- Overview
- Installing Cisco Intercloud Fabric
- Creating an Intercloud Fabric Cloud
- Deploying a Virtual Machine
- Onboarding a Cloud Virtual Machine
- Installing Intercloud Fabric Firewall
- Installing and Configuring Intercloud Fabric Router (CSR)
- Installing and Configuring Intercloud Fabric Router (Integrated)
- Upgrading Cisco Intercloud Fabric
- Additional Information
Overview
This chapter contains the following sections:
- About Cisco Intercloud Fabric
- About the Cisco Intercloud Fabric Product
- Cisco Intercloud Fabric Architecture
- Recommended Network Topology for Cisco Intercloud Fabric
About Cisco Intercloud Fabric
Cisco Intercloud Fabric provides a faster and flexible response to business needs and addresses the potential challenges with hybrid clouds. A hybrid cloud is an interaction between private and provider clouds where private clouds extend to provider clouds and use provider cloud resources in a secure and scalable way. Cisco Intercloud Fabric enables you to place workloads across heterogeneous environments in multiple provider clouds. Cisco Intercloud Fabric provides the architectural foundation for secure hybrid clouds, which allows enterprises to easily and securely connect the private clouds to the provider cloud as needed and on demand. With a hybrid cloud, enterprises can combine the benefits of private and provider clouds. Cisco Intercloud Fabric provides the following benefits:
-
Provides a single point of management and control for virtual workloads across multiple provider clouds.
-
Provides a choice of cloud providers, such as Amazon Web Services, Microsoft Azure, and multiple Intercloud Fabric provider-based clouds.
-
Provides highly secure, scalable connectivity to extend private clouds to service provider clouds.
-
Enforces consistent network and workload policies throughout the hybrid cloud.
-
Enables workload mobility to and from service provider clouds for virtual workloads.

About the Cisco Intercloud Fabric Product
The Cisco Intercloud Fabric architecture provides the following two product configurations to address the enterprise and service provider customers.
Cisco Intercloud Fabric for Business is intended for enterprise customers who want to transparently extend their private clouds into provider cloud environments, while keeping the same level of security and policy across environments. Cisco Intercloud Fabric for Business consists of the following components:
The Cisco Intercloud Fabric Getting Started Guide provides information on installing the components for Cisco Intercloud Fabric for Business.
Cisco Intercloud Fabric for Providers is intended for provider-managed cloud environments, allowing their enterprise customers to transparently extend their private cloud environments into the provider's cloud, while keeping the same level of security and policy across cloud environments.
The Cisco Intercloud Fabric Provider Platform Installation Guide provides information on installing the components for Cisco Intercloud Fabric for Providers.
Cisco Intercloud Fabric Architecture
Cisco Intercloud Fabric is a hybrid cloud solution deployed as virtual machines (VMs) in the private cloud and in the provider cloud. The Cisco Intercloud Fabric for Business consists of the following components:
-
Intercloud Fabric Virtual Machine: This VM contains Intercloud Fabric Director and Prime Network Services Controller.
-
Secure Cloud Extension: This component contains Intercloud Fabric Extender (ICX) and Intercloud Fabric Switch (ICS).

Intercloud Fabric Provider Platform provides an extensible adapter framework to allow integration with different provider cloud infrastructure management platforms, and other cloud APIs. It is a virtual appliance that is deployed on the provider cloud for providing service provider customers with the ability to access cloud resources using Intercloud Fabric APIs. It also translates the API calls to different provider infrastructure platforms, giving customers the choice to move their workloads regardless of the cloud API exposed by the service provider.

Intercloud Fabric Director
Intercloud Fabric Director is the single point of management and consumption for hybrid cloud solutions for end users and IT administrators. It offers a single console so that end users and IT administrators can provision workloads to private and provider clouds. Intercloud Fabric Director exposes northbound APIs that allow customers to programmatically manage their workloads in the hybrid cloud environment or to integrate with other cloud management platforms.
Intercloud Fabric Director also provides a self-service portal for IT administrators to manage and consume hybrid cloud offers, and for end users to consume services. For end users, Intercloud Fabric Director provides a service catalog that combines offers from multiple clouds and a single self-service IT portal for multiple provider clouds.
For IT administrators, Intercloud Fabric Director has an IT administrative portal from which administrators can perform various administrative tasks, such as configure users, create catalogs, and create VM template.

Secure Cloud Extension
The Secure Cloud Extension forms the basis for the core switching and services infrastructure in the Cisco Intercloud Fabric solution. The Secure Cloud Extension provides the following features:
-
Secure Layer 2 network extension from a private cloud to a provider cloud
-
Advanced switching features for applications running in the provider cloud
-
Support for services such as zone-based firewalls and routing in the provider cloud
The Secure Cloud Extension consists of several components working together to provide these functions. The private cloud is connected to the provider cloud through a highly secure tunnel that is established between a pair of virtual appliances. The Intercloud Fabric Extender (ICX) runs in the private cloud, and the Intercloud Fabric Switch (ICS) runs in the provider cloud. These appliances can be deployed in a high availability pair to provide redundancy. Virtual services are deployed within this environment to provide firewall and routing support in the provider cloud.

Intercloud Fabric Extender
The Intercloud Fabric Extender is a virtual machine that runs in the private cloud. It is responsible for establishing a secure tunnel for interconnecting the Intercloud Fabric components in the private cloud with the provider cloud. The main functions of the Intercloud Fabric Extender are as follows:
Intercloud Fabric Switch
The Intercloud Fabric Switch is a virtual machine that runs in the provider cloud. It is responsible for establishing secure tunnels for connecting VMs in the provider cloud to the private cloud VMs and other VMs in the cloud. The main functions of the Intercloud Fabric Switch are as follows:
-
Runs the Virtual Ethernet Module (VEM) to provide the Cisco Nexus 1000V functions.
-
Establishes a secure tunnel to connect the VEM with Intercloud Fabric Extender.
-
Establishes secure tunnels to connect all of the cloud VMs.
-
Monitors and reports statistics of VMs in the cloud.
-
Monitors and reports any component failures in the cloud to Cisco Prime Network Services Controller (PNSC).
The VEM is embedded in the Intercloud Fabric Switch and is responsible for the following:
-
Communicates with the Virtual Supervisor Module (VSM) function that runs at the private cloud for retrieving VM-specific network policies such as port profiles.
-
Switches the network traffic between cloud VMs.
-
Switches the network traffic between cloud VMs and the private cloud.
-
Applies network policies to any switching network traffic.
-
Collects and reports VEM-related statistics.
Cisco Intercloud Fabric Agent
The Cisco Intercloud Fabric Agent (ICA) provides a network overlay for the VMs in the cloud. It secures the guest VM traffic in the cloud and abstracts the cloud infrastructure. It is deployed in the provider cloud as a secure tunnel driver that runs within the cloud VM's operating system. It also redirects network traffic to the secure overlay network as follows:
Recommended Network Topology for Cisco Intercloud Fabric
We recommend the following network topology for Intercloud Fabric:
![]() Note | The two servers are deployed on a VMware HA-enabled cluster. |


Feedback