WAN if services m enabled Datacenter (HTTPS) ExpressRoute is NICs IP ranges not in West US Required geo, otherwise EXPRESSROUTE Microsoft https://*.data.microsoft.com Controller Public TCP 443 OUT Internet Telemetry Fixed IPs Internet (HTTPS) only none azure hosted IPs Microsoft http://*.windowsupdate.microsoft.com Controller Public TCP 80 OUT Internet Update https://*.update.microsoft.com Fixed IPs Internet (HTTP) Servers http://*.windowsupdate.com only none azure TCP 443 http://download.microsoft.com hosted IPs (HTTPS) http://wustat.windows.com http://ntservicepack.microsoft.com Certificate http://www.microsoft.com/pki/* Controller Public TCP 80 OUT Internet Revocation http://crl.microsoft.com/pki/* Fixed IPs Internet (HTTP) Lists only none azure TCP 443 hosted IPs (HTTPS) Akamai CDN http://*.deploy.akamaitechnologies.co Controller NA TCP 80 OUT Internet (for updates) m Fixed IPs (HTTP) only Microsoft http://*.msftncsi.com Controller NA TCP 80 OUT Internet network Fixed IPs (HTTP) connectivit only y status DNS Server - Cloud Internet UDP 53 OUT Internet or enabled based DNS (DNS) – If Internal DNS NICs server external servers with DNS is forwarders configure d NTP Server - Cloud Internet UDP 123 OUT Internet enabled based NTP (NTP) - If NICs server external NTP is configure d Support https://*.partners.extranet.microsoft.co Cloud NA 443 OUT Internet package m/* enabled HTTPS NICs Remote - All 5985 IN LAN PowerShell enabled HTTP NICs Remote - All 5986 IN LAN PowerShell enabled HTTPS NICs iSCSI - iSCSI 3260 IN LAN enabled (iSCSI) NICs Snapshot - All 5985 IN LAN Manager enabled NICs StorSimple Appliance Registration