Vmware SD-WAN by Velocloud Release 3.3 11
Total Page:16
File Type:pdf, Size:1020Kb
VeloCloud Administration Guide VMware SD-WAN 3.3 VeloCloud Administration Guide You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ VMware, Inc. 3401 Hillview Ave. Palo Alto, CA 94304 www.vmware.com © Copyright 2021 VMware, Inc. All rights reserved. Copyright and trademark information. VMware, Inc. 2 Contents 1 VMware SD-WAN by VeloCloud Release 3.3 11 2 Who Should Read This Document 14 3 VeloCloud Overview 15 Solution Components 16 Capabilities 16 Network Topologies 19 Branch Site Topologies 20 Roles and Privilege Levels 24 User Role Matrix 25 Key Concepts 28 Supported Modems 32 4 User Agreement (VCO Login Screen) 33 5 Log in to VCO Using SSO for Enterprise User 34 6 Monitor the VCO 35 Monitor Navigation Panel 35 Network Overview 35 Monitor Edges 38 Enterprise Global View 38 Overview Tab 39 QoE Tab 41 Transport Tab 44 Applications Tab 48 Sources Tab 50 Destinations Tab 51 Business Priority Tab 52 Flow Stats Rollups and Retention 53 Monitor Network Services 56 Monitor Routing 57 PIM Neighbors View 57 Monitor Alerts 58 Monitor Events 58 Auto Rollback to the Last Known “Good” Configuration 59 Event Types and Descriptions 60 VMware, Inc. 3 VeloCloud Administration Guide 7 Configuring VNFs 61 Monitor the Edge Overview 61 Configure a VNF Instance 62 VNF Monitoring for an Edge 72 VNF Events 74 Configure VNF Alerts and Notifications 75 8 Configure Segments 77 9 Configure Network Services 79 About Edge Clustering 80 How Edge Clustering Works 81 Configure Edge Clustering 87 Cloud VPN Hubs & Backhaul Sites (Summary View) 89 Configure a Non-VeloCloud Site 90 Configure Check Point 94 Step 1: Configure the Check Point CloudGuard Connect 94 Step 2: Configure Check Point as the Non-VeloCloud Site on the VeloCloud Orchestrator 94 Configure Amazon Web Services (AWS) 97 Obtain Amazon Web Services Configuration Details 97 Configure a Non-VeloCloud Site 97 Configure Zscaler 99 Step 1: Create and Configure a Non-VeloCloud Site 100 Step 2: Add to a Configuration Profile 101 Step 3: Configure Zscaler 102 Step 4: Configure Business Priority Rules 105 Configuration Tasks 107 VPN Workflow 107 Configure Cloud Proxy 111 Configure Cloud Security Services 111 Overview of Cloud Security Services 111 Configure Cloud Security Services 112 Add and Configure a Cloud Security Provider 113 Configure Cloud Security Services for Profiles 113 Configure Cloud Security Services for Edges 115 Monitor Cloud Security Services 117 Edges Screen 117 Network Services Screen 118 Configure DNS Services 119 Configure Netflow Settings 120 VMware, Inc. 4 VeloCloud Administration Guide Private Network Names 121 Configure Private Networks 122 Delete a Private Network Name 122 Configure Authentication Services 122 10 Configure Profiles 124 Create a Profile 124 Modify a Profile 126 Profile Overview Screen 126 Network to Segment Migration 126 Edge Upgrade from 2.X to 3.X Prerequisites 127 Best Practices for Upgrading Edges Deployed as Hub and Spoke 127 Best Practices for Upgrading Edges Deployed in HA 127 Migrate Network to Segment 127 Configure Local Credentials 132 Add Credentials 133 11 Configure a Profile Device 134 Configure a Device 134 Assign Segments in Profile 135 Configure Authentication Settings 137 Configure DNS Settings 137 Configure Netflow Settings at the Profile Level 137 Configure Syslog Settings at Profile Level 139 Configure Cloud VPN 142 Configure Branch to VPNs 142 Configure Branch to VeloCloud Hubs VPN 144 Configure Branch to Branch VPN 145 Enable Branch to Branch VPN 145 Enable Branch to Branch VPN Isolation 145 Enable Dynamic Branch to Branch VPN Isolation by Profile 146 Configure Multicast Settings 146 Configure Multicast Settings at the Interface Level 148 Add and Configure a VLAN 150 Configure the Management IP Address 151 Configure Device Settings 152 Configure Interface Settings 162 Configure Wi-Fi Radio Settings 169 Configure SNMP Settings at Profile Level 169 Configure Visibility Mode 171 Assign Partner Gateways 172 VMware, Inc. 5 VeloCloud Administration Guide Assign Controllers 174 Voice Quality Monitoring (VQM) 176 12 Cloud VPN 180 Overview of the Cloud VPN 180 Branch to Non-VeloCloud Site 182 Connect to Customer Data Center with Existing Firewall VPN Router 182 Iaas 183 Connect to CWS (Zscaler) 183 Branch to VeloCloud Hubs 183 Branch to Branch VPN 184 Branch to Branch VPN Isolation by Profile 184 Dynamic Branch to Branch 185 Dynamic Branch to Branch VPN Isolation by Profile 186 13 Configure Profile Business Policy 187 Create Business Policy 188 Configure Match Source 192 Configure Match Destination 192 Configure Match Application 193 Configure Action Priority 194 Configure Action Network Service 194 Configure Action Link Steering 195 Configure Policy-based NAT 200 Configure Action Service Class 201 Overlay QoS CoS Mapping 201 Tunnel Shaper for Service Providers with Partner Gateway 203 Configure Profile Firewall 204 Configure Firewall Rules 204 Create or Select a Network 210 Provision an Edge 218 Overview 218 Enterprise Edges Screen 218 Provision a New Edge 220 Actions Drop-down Menu 222 Activate Edges 225 Activate Edges Using Zero Touch Provisioning (Tech Preview) 226 Activate Edges Using Email 226 14 Edge Overview Tab 230 Edge Overview 230 VMware, Inc. 6 VeloCloud Administration Guide Edge Overview Properties 231 Properties Overview 231 Properties Area Field and Checkbox Descriptions 231 Initiate Edge Activation 232 Edge License 233 Edge Profile 233 Profile Overview 234 Profile Drop-Down Menu 234 Edge-specific Overrides and Additions 235 Contact & Location 235 Change Edge Location 236 Change Shipping Address 236 RMA Reactivation 236 Edge Reactivation Overview 236 RMA Reactivation Scenarios 237 RMA Reactivation Steps 237 RMA Reactivation Troubleshooting 239 15 Configure an Edge Device 241 Configure Netflow Settings at the Edge Level 243 Configure Syslog Settings at Edge Level 244 Configure Static Route Settings 246 Configure ICMP Probes/Responders 247 Edge Cloud VPN 247 High Availability (HA) 247 Configure VLAN Settings 248 Configure Device Settings 248 Configure DHCP Server on Routed Interfaces 248 Enabling RADIUS on a Routed Interface 250 Configure Edge LAN Overrides 251 Configure Edge WAN Overrides 251 Configure Edge WAN Overlay Settings 252 Configure Edge WAN Settings for MPLS Private Links 256 Configure Edge WAN Settings for MPLS Private Links 257 SD-WAN Service Reachability via MPLS 259 Configure SNMP Settings at Edge Level 263 Configure Wi-Fi Radio, DNS, Authentication, and Netflow Overrides 265 Configure Edge Business Policy 265 Configure Edge Firewall 266 Configure Edge Activation 270 LAN-side NAT Rules at Edge Level 271 VMware, Inc. 7 VeloCloud Administration Guide 16 Site Configurations 274 Data Center Configurations 275 Configure Branch and Hub 275 17 Configure Dynamic Routing with OSPF or BGP 287 Enable OSPF 287 Route Filters 291 Enable BGP 292 OSPF/BGP Redistribution 297 Overlay Flow Control 298 Global Routing Preferences 298 Overlay Flow Control Table 299 18 Configure Alerts 301 Configure SNMP Traps 301 19 Administration 303 Configure System Settings 303 Overview of Single Sign On 303 Configure Single Sign On for Enterprise User 303 Configure Single Sign On for Identity Partners 306 Configure an IDP for Single Sign On 306 Self-service Password Reset 324 Configure Two-factor Authentication 327 Enforce PCI Compliance on VCO 328 Monitor Edge Licensing 329 Generate an Edge Licensing Report 329 20 Configure VCE High Availability 330 Overview of VeloCloud Edge HA 330 Prerequisites 331 High Availability Options 331 HA Option 1: Standard HA 331 HA Option 2: Enhanced HA 335 Split-Brain Detection and Prevention 336 Split-Brain Condition 336 Split-Brain Detection and Prevention 336 Failure Scenarios 337 Support for BGP Over HA Link 337 Selection Criteria to Determine Active and Standby Status 338 VLAN-tagged Traffic Over HA Link 338 VMware, Inc. 8 VeloCloud Administration Guide Configure HA 339 1. Enable High Availability (HA) 339 2. Wait for VCE to Assume Active 339 3. Connect the Standby VCE to the Active Edge 340 4. Connect LAN and WAN Interfaces on Standby VCE 340 HA Event Details 341 21 Testing and Troubleshooting 342 Remote Diagnostics 343 Remote Actions 346 Edge Remote Action Definitions 347 Reset Edges to Factory Settings 347 Diagnostic Bundles 348 Request Packet Capture 348 Download Bundle 349 Delete Bundle 349 Request Diagnostic Bundle 350 22 VeloCloud Virtual Edge Deployment Guide 351 Overview of Virtual Edge 351 Deployment Prerequisites 351 Special Considerations for VeloCloud Virtual Edge deployment 352 Overview of cloud-init 353 Install Virtual Edge on KVM 354 Considerations 355 Enable SR-IOV on KVM 355 Install a Virtual Edge on KVM 356 Install Virtual Edge on VMware ESXi 360 Enable SR-IOV on VMware 360 Installing a Virtual Edge on VMware ESXi 362 23 AliCloud Virtual Edge Deployment Guide 367 AliCloud vVCE Deployment Overview 367 Topology A - Virtual Edge Deployment on AliCloud VPC 368 Topology B - Virtual Edge Deployment on AliCloud Single-Arm Topology 370 Create a Virtual Private Cloud 372 Create a VSwitch 373 Create a Security Group 375 Add Security Group Rules 377 Create Custom Route Tables and Associate VSwitches 378 Provision an Edge on the VCO 380 VMware, Inc. 9 VeloCloud Administration Guide Create a vVCE Instance on the ECS Console 384 Create an Elastic Network Interface 387 Create Elastic IP and Assign it to Public Interface of the Edge 389 Bind an ENI to an Edge instance 391 Create a LAN Instance 393 Add a Custom Route Table Entry 396 Create a Jump Host Instance