- Overview
- Installing Cisco Intercloud Fabric
- Creating an Intercloud Fabric Cloud
- Deploying a Virtual Machine
- Onboarding a Cloud Virtual Machine
- Installing Intercloud Fabric Firewall
- Installing and Configuring Intercloud Fabric Router (CSR)
- Installing and Configuring Intercloud Fabric Router (Integrated)
- Upgrading Cisco Intercloud Fabric
- Additional Information
- About the Intercloud Fabric Router (CSR)
- Guidelines and Limitations
- Prerequisites
- Installing and Configuring an Intercloud Fabric Router (CSR) Workflow
- Creating an Intercloud Fabric Cloud
- Managing Services
- Instantiating an Intercloud Fabric Router (CSR)
- About Network Address Translation and Port Address Translation Policies
- About Configuring VPN for Intercloud Fabric Router (CSR)
- Verifying the Installation of the Intercloud Fabric Router (CSR)
Installing and Configuring
Intercloud Fabric Router (CSR)
This chapter contains the following sections:
- About the Intercloud Fabric Router (CSR)
- Guidelines and Limitations
- Prerequisites
- Installing and Configuring an Intercloud Fabric Router (CSR) Workflow
About the Intercloud Fabric Router (CSR)
The Intercloud Fabric Router (CSR) provides a cloud-based virtual router that is deployed on a virtual machine (VM) instance on x86 server hardware. The Intercloud Fabric Router (CSR) is a virtual platform that provides selected Cisco IOS XE security and switching features on a virtualization platform.
The Intercloud Fabric Router (CSR) acts as an edge device in Intercloud Fabric and provides the following functionality:
-
Provides inter-VLAN routing for the virtual machines in the provider cloud.
-
Serves as the NAT gateway for the virtual machines in the provider cloud.
-
Provides VPN routing for the virtual machines in the provider cloud.
-
Enables you to extend the default gateway from the private cloud to the provider cloud.

The Intercloud Fabric Router (CSR) can also be deployed on Amazon Web Services (AWS) for private and provider cloud solutions. See the Cisco CSR 1000V Series Cloud Services Router Deployment Guide for Amazon Web Services for information on deploying the Intercloud Fabric Router AMI.
Guidelines and Limitations
-
The Intercloud Fabric Router (CSR) is not supported on Microsoft Azure.
-
The Intercloud Fabric Router (CSR) version 3.16.1 is required for Intercloud Fabric with VCD.
-
The Intercloud Fabric Router (CSR) version 3.14.01 is required for Intercloud Fabric with AWS.
-
The Intercloud Fabric Router (CSR) version 3.14.1.S is required for Intercloud Fabric with Cisco Intercloud Services – V.
-
Network Address Translation (NAT) functionality for the Intercloud Fabric Router (CSR) is available only if there is a default VPC in the Amazon Web Services (AWS) account.
-
If you configure dynamic NAT when working with Cisco Intercloud Services – V, return network traffic does not reach the Intercloud Fabric Router (CSR) cloud VM.
- During deployment of the Intercloud Fabric Router (CSR) in the provider cloud, inter-VLAN traffic might stop working between the private cloud and provider cloud virtual machines for VLANs that are not extended to the provider cloud. You must add routing for private cloud VLANs that are not extended on a data interface that is configured as the default gateway. If a data interface is not configured as a default gateway, add one with one of the private cloud VLANs that is not extended. Then, add routing for the remaining VLANs under that interface.
-
If you delete an Intercloud Fabric Router (CSR) instance and immediately try to recreate either the same instance or another instance of the Intercloud Fabric Router (CSR) in the same Intercloud Fabric cloud, you might receive the error can’t create; object already exists. We recommend that you wait for 10 minutes before you create a new instance of the Intercloud Fabric Router (CSR) in the Intercloud Fabric cloud.
-
After you perform any lifecycle operations using the PNSC GUI, you must refresh the GUI to view the status of the operation.
Prerequisites
-
You have an account in the provider cloud.
-
For Amazon Web Services, accept the terms and conditions as follows before launching the Intercloud Fabric Router (CSR) AMI from Intercloud Fabric: -
When you provision the virtual data centers in the Intercloud Fabric Router (CSR), ensure that the network policies associated with the virtual data centers have the VLANs that are required for creating the data interfaces for the Intercloud Fabric Router (CSR).
Installing and Configuring an Intercloud Fabric Router (CSR) Workflow
Installing and configuring an Intercloud Fabric Router (CSR) for Intercloud Fabric includes the following steps:
| Step 1 | For Amazon Web Services, discover an Intercloud Fabric Router (CSR) on Amazon Web Services using Intercloud Fabric. |
| Step 2 | For all other
providers, create an
Intercloud Fabric Router (CSR) service from
Intercloud Fabric or enable an
Intercloud Fabric Router (CSR) service after you create an
Intercloud Fabric cloud.
|
| Step 3 | Instantiate an
Intercloud Fabric Router (CSR) from
Cisco Prime Network Services
Controller
using
Intercloud Fabric, which includes the following tasks:
|
| Step 4 | (Optional)Configure NAT and Port Address Translation (PAT) policies. |
| Step 5 | (Optional)Configure VPN.
See Configuring VPN for Intercloud Fabric Router (CSR) Workflow. |
| Step 6 | Verify
installation of the
Intercloud Fabric Router (CSR) using
Cisco Prime Network Services
Controller.
See Verifying the Installation of the Intercloud Fabric Router (CSR). |
Creating an Intercloud Fabric Cloud
Use this procedure to create an Intercloud Fabric cloud.
-
You have created a provider account.
-
You know the credentials for the cloud provider.
-
You have created a tunnel network with the name icfTunnelNet. This applies only to Intercloud Fabric in OpenStack environments.
-
You have installed the infrastructure components.
-
You have configured the port profiles for a distributed virtual switch (such as Cisco Nexus 1000V, VMware vSwitch, VMware VDS, or Microsoft Hyper-V switch) in the private cloud.
-
You have created Intercloud Fabric infrastructure policies, such as a MAC pool, tunnel profile, and static IP pool.
-
Optionally, you have configured a native VLAN to use for your VM network in vCenter. A native VLAN is useful in flat network environments when only one VLAN is present.
-
If you are using a Cisco Nexus 1000V switch in the private cloud, you have added the switch to Intercloud Fabric. See Adding a Network Element.
-
You have configured the Intercloud Fabric Extender trunk port profile for the VLANs that will be extended into the cloud.
-
You have uploaded the services bundle to manage services. Choose to upload the services bundle.

Note
You do not need to upload the services bundle to manage the Intercloud Fabric Router (Integrated).
-
You have the required configurations and hardware to enable a dedicated network connection between the public cloud and AWS VPC using AWS Direct Connect.

Note
Direct Connect can only be enabled for AWS VPC.

Note
When Direct Connect is enabled, the provider's private IP address that is assigned to the Intercloud Fabric Switch will be used by PNSC and the Intercloud Fabric Extender to establish a tunnel.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 3 | Click the
IcfCloud tab and then click
Setup.
The Cloud Setup wizard appears. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 4 | Complete the
following fields for
Account
Credentials:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 5 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 6 | Complete the
following fields for
Configuration Details:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 7 | Click Next. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 8 | Complete the
following fields for
Secure
Cloud Extension:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 9 | Click
Next.
The Summary window provides a summary of the Intercloud Fabric cloud. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 10 | Click Submit. | ||||||||||||||||||||||||||||||||||||||||||||||||||||
| Step 11 | To view the
task status:
| ||||||||||||||||||||||||||||||||||||||||||||||||||||
Managing Services
Use this procedure to manage services after creating an Intercloud Fabric cloud.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||
| Step 3 | Select the
Intercloud Fabric
cloud and click
Manage
Services.
The Manage Services window appears. | ||||||||||||||||||
| Step 4 | Complete the
following fields for
Manage
Services:
| ||||||||||||||||||
| Step 5 | Click Submit. |
Instantiating an Intercloud Fabric Router (CSR)
Use this procedure to instantiate an Intercloud Fabric Router (CSR) by using the Add Edge Router wizard. This wizard lets you create the management interface as well as the cloud interface.
![]() Note | You must configure one management interface and at least two cloud interfaces. Because there is only one trunk between the devices, you need cloud interfaces for multiple VLANs. |
About Network Address Translation and Port Address Translation Policies
Cisco Prime Network Services Controller supports Network Address Translation (NAT) and Port Address Translation (PAT) policies for controlling address translation in the deployed network. These policies support both static and dynamic translation of IP addresses and ports.
-
NAT policy—Can contain multiple rules, which are evaluated sequentially until a match is found.
-
NAT policy set—Group of NAT policies that can be associated with an edge security profile. When the profile is applied, the NAT policies are applied only to ingress traffic.
-
PAT policy—Supports source dynamic and destination static interface PAT on edge firewalls.
![]() Note | If you do not configure NAT and PAT policies correctly for cloud providers, incoming traffic does not reach the provider. |
-
When working with Amazon clouds, use the AWS console to perform the following tasks:
-
When configuring dynamic NAT and adding a rule: -
Use the Prefix source condition.
-
Choose a source IP address pool that contains the cloud private IP addresses. The source IP address pool should contain the IP address of the cloud VMs that can be reached by incoming traffic.
-
If you configure dynamic NAT when working with Cisco Intercloud Services – V, return network traffic does not reach the Intercloud Fabric Router (CSR) cloud VM.
-
-
When configuring dynamic PAT and adding a rule: -
To configure dynamic NAT for ICFPP providers, see Configuring Dynamic NAT Policies for ICFPP Providers.
- Configuring Network Address Translation and Port Address Translation Policies
- Configuring Dynamic NAT Policies for ICFPP Providers
Configuring Network Address Translation and Port Address Translation Policies
Use this procedure to configure NAT and PAT policies.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||
| Step 3 | In the
Infrastructure tab, click the
Launch
PNSC button.
The PNSC GUI appears. | ||||||||||||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > NAT > NAT Policies. | ||||||||||||||||||||||
| Step 5 | In the General tab, click Add NAT Policy. | ||||||||||||||||||||||
| Step 6 | Complete the
following fields for
Add NAT
Policy:
| ||||||||||||||||||||||
| Step 7 | Complete the
following fields for
Add NAT
Policy Rule:
| ||||||||||||||||||||||
| Step 8 | (Optional)Complete the
following fields for
Add
Object Group:
| ||||||||||||||||||||||
| Step 9 | Click OK. | ||||||||||||||||||||||
| Step 10 | To apply the profile, choose . | ||||||||||||||||||||||
| Step 11 | Select the Intercloud Fabric Router (CSR) and then choose Edit Edge Router. | ||||||||||||||||||||||
| Step 12 | In the Edit Edge Router wizard, click Select in the Device Service Profile field. | ||||||||||||||||||||||
| Step 13 | In the Select Router Device Profile dialog box, choose the device profile. | ||||||||||||||||||||||
| Step 14 | Click OK and then Apply. | ||||||||||||||||||||||
Configuring Dynamic NAT Policies for ICFPP Providers
Use this procedure to configure dynamic NAT policies for ICFPP providers.
| Step 1 | Configure
dynamic NAT policy using PNSC.
See Configuring Network Address Translation and Port Address Translation Policies. |
| Step 2 | Log in to the
Cloud Services Router (CSR) CLI and remove the NAT rule.
Example: router#no ip nat pool nat-rule1-R1 192.168.3.239 192.168.3.239 netmask 255.255.255.252
router#no ip nat inside source list natacl-nat-rule1-R1 pool nat-rule1-R1
|
| Step 3 | Manually
configure the configuration for dynamic NAT from the CSR CLI.
Example: router#ip nat inside source list natacl-nat-rule1-R1 interface gigabitEthernet 8 |
| Step 4 | Verify the
configuration.
Example: router#show running-config | section ip nat ip nat inside ip nat outside ip nat inside source list natacl-nat-rule1-R1 interface GigabitEthernet8 overload |
| Step 5 | Save the
configuration.
Example: router#copy running-config startup-config |
About Configuring VPN for Intercloud Fabric Router (CSR)
-
To configure VPN for an Intercloud Fabric Router (CSR), you must configure the device service profile and the interface service profile. You must also create a public cloud interface for the tunnel.
-
Only one instance of crypto map-based IPSec site-to-site VPN is supported and it is created using the public cloud interface.
-
If you configure more than one IPSec site-to-site VPN, use the tunnel interfaces that are created on the public cloud interface.
-
If you configure a VPN using a tunnel interface, the crypto map policy cannot include any rules.
-
If you configure a VPN using a tunnel interface, you must add static route entries to reach the remote subnetworks through that tunnel interface.
- Configuring VPN for Intercloud Fabric Router (CSR) Workflow
- Configuring a VPN Device Policy
- Creating an Interface Service Profile
- Applying the Device Profile and Interface Service Profile to the Router
Configuring VPN for Intercloud Fabric Router (CSR) Workflow
Configuring VPN for an Intercloud Fabric Router (CSR) includes the following steps:
| Step 1 | Create a VPN
device policy:
See Configuring a VPN Device Policy. |
| Step 2 | Create an
interface service profile:
See Creating an Interface Service Profile. |
| Step 3 | Apply the device
policy and interface service profile to the
Intercloud Fabric Router
(CSR).
See Applying the Device Profile and Interface Service Profile to the Router. |
Configuring a VPN Device Policy
A VPN device policy enables you to specify VPN global settings, such as:
Use this procedure to configure VPN policies.
Ensure that you have created the following items:
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||||||||||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > VPN > VPN Device Policies. | ||||||||||||||||||||||||||||
| Step 5 | In the General tab, click Add VPN Device Policy. | ||||||||||||||||||||||||||||
| Step 6 | Complete the
following fields for
Add VPN
Device Policy:
| ||||||||||||||||||||||||||||
| Step 7 | In the IKE
Settings tab, complete the following fields for
Add VPN
Device Policy:
| ||||||||||||||||||||||||||||
| Step 8 | In the IPsec
Settings tab, complete the following fields for
Add VPN
Device Policy:
| ||||||||||||||||||||||||||||
| Step 9 | Click OK. |
Creating an Internet Key Exchange (IKE) Policy
The Internet Key Exchange (IKE) protocol is a hybrid protocol that implements Oakley and SKEME key exchanges inside the Internet Security Association and Key Management Protocol (ISAKMP) framework. Although the initial IKE implementation used the IPsec protocol, IKE can now be used with other protocols. IKE provides authentication of IPsec peers, negotiates IPsec keys, and negotiates the IPsec Security Associations (SAs).
Use this procedure to configure an IKE policy.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||
| Step 2 | Choose . | ||||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > VPN > IKE Policies. | ||||||||||||
| Step 5 | In the General tab, click Add IKE Policy. | ||||||||||||
| Step 6 | Complete the
following fields for
Add IKE
Policy:
| ||||||||||||
| Step 7 | Click
Add IKE
V1 Policy.
You must configure either an IKE V1 or IKE V2 policy. | ||||||||||||
| Step 8 | To configure an
IKE V1 policy, provide the following information and click
OK:
| ||||||||||||
| Step 9 | To configure
an IKE V2 policy, provide the following information and click
OK:
|
Creating a Peer Authentication Policy
A peer authentication policy defines the method used to authenticate a peer. Use this procedure to create a peer authentication policy.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||||||||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > VPN > Peer Authentication Policies. | ||||||||||||||||||||||||||
| Step 5 | In the General tab, click Add Peer Authentication Policy. | ||||||||||||||||||||||||||
| Step 6 | Complete the
following fields for
Add Peer
Authentication Policy:
| ||||||||||||||||||||||||||
| Step 7 | Click Add Policy to Authenticate Peer. | ||||||||||||||||||||||||||
| Step 8 | Complete the
following fields for
Add
Policy to Authenticate Peer:
| ||||||||||||||||||||||||||
| Step 9 | Click OK. | ||||||||||||||||||||||||||
Creating an Interface Service Profile
A profile is a collection of policies. By creating a profile with policies that you select, and then applying that profile to multiple objects, such as routers, you can ensure that those objects have consistent policies.
Interface policy sets enable you to group multiple policies, such as a crypto map policy and an IPsec policy, for inclusion in a router service profile. Use this procedure to create an interface service profile.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Edge Router > Interface Service Profiles. | ||||||||||||||||||
| Step 5 | In the General tab, click Add Router Interface Profile. | ||||||||||||||||||
| Step 6 | Complete the
following fields for
Add
Router Interface Profile:
| ||||||||||||||||||
| Step 7 | Complete the
following fields for
Add
Interface Policy Set:
| ||||||||||||||||||
| Step 8 | In the Domain
Settings tab, complete the following fields for
Add
Interface Policy Set:
| ||||||||||||||||||
| Step 9 | Click OK. | ||||||||||||||||||
Creating a Crypto Map Policy
A crypto map policy includes the following:
-
Rules for source and destination conditions.
-
IP Security (IPsec) options, including an IPsec policy.
-
Internet Key Exchange (IKE) options, including a peer device.
Crypto map policies are applied to interfaces by being included in interface policy sets. Use this procedure to create a crypto map policy.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||||||||
| Step 2 | Choose . | ||||||||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > VPN > Crypto Map Policies. | ||||||||||||||||
| Step 5 | In the General tab, click Add Crypto Map Policy. | ||||||||||||||||
| Step 6 | Complete the
following fields for
Add
Crypto Map Policy:
| ||||||||||||||||
| Step 7 | Complete the
following fields for
Add
Rule and click
OK:
| ||||||||||||||||
| Step 8 | In the
IPsec Settings tab, complete the following
fields for
Add
Crypto Map Policy:
| ||||||||||||||||
| Step 9 | In the
Other Settings tab, complete the following
fields for
Add
Crypto Map Policy and click
OK:
|
Creating an IPsec Policy
IPsec policies define the IPsec policy objects used to create a secure IPsec tunnel for a VPN. Use this procedure to create an IPsec policy.
| Step 1 | Log in to Intercloud Fabric. | ||||||||||
| Step 2 | Choose . | ||||||||||
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. | ||||||||||
| Step 4 | Choose Policy Management > Service Policies > root > Policies > VPN> Ipsec Policies. | ||||||||||
| Step 5 | In the General tab, click Add IPsec Policy. | ||||||||||
| Step 6 | Complete the
following fields for
Add IPsec
Policy:
| ||||||||||
| Step 7 | Complete the
following fields for
Add IPsec
IKEv1 Proposal and click
OK:
| ||||||||||
| Step 8 | Complete the
following fields for
Add
IPsec IKEv2 Proposal and click
OK:
|
Applying the Device Profile and Interface Service Profile to the Router
After you have created a device profile and an interface service profile, you can apply them to the Intercloud Fabric Router (CSR).
| Step 1 | Log in to Intercloud Fabric. |
| Step 2 | Choose . |
| Step 3 | In the
Infrastructure tab, click
Launch
PNSC.
The PNSC GUI appears. |
| Step 4 | To apply the device profile, choose . |
| Step 5 | Select the Intercloud Fabric Router (CSR) and then choose Edit Edge Router. |
| Step 6 | In the Edit Edge Router wizard, click Select in the Device Service Profile field. |
| Step 7 | Select the device profile in the Select Router Device Profile window. |
| Step 8 | Click OK and then Apply. |
| Step 9 | In the Edit Edge Router wizard, click the Network Interfaces tab. |
| Step 10 | Select the interface and then click Select in the Interface Service Profile field. |
| Step 11 | Select the interface service profile in the Select Router Interface Profile window. |
| Step 12 | Click OK and then Apply. |
Verifying the Installation of the Intercloud Fabric Router (CSR)
Use this procedure to verify the installation of the Intercloud Fabric Router (CSR).
Feedback