- Overview
- Installing Cisco Intercloud Fabric
- Creating an Intercloud Fabric Cloud
- Deploying a Virtual Machine
- Onboarding a Cloud Virtual Machine
- Installing Intercloud Fabric Firewall
- Installing and Configuring Intercloud Fabric Router (CSR)
- Installing and Configuring Intercloud Fabric Router (Integrated)
- Upgrading Cisco Intercloud Fabric
- Additional Information
- Information About Intercloud Fabric Cloud
- Guidelines and Limitations
- Prerequisites
- Creating an Intercloud Fabric Cloud Workflow
- Creating Intercloud Fabric Infrastructure Policies and Pools
- Configuring Port Profiles and Port Groups
- Adding a Network Element
- Accessing Security Credentials for Intercloud Fabric in Microsoft Azure
- Creating an Intercloud Fabric Cloud
- Managing Services
- Cloning an Intercloud Fabric Cloud
Creating an Intercloud Fabric Cloud
This chapter contains the following sections:
- Information About Intercloud Fabric Cloud
- Guidelines and Limitations
- Prerequisites
- Creating an Intercloud Fabric Cloud Workflow
- Creating Intercloud Fabric Infrastructure Policies and Pools
- Configuring Port Profiles and Port Groups
- Adding a Network Element
- Accessing Security Credentials for Intercloud Fabric in Microsoft Azure
- Creating an Intercloud Fabric Cloud
- Managing Services
- Cloning an Intercloud Fabric Cloud
Information About Intercloud Fabric Cloud
An Intercloud Fabric cloud is a secure connection between a private cloud and a provider cloud. An Intercloud Fabric cloud includes two virtual gateways: one on the private cloud and one on the provider cloud. The gateway on the private cloud is referred to as the Intercloud Fabric Extender, and the gateway on the provider cloud is referred to as the Intercloud Fabric Switch. A secure Layer 4 tunnel connects the gateways, thereby extending the Layer 2 private cloud network into the provider cloud.
Guidelines and Limitations
-
For the cloud provider Microsoft Azure:
-
You must register the certificate with the Microsoft Azure portal.
-
Intercloud Fabric will create a storage account with a name starting with pnsc and a container below that storage account with the name pnsc-sc in the region where the Intercloud Fabric cloud is created. This storage account will be created during the first upload call and will be used for all further uploads to the Microsoft Azure cloud.
-
-
All port profiles required for deploying a virtual machine must be created using Intercloud Fabric.
-
All port profiles required for creating an Intercloud Fabric cloud must be created using Intercloud Fabric.
-
All port profiles required for creating Intercloud network policies must be created using Intercloud Fabric.
-
All port profiles required for the Intercloud Fabric Firewall data interface and management interface must be created using Intercloud Fabric.
-
All port profiles required for virtual machines that need firewall protection in the Intercloud Fabric must be updated using PNSC to add the vPath configuration.
-
While cloning an Intercloud Fabric cloud, you must not migrate the source virtual machine or the destination virtual machine. Doing so will impact the cloning operation and any operations carried out on the destination virtual machine after migration.
Prerequisites
-
You have created an account in the provider cloud.
-
You have the credentials for the cloud provider, such as an access key and access ID for Amazon AWS, and a username, password, and URI for other supported providers.
-
In the Amazon Web Services GUI, you can access the security credentials for Intercloud Fabric by navigating to . Click the Access Keys (Access Key ID and Secret Access Key) (+) icon to obtain the AWS access key ID. To create a new access key, click Create New Access Key. Download the key file to get the access key ID and secret access key. Optionally, click the Show Access Key link to see the access key ID and the secret access key.
-
For Microsoft Azure, see Accessing Security Credentials for Intercloud Fabric in Microsoft Azure.
-
For Cisco ICFPP-based providers, you will receive a welcome email from Cisco with information about the security credentials.
-
-
You have installed the Intercloud Fabric infrastructure components.
-
If you are using Cisco Nexus 1000V in the private cloud, you have added the Cisco Nexus 1000V switch to Intercloud Fabric.
-
For Cisco ICFPP-based providers, you have configured the cloud instance and tenant in Cisco ICFPP for use with Intercloud Fabric. See the Cisco Intercloud Fabric Provider Platform Installation Guide.
-
To integrate VCD with Cisco ICFPP, see the Configuring VMware vCloud Director for Cisco ICFPP chapter in the Cisco Intercloud Fabric Provider Platform Installation Guide.
Creating an Intercloud Fabric Cloud Workflow
Installing the Intercloud Fabric cloud includes the following steps:
| Step 1 | Create
Intercloud Fabric infrastructure policies, profiles, and pools. Pools can include a
management IP address pool for the Intercloud Fabric Extender, a tunnel IP
address pool for the Intercloud Fabric Extender, a management IP pool for the
Intercloud Fabric Switch, an interface IP address pool for services, and an IP
address pool for VMs in the cloud.
See Creating Intercloud Fabric Infrastructure Policies.
| ||
| Step 2 | Create port profiles for the Distributed Virtual Switch (DVS) in the private cloud. | ||
| Step 3 | Create
management and data port profiles for the
Intercloud Fabric Virtual Security Gateway.
See Creating Port Profiles for the Intercloud Fabric Firewall. | ||
| Step 4 | Create an Intercloud Fabric cloud using the wizard. |
Creating Intercloud Fabric Infrastructure Policies and Pools
Successful implementation of an Intercloud Fabric cloud depends on the correct configuration of the following items:
| Step 1 | Configure MAC address pools. |
| Step 2 | Add private subnets. |
| Step 3 | Create an IP
group.
See Adding an IP Group. |
| Step 4 | Configure tunnel profiles. |
| Step 5 | Create port profiles. |
Adding a MAC Address Pool
Add a MAC address pool to allocate a group of MAC addresses to a virtual private cloud.
![]() Note | Ensure that there is no overlapping MAC address pool for multiple Intercloud Fabric setups. |
Adding a Private Subnet
Define a private subnet for a virtual machine in the cloud. A private subnet is used to define the private IP space in the provider environment.
![]() Note | Private subnets apply only to Microsoft Azure. |
| Step 1 | Log in to Intercloud Fabric. | ||||||
| Step 2 | Choose . | ||||||
| Step 3 | In the Intercloud Fabric Infrastructure Policies window, click the Private Subnet tab. | ||||||
| Step 4 | Click
Add.
The Add Subnet window appears. | ||||||
| Step 5 | Complete the
following details:
| ||||||
| Step 6 | Click Submit to create a private subnet. |
Adding an IP Group
An IP group protects cloud resources by ensuring that only the ports required for Intercloud Fabric are open to the public interface of the cloud VMs in an Intercloud Fabric cloud. The allowed IP addresses are typically the enterprise public IP space.
The following ports are required for Intercloud Fabric:
-
SSH port: TCP 22
-
HTTPS port: TCP 443
-
RDP port: TCP 3389
-
Intercloud Fabric tunnel ports: TCP 6644 and 6646
-
Intercloud Fabric tunnel ports: UDP 6644 and 6646
-
Intercloud Fabric Router (CSR) VPN tunnel ports: UDP and TCP 500, 4500
![]() Note | Failure to configure an IP group could permit unauthorized access to your cloud VMs, Intercloud Fabric Switch, and enterprise data center. |
| Step 1 | Log in to Intercloud Fabric. | ||||||
| Step 2 | Choose . | ||||||
| Step 3 | In the Intercloud Fabric Infrastructure Policies window, click the IP Group tab. | ||||||
| Step 4 | Click
Add.
The Add IP Group window appears. | ||||||
| Step 5 | Complete the
following details:
| ||||||
| Step 6 | Click Submit to create the IP group. |
Configuring a Tunnel Profile
A tunnel profile pairs a connection parameter policy with a key policy to ensure secure communication for specific tunnel ports. After you configure tunnel profiles, you can apply them to tunnels between the following elements:
A site-to-site tunnel profile is used for tunnels between Intercloud Fabric Extender and Intercloud Fabric Switch. An access tunnel profile is used for tunnels between an Intercloud Fabric Switch and cloud VMs.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||||||||
| Step 3 | In the Intercloud Fabric Infrastructure Policies window, click the Tunnel Profile tab. | ||||||||||||||||||||||||||||||||
| Step 4 | Click
Add.
The Add Tunnel Profile window appears. | ||||||||||||||||||||||||||||||||
| Step 5 | Complete the
following details:
| ||||||||||||||||||||||||||||||||
| Step 6 | Click Submit to create a tunnel profile. |
Creating Port Profiles
Use this procedure to create port profiles in Intercloud Fabric.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||
| Step 2 | Choose . | ||||||||||||||
| Step 3 | Select the cloud from the All Clouds drop-down list. | ||||||||||||||
| Step 4 | In the IcfVSM tab, select the VSM. | ||||||||||||||
| Step 5 | Click the
Add Port
Profile button.
The Add Port Profile appears. | ||||||||||||||
| Step 6 | Complete the
following fields for the port profile:
| ||||||||||||||
| Step 7 | Click Next. | ||||||||||||||
| Step 8 | View the port profiles in the Port Profile tab. |
Configuring Port Profiles and Port Groups
This section contains information about the port profiles and port groups that must be associated with the vNICs of Intercloud Fabric and Intercloud Fabric Extender.
If you are using Cisco Nexus 1000V to deploy the virtual machines, you must create the port profiles in the Cisco Nexus 1000V VSM. If you are using VMware vSwitch or VDS, you must create the port groups in the vCenter. See the Cisco Nexus 1000V Port Profile Configuration Guide for information about creating port profiles. See the VMware vSphere documentation for information about creating port groups.
Intercloud Fabric Extender has the following three vNICs:
-
Tunnel vNIC: The tunnel vNIC is used to provide a secure tunnel between Intercloud Fabric Extender and Intercloud Fabric Switch. The use of this vNIC is optional. If used, it must be associated with the access port profile or port group that provides internet access to the service provider. You can also use a management vNIC to provide a secure tunnel between Intercloud Fabric Extender and Intercloud Fabric Switch. By default, the management vNIC is used to provide a secure tunnel connection to the Intercloud Fabric Switch. While creating an Intercloud Fabric cloud, you can use the tunnel vNIC for creating a secure tunnel by checking the Advanced check box in the Intercloud Fabric cloud set up wizard.
-
Management vNIC: The management vNIC is used to provide management access to the Intercloud Fabric Extender and connectivity to PNSC, Intercloud Fabric VSM, and enterprise servers such as DNS and NTP. It must be associated with the access port profile or port group that provides management access to the Intercloud Fabric Extender and connectivity to PNSC, the Intercloud Fabric VSM, and the enterprise servers. It can also be used to establish a secure tunnel connection to an Intercloud Fabric Switch in the service provider network. If you use the management vNIC to provide a secure tunnel for the Intercloud Fabric Switch, you must associate it with a port profile or port group that also provides internet access to the service provider and management access.
-
Enterprise Data Trunk vNIC: The enterprise data trunk vNIC is used as an uplink to send or receive traffic over the secure tunnel. It must be associated with the trunk port profile or port group. The trunk port profile must contain all VLANs that will be extended to the provider cloud. If you use a VMware vSwitch or VDS in the private cloud, you must enable promiscuous mode for the port group associated with the data trunk vNIC.
You can create a common access port profile or port group for the Intercloud Fabric and Intercloud Fabric Extender management vNIC. If you use the tunnel vNIC instead of the management vNIC to provide a secure tunnel connection to the Intercloud Fabric Switch, you should create a separate access port profile or port group.
![]() Note | The VLANs specified in the trunk port profile for internal tunnel trunk interfaces for the Intercloud Fabric Extender and Intercloud Fabric Switch should exist in the trunk port profile for the Intercloud Fabric Extender trunk interface. |
If you use a VMware vSwitch, you must configure a port group for the Intercloud Fabric Extender tunnel interface. This port group should allow all VLANs in trunk mode.
| Step 1 | If the
Cisco Nexus 1000V is used in the private cloud and you want to create a management
port profile, use this configuration example:
port-profile type vethernet VLAN-36 vmware port-group switchport mode access switchport access vlan 36 no shutdown state enabled |
| Step 2 | If the
Cisco Nexus 1000V is used in the private cloud and you want to create a tunnel port
profile, use this configuration example:
port-profile type vethernet VLAN-37 vmware port-group switchport mode access switchport access vlan 37 no shutdown state enabled |
| Step 3 | If the
Cisco Nexus 1000V is used in the private cloud and you want to create a trunk port
profile, use this configuration example:
port-profile type vethernet Trunk vmware port-group switchport mode trunk switchport trunk allowed vlan 36-37,208,1300-1315 no shutdown state enabled |
Adding a Network Element
If you use a Cisco Nexus 1000V switch, you must add the Cisco Nexus 1000V switch to Intercloud Fabric before creating an Intercloud Fabric cloud. After the Cisco Nexus 1000V switch is added as a network element in Intercloud Fabric, it appears under the Managed Network Element tab.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||
| Step 3 | In the Managed Network Elements tab, click Add Network Element. | ||||||||||||||||
| Step 4 | In the
Add
Network Element dialog box, complete the following fields:
| ||||||||||||||||
| Step 5 | Click Submit. |
Accessing Security Credentials for Intercloud Fabric in Microsoft Azure
Use this procedure to access the security credentials for Intercloud Fabric in Microsoft Azure.
You have installed the infrastructure components.
| Step 1 | Log in to Intercloud Fabric. |
| Step 2 | Choose . |
| Step 3 | In the Infrastructure tab, click Export Azure Certificate. |
| Step 4 | Log in to the Microsoft Azure management portal. |
| Step 5 | Choose . |
| Step 6 | Click Upload to upload the certificate. |
| Step 7 | In the Items page, select the subscription ID from the Subscription drop-down list located at the top. |
What to Do Next
Use this subscription ID to create the Intercloud Fabric cloud in Intercloud Fabric.
Creating an Intercloud Fabric Cloud
Use this procedure to create an Intercloud Fabric cloud.
-
You have created a provider account.
-
You know the credentials for the cloud provider.
-
You have created a tunnel network with the name icfTunnelNet. This applies only to Intercloud Fabric in OpenStack environments.
-
You have installed the infrastructure components.
-
You have configured the port profiles for a distributed virtual switch (such as Cisco Nexus 1000V, VMware vSwitch, VMware VDS, or Microsoft Hyper-V switch) in the private cloud.
-
You have created Intercloud Fabric infrastructure policies, such as a MAC pool, tunnel profile, and static IP pool.
-
Optionally, you have configured a native VLAN to use for your VM network in vCenter. A native VLAN is useful in flat network environments when only one VLAN is present.
-
If you are using a Cisco Nexus 1000V switch in the private cloud, you have added the switch to Intercloud Fabric. See Adding a Network Element.
-
You have configured the Intercloud Fabric Extender trunk port profile for the VLANs that will be extended into the cloud.
-
You have uploaded the services bundle to manage services. Choose to upload the services bundle.

Note
You do not need to upload the services bundle to manage the Intercloud Fabric Router (Integrated).
-
You have the required configurations and hardware to enable a dedicated network connection between the public cloud and AWS VPC using AWS Direct Connect.

Note
Direct Connect can only be enabled for AWS VPC.

Note
When Direct Connect is enabled, the provider's private IP address that is assigned to the Intercloud Fabric Switch will be used by PNSC and the Intercloud Fabric Extender to establish a tunnel.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 3 | Click the
IcfCloud tab and then click
Setup.
The Cloud Setup wizard appears. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 4 | Complete the
following fields for
Account
Credentials:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 5 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 6 | Complete the
following fields for
Configuration Details:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 7 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 8 | Complete the
following fields for
Secure
Cloud Extension:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 9 | Click
Next.
The Summary window provides a summary of the Intercloud Fabric cloud. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 10 | Click Submit. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 11 | To view the
task status:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
Managing Services
Use this procedure to manage services after creating an Intercloud Fabric cloud.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||
| Step 3 | Select the
Intercloud Fabric
cloud and click
Manage
Services.
The Manage Services window appears. | ||||||||||||||||||
| Step 4 | Complete the
following fields for
Manage
Services:
| ||||||||||||||||||
| Step 5 | Click Submit. |
Cloning an Intercloud Fabric Cloud
Use this procedure to clone an Intercloud Fabric cloud. When you clone an Intercloud Fabric cloud, you can modify all the fields except the provider account information.
![]() Note | 1-click Clone is not supported for creating Intercloud Fabric clouds in Microsoft environments. |
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 3 | In the IcfCloud window, click the IcfCloud tab. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 4 | In the
IcfCloud tab, select the
Intercloud Fabric cloud
and click
Clone.
The Cloud Setup wizard appears. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 5 | Complete the
following fields for
Account
Credentials:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 6 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 7 | Complete the
following fields for
Configuration Details:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 8 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 9 | Complete the
following fields for
Secure
Cloud Extension:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 10 | Click
Next.
The Summary window lists a summary of the Intercloud Fabric cloud. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 11 | Click Submit to clone the Intercloud Fabric cloud. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 12 | To view the
task status:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
Feedback