Installing and Configuring Intercloud Fabric Router (CSR)

This chapter contains the following sections:

About the Intercloud Fabric Router (CSR)

The Intercloud Fabric Router (CSR) provides a cloud-based virtual router that is deployed on a virtual machine (VM) instance on x86 server hardware. The Intercloud Fabric Router (CSR) is a virtual platform that provides selected Cisco IOS XE security and switching features on a virtualization platform.

The Intercloud Fabric Router (CSR) acts as an edge device in Intercloud Fabric and provides the following functionality:

  • Provides inter-VLAN routing for the virtual machines in the provider cloud.

  • Serves as the NAT gateway for the virtual machines in the provider cloud.

  • Provides VPN routing for the virtual machines in the provider cloud.

  • Enables you to extend the default gateway from the private cloud to the provider cloud.

Figure 1. Cisco Intercloud Fabric Router (CSR) Topology

The Intercloud Fabric Router (CSR) can also be deployed on Amazon Web Services (AWS) for private and provider cloud solutions. See the Cisco CSR 1000V Series Cloud Services Router Deployment Guide for Amazon Web Services for information on deploying the Intercloud Fabric Router AMI.

Guidelines and Limitations

  • The Intercloud Fabric Router (CSR) is not supported on Microsoft Azure.

  • The Intercloud Fabric Router (CSR) version 3.16.1 is required for Intercloud Fabric with VCD.

  • The Intercloud Fabric Router (CSR) version 3.14.01 is required for Intercloud Fabric with AWS.

  • The Intercloud Fabric Router (CSR) version 3.14.1.S is required for Intercloud Fabric with Cisco Intercloud Services – V.

  • Network Address Translation (NAT) functionality for the Intercloud Fabric Router (CSR) is available only if there is a default VPC in the Amazon Web Services (AWS) account.

  • If you configure dynamic NAT when working with Cisco Intercloud Services – V, return network traffic does not reach the Intercloud Fabric Router (CSR) cloud VM.

  • During deployment of the Intercloud Fabric Router (CSR) in the provider cloud, inter-VLAN traffic might stop working between the private cloud and provider cloud virtual machines for VLANs that are not extended to the provider cloud. You must add routing for private cloud VLANs that are not extended on a data interface that is configured as the default gateway. If a data interface is not configured as a default gateway, add one with one of the private cloud VLANs that is not extended. Then, add routing for the remaining VLANs under that interface.
  • If you delete an Intercloud Fabric Router (CSR) instance and immediately try to recreate either the same instance or another instance of the Intercloud Fabric Router (CSR) in the same Intercloud Fabric cloud, you might receive the error can’t create; object already exists. We recommend that you wait for 10 minutes before you create a new instance of the Intercloud Fabric Router (CSR) in the Intercloud Fabric cloud.

  • After you perform any lifecycle operations using the PNSC GUI, you must refresh the GUI to view the status of the operation.

Prerequisites

  • You have an account in the provider cloud.

  • For Amazon Web Services, accept the terms and conditions as follows before launching the Intercloud Fabric Router (CSR) AMI from Intercloud Fabric:
    • In the Amazon Web Services Marketplace, search for Cisco CSR.

    • Accept the terms for Cisco CSR release 3.14.01.S Bring Your Own License (BYOL).

  • When you provision the virtual data centers in the Intercloud Fabric Router (CSR), ensure that the network policies associated with the virtual data centers have the VLANs that are required for creating the data interfaces for the Intercloud Fabric Router (CSR).

Installing and Configuring an Intercloud Fabric Router (CSR) Workflow

Installing and configuring an Intercloud Fabric Router (CSR) for Intercloud Fabric includes the following steps:

Procedure
    Step 1   For Amazon Web Services, discover an Intercloud Fabric Router (CSR) on Amazon Web Services using Intercloud Fabric.

    See Creating an Intercloud Fabric Cloud.

    Step 2   For all other providers, create an Intercloud Fabric Router (CSR) service from Intercloud Fabric or enable an Intercloud Fabric Router (CSR) service after you create an Intercloud Fabric cloud.
    Step 3   Instantiate an Intercloud Fabric Router (CSR) from Cisco Prime Network Services Controller using Intercloud Fabric, which includes the following tasks:
    1. Create a management interface using Cisco Prime Network Services Controller.

      When you instantiate an Intercloud Fabric Router (CSR), the Add Edge Router wizard in Prime Network Services Controller lets you create the management interface.

    2. Create cloud interfaces using Cisco Prime Network Services Controller.

      When you instantiate an Intercloud Fabric Router (CSR), the Add Edge Router wizard in Prime Network Services Controller lets you create the cloud interface.

    3. Create a cloud public interface using Prime Network Services Controller. A public cloud interface is required for Network Address Translation (NAT) and VPN configuration.

    See Instantiating an Intercloud Fabric Router (CSR).

    Step 4   (Optional)Configure NAT and Port Address Translation (PAT) policies.
    Step 5   (Optional)Configure VPN.

    See Configuring VPN for Intercloud Fabric Router (CSR) Workflow.

    Step 6   Verify installation of the Intercloud Fabric Router (CSR) using Cisco Prime Network Services Controller.

    See Verifying the Installation of the Intercloud Fabric Router (CSR).


    Creating an Intercloud Fabric Cloud

    Use this procedure to create an Intercloud Fabric cloud.

    Before You Begin
    • You have created a provider account.

    • You know the credentials for the cloud provider.

    • You have created a tunnel network with the name icfTunnelNet. This applies only to Intercloud Fabric in OpenStack environments.

    • You have installed the infrastructure components.

    • You have configured the port profiles for a distributed virtual switch (such as Cisco Nexus 1000V, VMware vSwitch, VMware VDS, or Microsoft Hyper-V switch) in the private cloud.

    • You have created Intercloud Fabric infrastructure policies, such as a MAC pool, tunnel profile, and static IP pool.

    • Optionally, you have configured a native VLAN to use for your VM network in vCenter. A native VLAN is useful in flat network environments when only one VLAN is present.

    • If you are using a Cisco Nexus 1000V switch in the private cloud, you have added the switch to Intercloud Fabric. See Adding a Network Element.

    • You have configured the Intercloud Fabric Extender trunk port profile for the VLANs that will be extended into the cloud.

    • You have uploaded the services bundle to manage services. Choose Intercloud > Infrastructure > Upload Services Bundle to upload the services bundle.


      Note


      You do not need to upload the services bundle to manage the Intercloud Fabric Router (Integrated).


    • You have the required configurations and hardware to enable a dedicated network connection between the public cloud and AWS VPC using AWS Direct Connect.


      Note


      Direct Connect can only be enabled for AWS VPC.



      Note


      When Direct Connect is enabled, the provider's private IP address that is assigned to the Intercloud Fabric Switch will be used by PNSC and the Intercloud Fabric Extender to establish a tunnel.


    Procedure
      Step 1   Log in to Intercloud Fabric.
      Step 2   Choose Intercloud > IcfCloud.
      Step 3   Click the IcfCloud tab and then click Setup.

      The Cloud Setup wizard appears.

      Step 4   Complete the following fields for Account Credentials:
      Note    Many of the fields in the following table are displayed only if you create a new provider account. In addition, the fields that are displayed are specific to the provider.

      Name Description

      Cloud Name

      The name of the virtual account that you are creating in Intercloud Fabric Director. This name can contain from 1 to 16 alphanumeric characters, including hyphens, underscores, periods, and colons. You cannot change this name after the object has been saved.

      Cloud Type

      Choose the provider cloud type.

      Sub Type

      Choose the sub type (Classic or VPC) for Amazon Web Services.

      Provider Account

      Choose an existing provider or create a new provider account.

      Based on the selected provider account, the appropriate fields are displayed.

      Provider Account Name

      The name of the provider account.

      Access ID

      The alphanumeric text string that identifies the account owner.

      Access Key

      The unique key for the account.

      URI

      The unique resource identifier for the account.

      Username

      The username for the provider cloud in the format username@tenant-name.

      Password

      The password.

      Validate Credentials

      Click to validate credentials. You must validate the credentials to populate the remaining fields.

      Enable Direct Connect

      Check the Enable Direct Connect check box to enable the Intercloud Fabric administrator to create an Intercloud Fabric cloud by establishing a dedicated network connection between public clouds and a configured Amazon Web Services VPC.

      Location

      Choose the location of the provider cloud.

      Provider VPC

      Choose the VPC for the provider cloud.

      Provider Private Subnet

      Enter the private subnet for the provider cloud.

      Step 5   Click Next.
      Step 6   Complete the following fields for Configuration Details:

      Name

      Description

      Network Configuration

      Check the Advanced check box to create new polices or click Next to proceed with the default values.

      MAC Pool

      Choose a default or existing MAC pool, or create a new MAC pool.

      See Adding a MAC Address Pool to create a new MAC pool.

      Tunnel Profile

      Choose a default or existing tunnel profile, or create a new tunnel profile.

      See Configuring a Tunnel Profile to create a new tunnel profile.

      IP Group

      Choose a default or existing IP group, or create a new IP group.

      See Adding an IP Group to create a new IP group.

      Private Subnet

      Choose a default or existing private subnet, or create a new private subnet.

      See Adding a Private Subnet to create a new private subnet.

      Services

      ICF Firewall (VSG)

      Check the ICF Firewall check box to create an Intercloud Fabric Firewall (VSG) template.

      Selecting this option results in a service template being made available for this cloud. To configure the service, use PNSC.

      See Installing Intercloud Fabric Firewall.

      ICF Router (Integrated)

      Supported on Azure clouds only.

      Check the ICF Router (Integrated) check box to create an ICF Router (Integrated) instance on the associated Intercloud Fabric cloud instance.

      After the ICF Router (Integrated) is instantiated, you can configure it in PNSC as described in Installing and Configuring Intercloud Fabric Router (Integrated) Workflow.

      ICF Router (CSR)

      Check the ICF Router (CSR) check box to create an Intercloud Fabric Router (CSR) template.

      Selecting this option results in a service template being made available for this cloud. To configure the service, use PNSC.

      See Installing and Configuring Intercloud Fabric Router (CSR).

      Cloud Services Router (CSR) Management VLAN

      Enter the management VLAN ID for the Intercloud Fabric Router (CSR).

      This VLAN is used to manage the Intercloud Fabric Router (CSR).

      To access this property, you must check the ICF Router (CSR) check box.

      Step 7   Click Next.
      Step 8   Complete the following fields for Secure Cloud Extension:
      Note   

      Not all fields apply when you create Intercloud Fabric clouds in Microsoft environments.

      Name Description

      Intercloud Extender Network

      Complete the following fields for the Intercloud Fabric Extender.

      VM Manager

      Choose a VM manager for the Intercloud Fabric Extender.

      Datacenter

      Choose a data center in which to deploy the Intercloud Fabric Extender.

      Data Trunk Network

      Choose the trunk interface on the Intercloud Fabric Extender for data traffic.

      Management Interface Network

      Choose the management interface on the Intercloud Fabric Extender for data traffic.

      Management VLAN

      Choose the VLAN for the management interface. This VLAN must match the VLAN specified in the management IP pool policy.

      Management IP Pool Policy

      Choose the IP pool policy for the management interface or create a new IP pool policy.

      See Creating a Static IP Pool Policy to create a new IP pool policy.

      Separate Mgmt and Tunnel Interface

      Check this check box to use different VLANs for the management interface and tunnel interface. If this check box is not checked, the same VLAN is used for the tunnel interface and the management interface by default.

      To access this property, you must check the Advanced check box.

      Tunnel Interface Network

      Choose the tunnel interface on the Intercloud Fabric Extender for data traffic.

      This drop-down list displays only if you check the Separate Mgmt and Tunnel Interface check box.

      Tunnel VLAN

      Choose the VLAN for the tunnel interface.

      This field displays only if you check the Separate Mgmt and Tunnel Interface check box.

      Tunnel IP Pool Policy

      Choose the IP pool policy for the tunnel interface or create a new IP pool policy.

      See Creating a Static IP Pool Policy to create a new IP pool policy.

      This drop-down list displays only if you check the Separate Mgmt and Tunnel Interface check box.

      Intercloud Extender Placement/Association

      ICX

      (Microsoft environments only) Select the host for the Intercloud Fabric Extender.

      To specify a data store for a Primary Intercloud Extender and Secondary Intercloud Extender, check the Advanced check box and then check the High Availability check box.

      Host

      Select the host for the Intercloud Fabric Extender.

      For high availability, check the Advanced check box and then check the High-Availability check box to specify the host for the Primary Intercloud Extender and Secondary Intercloud Extender.

      Datastore

      Select the data store for the Intercloud Fabric Extender.

      For high availability, check the Advanced check box and then check the High-Availability check box to specify the data store for the Primary Intercloud Extender and Secondary Intercloud Extender.

      To access this property, you must check the Advanced check box.

      Intercloud Switch Network

      Complete the following fields for the Intercloud Fabric Switch in the cloud.

      To access this property, you must check the Advanced check box.

      Management VLAN

      Choose the VLAN for the management interface.

      Management IP Pool Policy

      Choose the IP policy for the management interface or create a new IP pool policy.

      See Creating a Static IP Pool Policy to create a new IP pool policy.

      Native VLAN

      (Optional) Specify a native VLAN to use for your VM network in vCenter. A native VLAN is useful in flat network environments when only one VLAN is present.

      VSG Service Interface

      To access this property, you must check the ICF Firewall (VSG) check box.

      This service interface is created on the Intercloud Fabric Switch and is used to communicate with the Intercloud Fabric Firewall data interface.

      VLAN

      Choose the VLAN for the service interface. The VLAN is used to communicate between the Intercloud Fabric Switch and the Intercloud Fabric Firewall and can be a private VLAN, completely isolated from other VLANs.

      IP Pool Policy

      Choose the IP pool policy for the service interface or create a new IP pool policy.

      VSG Management

      To access this property, you must check the ICF Firewall (VSG) check box.

      VSG Management VLAN

      Choose the VLAN for the management interface. This VLAN is used to manage the Intercloud Fabric Firewall.

      Step 9   Click Next.

      The Summary window provides a summary of the Intercloud Fabric cloud.

      Step 10   Click Submit.
      Step 11   To view the task status:
      1. In the IcfCloud tab, locate the service request number of the task.
      2. Choose Organizations > Service Requests.
      3. Click the Service Request tab.
      4. Locate the service request number or enter the service request number in the search field.
      5. Click View Details to view detailed information, such as workflow status, logs, and input information for the service request.

      Managing Services

      Use this procedure to manage services after creating an Intercloud Fabric cloud.

      Before You Begin
      • You have created an Intercloud Fabric cloud.

      • You have uploaded the services bundle to manage services. Choose Intercloud > Infrastructure > Upload Services Bundle to upload the services bundle.


        Note


        You do not need to upload the services bundle to manage Intercloud Fabric Router (Integrated).


      Procedure
        Step 1   Log in to Intercloud Fabric.
        Step 2   Choose Intercloud > IcfCloud.
        Step 3   Select the Intercloud Fabric cloud and click Manage Services.

        The Manage Services window appears.

        Step 4   Complete the following fields for Manage Services:

        Name

        Description

        ICF Firewall

        Check the ICF Firewall check box to create an Intercloud Fabric Firewall (VSG) template.

        Service Interface VLAN

        Enter the VLAN for the service interface. The VLAN is used to communicate between the Intercloud Fabric Switch and the Intercloud Fabric Firewall and can be a private VLAN, completely isolated from other VLANs.

        This service interface is created on the Intercloud Fabric Switch and is used to communicate with the Intercloud Fabric Firewall data interface.

        This field displays only if you check the ICF Firewall check box.

        Service Interface IP Pool Policy

        Choose the IP pool policy for the service interface or create a new IP pool policy.

        See Creating a Static IP Pool Policy to create a new IP pool policy.

        This field displays only if you check the ICF Firewall check box.

        VSG Management VLAN

        Enter the VLAN for the management interface. This VLAN is used to manage the Intercloud Fabric Firewall.

        This field displays only if you check the ICF Firewall check box.

        Note   

        The firewall management port profile is automatically created when you select the Intercloud Fabric Firewall service while creating an Intercloud Fabric cloud. The Intercloud Fabric cloud name is added as a prefix to the name of the port profile and the VLAN ID is added as a suffix to the name of the port profile; for example, icf-amz1_VSG_Management_72.

        ICF Router (CSR)

        Check the ICF Router (CSR) check box to create an Intercloud Fabric Router (CSR) template.

        CSR Management VLAN

        Enter the management VLAN ID for the Intercloud Fabric Router (CSR).

        This field displays only if you check the ICF Router (CSR) check box.

        ICF Router (Integrated)

        Check the ICF Router (Integrated) check box to create an ICF Router (Integrated).

        Step 5   Click Submit.

        Instantiating an Intercloud Fabric Router (CSR)

        Use this procedure to instantiate an Intercloud Fabric Router (CSR) by using the Add Edge Router wizard. This wizard lets you create the management interface as well as the cloud interface.


        Note


        You must configure one management interface and at least two cloud interfaces. Because there is only one trunk between the devices, you need cloud interfaces for multiple VLANs.
        Before You Begin
        • You have installed the infrastructure components.

        • You have created an Intercloud Fabric cloud.

        • You have created VDCs that include the VLANs for CSR cloud interfaces.

        Procedure
          Step 1   Log in to Intercloud Fabric.
          Step 2   Choose Intercloud > Infrastructure.
          Step 3   In the Infrastructure tab, click Launch PNSC.

          The PNSC GUI appears.

          Step 4   Choose Tenant Management Management > Root > Create tenant.
          Step 5   Choose Resource Management > Managed Resources > tenant.
          Step 6   From the Network Services Actions drop-down list, choose Add Edge Router.

          The Add Edge Router wizard appears.

          Step 7   Complete the following fields for Properties:
          Name Description

          Name

          The name of the edge router.

          Description

          The description of the edge router.

          Device Profile

          Choose an existing or default device profile for the edge router.

          Device Service Profile

          Choose an existing or default device service profile for the edge router.

          Host Name

          The hostname.

          VM Access

          User Name

          Enter the username.

          Password

          Enter the password.

          Confirm Password

          Confirm the password.

          Step 8   Click Next.
          Step 9   Complete the following fields for Service Device:
          Name Description

          Instantiate in Cloud

          Select to instantiate the cloud edge router.

          Select

          Select the cloud image to use to instantiate the cloud edge router.

          Compute

          CPU Cores

          Four CPU cores are allocated for each interface.

          Memory

          4000 MB of memory is allocated for each interface.

          Step 10   Click Next.
          Step 11   Select the Intercloud Fabric cloud and then click Next.
          Step 12   Click Add Interfaces to create a management interface.
          Step 13   Complete the following fields for Add Interfaces:
          Name Description

          Name

          The name of the management interface.

          Description

          The description of the management interface.

          Type

          Choose Management.

          Mode

          Choose the mode.

          Port Profile

          Choose the port profile with the name using the format icf-link-name*, such as ICS_Trunk_Tunnel.

          Category

          Choose Tagged Interface.

          VLAN

          Choose the VLAN for the interface. The VLAN ID must be included in the port profile you chose.

          Sub Management Information

          Sub Management IP

          The IP address used for communication between PNSC and the Intercloud Fabric Router (CSR).

          Port

          The submanagement port of the interface.

          IP Address

          The IP address of the interface.

          IP Subnet Mask

          The subnet mask for the IP address.

          Gateway

          The gateway IP address.

          Step 14   Click Next.
          Step 15   Click Add Interfaces to create a cloud interface. Create at least two cloud interfaces.
          Step 16   Complete the following fields for Add Interfaces:
          Name Description

          Name

          The name of the cloud interface.

          Description

          The description of the cloud interface.

          Type

          Choose Ethernet.

          Admin State

          Choose the administrative state of the subinterface.

          Interface Service Profile

          Click Select to choose an interface service profile or add the default interface service profile.

          Mode

          Trunk is selected by default.

          Port Profile

          Choose the trunk port profile to which the interface belongs.

          Category

          Choose Tagged Interface.

          VLAN

          Enter the VLAN for the interface. The VLAN ID must be included in the port profile you chose.

          Use As Default Gateway

          Check the Use As Default Gateway check box to enable the Default Gateway Extension feature, also known as Address Resolution Protocol (ARP) filtering.

          DHCP

          Check the Enable check box to use DHCP instead of ARP filtering.

          IP Address

          The primary IP address and, optionally, a secondary IP address if HA is enabled.

          Subnet Mask

          The subnet mask for the IP address.

          Extend Default Gateway

          To configure ARP filtering, check the check box.

          Enterprise Gateway

          The enterprise gateway IP address.

          Step 17   Click Add Interfaces to create a public cloud interface.

          A public cloud interface is required for NAT and VPN configuration. If the VPN is based on crypto map policies, you must create a public cloud interface. In this case, the interface service profile with the VPN configuration is associated with the public cloud interface.

          Step 18   Complete the following fields for Add Interfaces:
          Name Description

          Name

          The name of the public cloud interface.

          Description

          The description of the public cloud interface.

          Type

          Choose public cloud.

          Admin State

          Choose the administrative state of the interface.

          Interface Service Profile

          Click Select to choose an interface service profile or add the default interface service profile.

          Step 19   Click Add Interfaces to create a tunnel interface.

          A tunnel interface is required only for VPN configuration. If the VPN is supported using Virtual Tunnel Interface (VTI), you must create a tunnel interface for each VPN. In this case, the interface service profile with the VPN configuration is associated with the tunnel interface.

          Step 20   Complete the following fields for Add Interfaces:
          Name Description

          Name

          The name of the tunnel interface.

          Description

          The description of the tunnel interface.

          Type

          Choose tunnel.

          Source Interface

          Choose the source interface

          Admin State

          Choose the administrative state of the interface.

          Interface Service Profile

          Click Select to choose an interface service profile or add the default interface service profile.

          Primary IP Address

          Enter the IP address for the interface.

          Primary Subnet Mask

          Enter the subnet mask for the interface.

          Step 21   Click Next to view the summary and then click Finish.

          About Network Address Translation and Port Address Translation Policies

          Cisco Prime Network Services Controller supports Network Address Translation (NAT) and Port Address Translation (PAT) policies for controlling address translation in the deployed network. These policies support both static and dynamic translation of IP addresses and ports.

          Cisco Prime Network Services Controller lets you configure the following policy items:
          • NAT policy—Can contain multiple rules, which are evaluated sequentially until a match is found.

          • NAT policy set—Group of NAT policies that can be associated with an edge security profile. When the profile is applied, the NAT policies are applied only to ingress traffic.

          • PAT policy—Supports source dynamic and destination static interface PAT on edge firewalls.

          The following guidelines apply when configuring NAT and PAT policies for cloud providers:

          Note


          If you do not configure NAT and PAT policies correctly for cloud providers, incoming traffic does not reach the provider.


          • When working with Amazon clouds, use the AWS console to perform the following tasks:

            • Configure secondary AWS private IP addresses in the Intercloud Fabric Router (CSR).

            • Rent elastic IP addresses to bind to the secondary IP addresses of the Intercloud Fabric Router (CSR).

          • When configuring dynamic NAT and adding a rule:
            • Use the Prefix source condition.

            • Choose a source IP address pool that contains the cloud private IP addresses. The source IP address pool should contain the IP address of the cloud VMs that can be reached by incoming traffic.

            • If you configure dynamic NAT when working with Cisco Intercloud Services – V, return network traffic does not reach the Intercloud Fabric Router (CSR) cloud VM.

          • When configuring dynamic PAT and adding a rule:
            • Use the Prefix source condition.

            • Choose a source IP PAT pool that contains the ports to be accessible on the cloud provider.

          • To configure dynamic NAT for ICFPP providers, see Configuring Dynamic NAT Policies for ICFPP Providers.

          Configuring Network Address Translation and Port Address Translation Policies

          Use this procedure to configure NAT and PAT policies.

          Procedure
            Step 1   Log in to Intercloud Fabric.
            Step 2   Choose Intercloud > Infrastructure.
            Step 3   In the Infrastructure tab, click the Launch PNSC button.

            The PNSC GUI appears.

            Step 4   Choose Policy Management > Service Policies > root > Policies > NAT > NAT Policies.
            Step 5   In the General tab, click Add NAT Policy.
            Step 6   Complete the following fields for Add NAT Policy:
            Name Description

            Name

            The name of the policy.

            Description

            The description of the edge router policy.

            Admin State

            The administrative state of the policy.

            Add Rule

            Click Add Rule to add a rule to the policy.

            Step 7   Complete the following fields for Add NAT Policy Rule:
            Field Description

            Name

            The name of the rule.

            Description

            The description of the rule.

            Original Packet Match Conditions

            Source Match Conditions

            Source attributes that must be matched for the current policy to apply.

            To add a new condition, click Add Rule Condition.

            Available source attributes are IP Address and Network Port.

            Destination Match Conditions

            Destination attributes that must be matched for the current policy to apply.

            To add a new condition, click Add Rule Condition.

            Available destination attributes are IP Address and Network Port.

            Protocol

            Specify the protocols to which the rule applies:
            • To apply the rule to any protocol, check the Any check box.

            • To apply the rule to specific protocols:

              1. Uncheck the Any check box.

              2. From the Operator drop-down list, choose a qualifier: Equal, Not equal, Member, Not Member, In range, or Not in range.

              3. In the Value fields, specify the protocol, object group, or range.

            NAT Action Table

            NAT Action

            The required translation option: Static or Dynamic.

            Translated Address

            Identify a translated address pool for each original packet match condition from the following options:
            • Resolved Source IP Pool

            • Resolved Source Port Pool

            • Resolved Source IP PAT Pool

            • Resolved Destination IP Pool

            • Resolved Destination Port Pool

            For example, if you specify a source IP address match condition, you must identify a Source IP Pool object group. Similarly, a destination network port match requires a Destination Port Pool object group.

            The Source IP PAT Pool option is available only if you choose dynamic translation.

            Click Add Object Group to add object groups for the translation actions. See Step 8.

            NAT Options

            Check and uncheck the check boxes as required:
            • Enable Bidirectional—Check this check box for connections to be initiated bidirectionally; that is, both to and from the host. Available only for static address translation.

            • Enable DNS—Check this check box to enable DNS for NAT.

            • Enable Round Robin IP—Check this check box to allocate IP addresses on a round-robin basis. Available only for dynamic address translation.

            • Disable Proxy ARP—Check this check box to disable proxy ARP. Available only for static address translation.

            Step 8   (Optional)Complete the following fields for Add Object Group:
            Field Description

            Name

            Object group name.

            The name can be between 2 and 32 identifier characters. You can use alphanumeric characters including hyphens, underscores, periods, and colons. You cannot change this name after it is saved.

            Description

            Brief description of the object group.

            The description can be between 1 and 256 identifier characters. You can use alphanumeric characters including hyphens, underscores, periods, and colons.

            Attribute Type

            Available attribute types: Network, VM, User Defined, vZone, and Time Range.

            You must configure an attribute type and name to add an object group expression.

            Attribute Name

            Available attribute names for the selected attribute type.

            Expression Table

            Add Object Group Expression

            Click to add an object group expression.

            Operator

            Operator for the selected expression.

            Value

            Value for the selected expression.

            Step 9   Click OK.
            Step 10   To apply the profile, choose Resource Management > Managed Resources > tenant.
            Step 11   Select the Intercloud Fabric Router (CSR) and then choose Edit Edge Router.
            Step 12   In the Edit Edge Router wizard, click Select in the Device Service Profile field.
            Step 13   In the Select Router Device Profile dialog box, choose the device profile.
            Step 14   Click OK and then Apply.

            Configuring Dynamic NAT Policies for ICFPP Providers

            Use this procedure to configure dynamic NAT policies for ICFPP providers.

            Procedure
              Step 1   Configure dynamic NAT policy using PNSC.

              See Configuring Network Address Translation and Port Address Translation Policies.

              Step 2   Log in to the Cloud Services Router (CSR) CLI and remove the NAT rule.

              Example:
              router#no  ip nat pool nat-rule1-R1 192.168.3.239 192.168.3.239 netmask 255.255.255.252
                   router#no ip nat inside source list natacl-nat-rule1-R1 pool nat-rule1-R1
              
              Step 3   Manually configure the configuration for dynamic NAT from the CSR CLI.

              Example:
              router#ip nat inside source list natacl-nat-rule1-R1 interface gigabitEthernet 8
              
              Step 4   Verify the configuration.

              Example:
              router#show running-config | section ip nat
              ip nat inside
              ip nat outside
              ip nat inside source list natacl-nat-rule1-R1 interface GigabitEthernet8 overload
              
              Step 5   Save the configuration.

              Example:
              router#copy running-config startup-config
              

              About Configuring VPN for Intercloud Fabric Router (CSR)

              • To configure VPN for an Intercloud Fabric Router (CSR), you must configure the device service profile and the interface service profile. You must also create a public cloud interface for the tunnel.

              • Only one instance of crypto map-based IPSec site-to-site VPN is supported and it is created using the public cloud interface.

              • If you configure more than one IPSec site-to-site VPN, use the tunnel interfaces that are created on the public cloud interface.

              • If you configure a VPN using a tunnel interface, the crypto map policy cannot include any rules.

              • If you configure a VPN using a tunnel interface, you must add static route entries to reach the remote subnetworks through that tunnel interface.

              Configuring VPN for Intercloud Fabric Router (CSR) Workflow

              Configuring VPN for an Intercloud Fabric Router (CSR) includes the following steps:

              Procedure
                Step 1   Create a VPN device policy:

                See Configuring a VPN Device Policy.

                1. Create an IKE policy.

                  See Creating an Internet Key Exchange (IKE) Policy.

                2. Create a peer authentication policy.

                  See Creating a Peer Authentication Policy.

                Step 2   Create an interface service profile:

                See Creating an Interface Service Profile.

                1. Create a crypto map policy.

                  See Creating a Crypto Map Policy.

                2. Create an IPsec policy.

                  See Creating an IPsec Policy.

                Step 3   Apply the device policy and interface service profile to the Intercloud Fabric Router (CSR).

                See Applying the Device Profile and Interface Service Profile to the Router.


                Configuring a VPN Device Policy

                A VPN device policy enables you to specify VPN global settings, such as:

                • IKE policy

                • IKE global settings

                • IPsec global settings

                • Peer authentication policy

                Use this procedure to configure VPN policies.

                Before You Begin

                Ensure that you have created the following items:

                • A public cloud interface

                • An IKE policy

                • A peer authentication policy

                Procedure
                  Step 1   Log in to Intercloud Fabric.
                  Step 2   Choose Intercloud > Infrastructure.
                  Step 3   In the Infrastructure tab, click Launch PNSC.

                  The PNSC GUI appears.

                  Step 4   Choose Policy Management > Service Policies > root > Policies > VPN > VPN Device Policies.
                  Step 5   In the General tab, click Add VPN Device Policy.
                  Step 6   Complete the following fields for Add VPN Device Policy:
                  Name Description

                  Name

                  The name of the policy.

                  Description

                  The description of the policy.

                  IKE Policy

                  Choose an existing policy from the drop-down list, or click Add IKE Policy to add a new policy.

                  Peer Authentication Policy

                  Choose an existing policy from the drop-down list, or click Add Peer Authentication Policy to add a new policy.

                  Step 7   In the IKE Settings tab, complete the following fields for Add VPN Device Policy:
                  Name Description

                  Enable IPsec over TCP

                  Whether or not IPsec traffic is allowed over TCP. If IPsec over TCP is enabled, this method takes precedence over all other connection methods.

                  Send Disconnect Notification

                  Whether or not clients are notified that sessions will be disconnected.

                  Allow Inbound Aggressive Mode

                  Whether or not inbound aggressive mode is permitted.

                  Wait for Termination before Rebooting check box

                  Whether or not a reboot can occur only when all active sessions have terminated voluntarily.

                  Threshold for Cookie Challenge (0-100 Percent)

                  Percentage of the maximum number of allowed Security Associations (SAs) that can be in-negotiation (open) before cookie challenges are issued for future SA negotiations.

                  Negotiation Threshold for Maximum SAs (0-100 Percent)

                  Percentage of the maximum number of allowed SAs that can be in-negotiation before additional connections are denied.

                  The default value is 100 percent.

                  IKE Identity

                  Phase 2 identification method:

                  • Automatic—Determines ISAKMP negotiation by connection type:

                    • IP address for a preshared key.

                    • Cert DN for certificate authentication.

                  • IP Address—IP address of the host exchanging ISAKMP identity information.

                  • Hostname—Fully qualified domain name of the host exchanging ISAKMP identity information.

                  • Key ID—String used by the remote peer to look up the preshared key.

                  Key for IKE Identity

                  The key to use for IKE identity if the IKE identification method is Key ID.

                  NAT Traversal

                  Whether or not IPsec peers can establish a connection through a NAT device.

                  Keep-Alive Time for NAT Traversal

                  Length of time (in hours, minutes, and seconds) that a tunnel can exist with no activity before the device sends keepalive messages to the peer.

                  Values range from 10 to 3600 seconds, with a default of 20 seconds.

                  IKEv2 IPsec Maximum Security Associations

                  Whether or not the total number of IKE V2 SAs on the node can be set.

                  Maximum Number of SA

                  Maximum number of SA connections allowed.

                  IKEv1 over TCP Port

                  1. Click Add IKE V1 Over TCP Port to add a new port.

                  2. In the Port field, enter the TCP port to use for IKE V1.

                  Step 8   In the IPsec Settings tab, complete the following fields for Add VPN Device Policy:
                  Name Description

                  Anti Replay

                  Whether or not SA anti-replay is enabled.

                  Anti Replay Window Size

                  Window size to use to track and prevent duplication of packets. Using a larger window size allows the decryptor to track more packets.

                  SA Lifetime

                  Length of time (in days, hours, minutes, and seconds) that an SA can live before expiring.

                  SA Lifetime Volume (KB)

                  Length of time (in days, hours, minutes, and seconds) that an SA can live before expiring.

                  Step 9   Click OK.

                  Creating an Internet Key Exchange (IKE) Policy

                  The Internet Key Exchange (IKE) protocol is a hybrid protocol that implements Oakley and SKEME key exchanges inside the Internet Security Association and Key Management Protocol (ISAKMP) framework. Although the initial IKE implementation used the IPsec protocol, IKE can now be used with other protocols. IKE provides authentication of IPsec peers, negotiates IPsec keys, and negotiates the IPsec Security Associations (SAs).

                  Use this procedure to configure an IKE policy.

                  Procedure
                    Step 1   Log in to Intercloud Fabric.
                    Step 2   Choose Intercloud > Infrastructure.
                    Step 3   In the Infrastructure tab, click Launch PNSC.

                    The PNSC GUI appears.

                    Step 4   Choose Policy Management > Service Policies > root > Policies > VPN > IKE Policies.
                    Step 5   In the General tab, click Add IKE Policy.
                    Step 6   Complete the following fields for Add IKE Policy:
                    Name Description

                    Name

                    The name of the policy.

                    Description

                    The description of the policy.

                    Step 7   Click Add IKE V1 Policy.

                    You must configure either an IKE V1 or IKE V2 policy.

                    Step 8   To configure an IKE V1 policy, provide the following information and click OK:
                    Name Description

                    DH Group

                    Diffie-Hellman group: Group 1, Group 2, or Group 5.

                    Encryption

                    Encryption method: 3DES, AES, AES-192, AES-256, or DES.

                    Hash

                    Hash algorithm: MD5 or SHA.

                    Authentication

                    Authentication method is Preshared key.

                    SA Lifetime

                    Length of time (in days, hours, minutes, and seconds) that an SA lives before expiring.

                    Step 9   To configure an IKE V2 policy, provide the following information and click OK:
                    Name Description

                    DH Group

                    Diffie-Hellman group: Group 1, Group 2, Group 5, or Group 14.

                    Encryption

                    Encryption method: 3DES, AES, AES-192, AES-256, or DES.

                    Hash

                    Hash integrity algorithm: MD5, SHA, SHA256, SHA384, or SHA512.

                    Pseudo Random Function Hash

                    Pseudo-random function (PRF) has algorithm: MD5, SHA, SHA256, SHA384, or SHA512.

                    SA Lifetime

                    Length of time (in days, hours, minutes, and seconds) that an SA lives before expiring.


                    Creating a Peer Authentication Policy

                    A peer authentication policy defines the method used to authenticate a peer. Use this procedure to create a peer authentication policy.

                    Procedure
                      Step 1   Log in to Intercloud Fabric.
                      Step 2   Choose Intercloud > Infrastructure.
                      Step 3   In the Infrastructure tab, click Launch PNSC.

                      The PNSC GUI appears.

                      Step 4   Choose Policy Management > Service Policies > root > Policies > VPN > Peer Authentication Policies.
                      Step 5   In the General tab, click Add Peer Authentication Policy.
                      Step 6   Complete the following fields for Add Peer Authentication Policy:
                      Name Description

                      Name

                      The name of the policy.

                      Description

                      The description of the policy.

                      Step 7   Click Add Policy to Authenticate Peer.
                      Step 8   Complete the following fields for Add Policy to Authenticate Peer:
                      Name Description

                      Peer IP Address

                      Unique IP address or hostname of the peer.

                      IKEv1 Area

                      Local

                      Preshared key.

                      Confirm

                      Preshared key for confirmation.

                      Set

                      Whether or not the preshared key has been set and is properly configured (read-only).

                      IKEv2 Area

                      Local

                      Local preshared key.

                      Confirm

                      Local preshared key for confirmation.

                      Set

                      Whether or not the local preshared key has been set and is properly configured (read-only).

                      Remote

                      Remote preshared key.

                      Confirm

                      Remote preshared key for confirmation.

                      Set

                      Whether or not the remote preshared key has been set and is properly configured (read-only).

                      Step 9   Click OK.

                      Creating an Interface Service Profile

                      A profile is a collection of policies. By creating a profile with policies that you select, and then applying that profile to multiple objects, such as routers, you can ensure that those objects have consistent policies.

                      Interface policy sets enable you to group multiple policies, such as a crypto map policy and an IPsec policy, for inclusion in a router service profile. Use this procedure to create an interface service profile.

                      Procedure
                        Step 1   Log in to Intercloud Fabric.
                        Step 2   Choose Intercloud > Infrastructure.
                        Step 3   In the Infrastructure tab, click Launch PNSC.

                        The PNSC GUI appears.

                        Step 4   Choose Policy Management > Service Policies > root > Edge Router > Interface Service Profiles.
                        Step 5   In the General tab, click Add Router Interface Profile.
                        Step 6   Complete the following fields for Add Router Interface Profile:
                        Name Description

                        Name

                        The name of the profile.

                        Description

                        The description of the profile.

                        VPN Interface Policy Set

                        Choose an existing policy from the drop-down list, or click Add Interface Policy Set to add a new policy set.

                        Step 7   Complete the following fields for Add Interface Policy Set:
                        Name Description

                        Name

                        The name of the policy set.

                        Description

                        The description of the policy set.

                        Admin State

                        Administrative state of the policy set: enabled or disabled.

                        Policies Area

                        Add Crypto Map Policy

                        Click to add a new policy.

                        See Creating a Crypto Map Policy.

                        Available

                        Policies that can be assigned to the policy set.

                        Use the arrows between the columns to move policies between columns.

                        Assigned

                        Policies assigned to the policy set.

                        Up and down arrows

                        Changes the priority of the selected policies.

                        Arrange the policies from highest to lowest priority, with the highest priority policy at the top of the list.

                        Step 8   In the Domain Settings tab, complete the following fields for Add Interface Policy Set:
                        Name Description

                        Enable IKE

                        Check the appropriate check box to specify IKE V1 or IKE V2.

                        Enable IPsec Pre-fragmentation

                        Check the check box to fragment packets before encryption. Pre-fragmentation minimizes post-fragmentation (fragmentation after encryption) and the resulting reassembly before decryption, thereby improving performance.

                        Admin StateDo Not Fragment

                        Available only if the Enable IPsec Pre-fragmentation check box is checked.

                        Choose the action to take with the Don't Fragment (DF) bit in the encapsulated header:

                        • Clear

                        • Copy

                        • Set

                        Step 9   Click OK.

                        Creating a Crypto Map Policy

                        A crypto map policy includes the following:

                        • Rules for source and destination conditions.

                        • IP Security (IPsec) options, including an IPsec policy.

                        • Internet Key Exchange (IKE) options, including a peer device.

                        Crypto map policies are applied to interfaces by being included in interface policy sets. Use this procedure to create a crypto map policy.

                        Procedure
                          Step 1   Log in to Intercloud Fabric.
                          Step 2   Choose Intercloud > Infrastructure.
                          Step 3   In the Infrastructure tab, click Launch PNSC.

                          The PNSC GUI appears.

                          Step 4   Choose Policy Management > Service Policies > root > Policies > VPN > Crypto Map Policies.
                          Step 5   In the General tab, click Add Crypto Map Policy.
                          Step 6   Complete the following fields for Add Crypto Map Policy:
                          Name Description

                          Name

                          The name of the policy.

                          Description

                          The description of the policy.

                          Admin State

                          The administrative state of the policy: enabled or disabled.

                          Add Rule

                          Click Add Rule to add a new rule to the current policy.

                          Step 7   Complete the following fields for Add Rule and click OK:
                          Field Description

                          Name

                          Rule name.

                          Description

                          Brief rule description.

                          VPN Action

                          Action to take based on this rule: Permit or Deny.

                          Protocol

                          Protocols to examine for this rule:
                          • To examine all protocols, check the Any check box.

                          • To examine specific protocols:

                            1. Uncheck the Any check box.

                            2. From the Operator drop-down list, choose a qualifier: Equal, Not equal, Member, Not Member, In range, or Not in range.

                            3. In the Value fields, specify the protocol, object group, or range.

                          EtherType

                          Encapsulated protocols to examine for this rule:
                          • To examine all encapsulated protocols, check the Any check box.

                          • To examine specific encapsulated protocols:

                            1. Uncheck the Any check box.

                            2. From the Operator drop-down list, choose a qualifier: Greater Than, Less Than, Equal, Not equal, Member, Not Member, In range, or Not in range.

                            3. In the Value fields, specify the hexadecimal value, object group, or hexadecimal range.

                          Source Conditions

                          Source attributes that must be matched for the rule to apply.

                          To add a new condition, click Add Rule Condition.

                          Available source attributes are IP Address and Network Port.

                          Destination Conditions

                          Destination attributes that must be matched for the rule to apply.

                          To add a new condition, click Add Rule Condition.

                          Available destination attributes are IP Address and Network Port.

                          Step 8   In the IPsec Settings tab, complete the following fields for Add Crypto Map Policy:
                          Field Description

                          SA Lifetime

                          Length of time (in days, hours, minutes, and seconds) that a security association (SA) lives before expiring.

                          SA Lifetime Traffic (KB)

                          Volume of traffic, in kilobytes, that can pass between IPsec peers using a given SA before that association expires.

                          Enable Perfect Forwarding Secrecy

                          Whether or not Perfect Forward Secrecy (PFS) is enabled.

                          PFS is a cryptographic characteristic associated with a derived shared-secret value. With PFS, if one key is compromised, previous and subsequent keys are not compromised, because subsequent keys are not derived from previous keys.

                          Diffie-Hellman Group

                          Available if PFS is enabled.

                          Choose the Diffie-Hellman (DH) group for this policy:
                          • Group 1—The 768-bit DH group.

                          • Group 2—The 1024-bit DH group.

                          • Group 5—The 1536-bit DH group.

                          IPsec Policies

                          The IPsec policy that applies to the current policy.

                          Choose an existing IPsec policy or click Add IPsec Policy to create a new policy.

                          See Creating an IPsec Policy.

                          Peer Device

                          Choose an existing peer or click Add Peer Device to add a new peer.

                          In the Add Peer Device dialog box, enter the peer device IP address or hostname.

                          Step 9   In the Other Settings tab, complete the following fields for Add Crypto Map Policy and click OK:
                          Field Description

                          Enable NAT Traversal

                          Whether or not IPsec peers can establish a connection through a NAT device.

                          Enable Reverse Route Injection

                          Whether or not static routes are automatically added to the routing table and then announced to neighbors on the private network.

                          Connection Type

                          Connection type for this policy:
                          • Answer-Only—Responds only to inbound IKE connections during the initial proprietary exchange to determine the appropriate peer to which to connect.

                          • Bidirectional—Accepts and originates connections based on this policy.

                          • Originate-Only—Initiates the first proprietary exchange to determine the appropriate peer to which to connect.

                          Negotiation Mode

                          Mode to use for exchanging key information and setting up SAs:
                          • Aggressive Mode—Faster mode, using fewer packets and exchanges, but does not protect the identity of the communicating parties.

                          • Main Mode—Slower mode, using more packets and exchanges, but protects the identities of the communicating parties.

                          DH Group for Aggressive Mode

                          DH group to use when in aggressive mode: Group 1, Group 2, or Group 5.


                          Creating an IPsec Policy

                          IPsec policies define the IPsec policy objects used to create a secure IPsec tunnel for a VPN. Use this procedure to create an IPsec policy.

                          Procedure
                            Step 1   Log in to Intercloud Fabric.
                            Step 2   Choose Intercloud > Infrastructure.
                            Step 3   In the Infrastructure tab, click Launch PNSC.

                            The PNSC GUI appears.

                            Step 4   Choose Policy Management > Service Policies > root > Policies > VPN> Ipsec Policies.
                            Step 5   In the General tab, click Add IPsec Policy.
                            Step 6   Complete the following fields for Add IPsec Policy:
                            Name Description

                            Name

                            The name of the policy.

                            Description

                            The description of the policy.

                            IPsec IKEv1 Proposal

                            Click Add IPsec IKEv1 Proposal to configure an IKE V1 proposal.

                            You must configure either an IKE V1 or IKE V2 proposal for an IPsec policy.

                            IPsec IKEv2 Proposal

                            Click Add IPsec IKEv2 Proposal to configure an IKE V2 proposal.

                            Step 7   Complete the following fields for Add IPsec IKEv1 Proposal and click OK:
                            Field Description

                            Mode

                            Mode in which the IPsec tunnel operates.

                            In Tunnel mode, the IPsec tunnel encapsulates the entire IP packet.

                            ESP Encryption

                            Encapsulating Security Protocol (ESP) encryption method:
                            • 3DES—Encrypts three times according to the Data Encryption Standard (DES) using 56-bit keys.

                            • AES—Encrypts according to the Advanced Encryption Standard (AES) using 128-bit keys.

                            • AES-192—Encrypts according to the AES using 192-bit keys.

                            • AES-256—Encrypts according to the AES using 256-bit keys.

                            • DES—Encrypts according to the DES using 56-bit keys.

                            • Null—Null encryption algorithm. Transform sets defined with ESP-Null provide authentication without encryption; this method is typically used for testing purposes only.

                            ESP Authentication

                            Hash authentication algorithm:
                            • MD5—Produces a 128-bit digest.

                            • Null—Does not perform authentication.

                            • SHA—Produces a 160-bit digest.

                            Step 8   Complete the following fields for Add IPsec IKEv2 Proposal and click OK:
                            Field Description

                            ESP Encryption Algorithm

                            To add an ESP encryption method:
                            1. Click Add ESP Encryption Algorithm.

                            2. From the ESP Encryption drop-down list, choose the encryption method:

                              • 3DES—Encrypts three times according to the Data Encryption Standard (DES) using 56-bit keys.

                              • AES—Encrypts according to the Advanced Encryption Standard (AES) using 128-bit keys.

                              • AES-192—Encrypts according to the AES using 192-bit keys.

                              • AES-256—Encrypts according to the AES using 256-bit keys.

                              • DES—Encrypts according to the DES using 56-bit keys.

                              • Null—Null encryption algorithm. Transform sets defined with ESP-Null provide authentication without encryption; this method is typically used for testing purposes only.

                            Integrity Algorithm

                            To add an integrity algorithm:
                            1. Click Add Integrity Algorithm.

                            2. From the Integrity Algorithm drop-down list, choose the authentication algorithm:

                              • MD5—Produces a 128-bit digest.

                              • Null—Does not perform authentication.

                              • SHA—Produces a 160-bit digest.


                            Applying the Device Profile and Interface Service Profile to the Router

                            After you have created a device profile and an interface service profile, you can apply them to the Intercloud Fabric Router (CSR).

                            Procedure
                              Step 1   Log in to Intercloud Fabric.
                              Step 2   Choose Intercloud > Infrastructure.
                              Step 3   In the Infrastructure tab, click Launch PNSC.

                              The PNSC GUI appears.

                              Step 4   To apply the device profile, choose Resource Management > Managed Resources > tenant.
                              Step 5   Select the Intercloud Fabric Router (CSR) and then choose Edit Edge Router.
                              Step 6   In the Edit Edge Router wizard, click Select in the Device Service Profile field.
                              Step 7   Select the device profile in the Select Router Device Profile window.
                              Step 8   Click OK and then Apply.
                              Step 9   In the Edit Edge Router wizard, click the Network Interfaces tab.
                              Step 10   Select the interface and then click Select in the Interface Service Profile field.
                              Step 11   Select the interface service profile in the Select Router Interface Profile window.
                              Step 12   Click OK and then Apply.

                              Verifying the Installation of the Intercloud Fabric Router (CSR)

                              Use this procedure to verify the installation of the Intercloud Fabric Router (CSR).

                              Procedure
                                Step 1   Log in to the Intercloud Fabric Router (CSR) CLI.
                                Step 2   Enter the following commands:
                                1. show running configuration


                                  Example:
                                  # show running configuration
                                  Building configuration...
                                  
                                  Current configuration : 5052 bytes
                                  !
                                  ! Last configuration change at 19:01:11 UTC Tue Mar 10 2015
                                  !
                                  version 15.5
                                  service timestamps debug datetime msec
                                  no service timestamps log uptime
                                  no platform punt-keepalive disable-kernel-core
                                  platform console auto
                                  !
                                  hostname CSR11
                                  !
                                  boot-start-marker
                                  boot-end-marker
                                  !
                                  !
                                  no logging buffered
                                  no logging console
                                  no logging monitor
                                  !
                                  no aaa new-model
                                  !
                                  ip domain name opsourcecloud.net
                                  !
                                  !
                                  subscriber templating
                                  !
                                  multilink bundle-name authenticated
                                  !
                                  crypto pki trustpoint TP-self-signed-1700464965
                                   enrollment selfsigned
                                   subject-name cn=IOS-Self-Signed-Certificate-1700464965
                                   revocation-check none
                                   rsakeypair TP-self-signed-1700464965
                                  !
                                  !
                                  license udi pid CSR1000V sn 916Z0U0VCZ5
                                  license boot level lite
                                  remote-management
                                    pnsc host 10.3.1.99 local-port 58443 shared-secret AL]\cFcCRZIiYZUaiRcRgbIfOEE\eWAAB
                                  !
                                  username admin privilege 15 secret 5 $1$CX8v$0Io63wbgoLfsjpVQJ7ltn.
                                  !
                                  redundancy
                                  !
                                  !
                                  ip ssh rsa keypair-name ssh-key
                                  ip ssh version 2
                                  ! 
                                  
                                  interface VirtualPortGroup0
                                   ip unnumbered GigabitEthernet1.301
                                   ip mtu 1352
                                  !
                                  interface GigabitEthernet1
                                   description configured by PolicyAgent
                                   no ip address
                                   negotiation auto
                                  !
                                  interface GigabitEthernet1.301
                                   encapsulation dot1Q 301
                                   ip address 10.3.1.39 255.255.0.0
                                   ip mtu 1352
                                  !
                                  interface GigabitEthernet1.311
                                   description configured by PolicyAgent
                                   encapsulation dot1Q 311
                                   ip address 192.168.11.39 255.255.255.0
                                   ip mtu 1352
                                   ip access-group default-ingress in
                                   ip access-group default-egress out
                                  !
                                  interface GigabitEthernet1.312
                                   description configured by PolicyAgent
                                   encapsulation dot1Q 312
                                   ip address 192.168.12.39 255.255.255.0
                                   ip mtu 1352
                                   ip access-group default-ingress in
                                   ip access-group default-egress out
                                  !
                                  !
                                  interface GigabitEthernet8
                                   description configured by PolicyAgent
                                   ip address 10.229.179.12 255.255.255.0
                                   ip mtu 1352
                                   ip access-group default-ingress in
                                   ip access-group default-egress out
                                   negotiation auto
                                  !
                                  !
                                  virtual-service csr_mgmt
                                   vnic gateway VirtualPortGroup0
                                    guest ip address 10.3.1.49
                                   activate
                                  !
                                  ip forward-protocol nd
                                  !
                                  no ip http server
                                  ip http secure-server
                                  ip route 10.3.1.49 255.255.255.255 VirtualPortGroup0
                                  ip route 173.36.216.0 255.255.255.0 10.3.1.1
                                  !
                                  ip access-list extended default-egress
                                  ip access-list extended default-ingress
                                  
                                  no logging trap
                                  !
                                  !
                                  !
                                  control-plane
                                  !
                                  banner exec ^CWARNING: This device is managed by Prime Network Services Controller. 
                                  RESTful API is read only. Changing configuration using CLI is not recommended.^C
                                  banner login ^CWARNING: This device is managed by Prime Network Services Controller. 
                                  RESTful API is read only. Changing configuration using CLI is not recommended.^C
                                  !
                                  line con 0
                                   stopbits 1
                                  line vty 0 4
                                   login local
                                   transport input ssh
                                  !
                                  !
                                  end
                                  
                                  
                                2. show ip interface brief

                                  This command displays the interfaces created for the Intercloud Fabric Router (CSR).



                                  Example:
                                  #show ip int brief
                                  Interface IP-Address OK? Method Status Protocol
                                  GigabitEthernet1 unassigned YES NVRAM up up
                                  GigabitEthernet1.401 10.4.36.209 YES NVRAM up up <---mgmt int
                                  GigabitEthernet1.464 192.168.64.131 YES NVRAM up up <---data interface 1
                                  GigabitEthernet1.465 192.168.65.131 YES NVRAM up up <--- data interface 2
                                  GigabitEthernet2 unassigned YES NVRAM administratively down down
                                  GigabitEthernet3 unassigned YES NVRAM administratively down down
                                  GigabitEthernet4 unassigned YES NVRAM administratively down down
                                  GigabitEthernet5 unassigned YES NVRAM administratively down down
                                  GigabitEthernet6 unassigned YES NVRAM administratively down down
                                  GigabitEthernet7 unassigned YES NVRAM administratively down down
                                  GigabitEthernet8 172.31.31.18 YES DHCP up up <--- public intf
                                  VirtualPortGroup0 10.4.36.209 YES unset up up
                                  
                                  
                                3. show remote-management status

                                  This command displays the virtual service and remote management status.



                                  Example:
                                  #show remote-management status
                                  Remote management release version: 1.5.1
                                  
                                  ----------------------------------------------------------------------
                                  Process Status Uptime # of restarts
                                  ----------------------------------------------------------------------
                                  nginx UP 0Y 0W 1D 0: 5:21 0
                                  climgr UP 0Y 0W 1D 0: 5:21 0
                                  restful_api UP 0Y 0W 1D 0: 5:21 0
                                  fcgicpa UP 0Y 0W 1D 0: 5:12 0
                                  pnscag UP 0Y 0W 1D 0: 5:12 0
                                  pnscdme UP 0Y 0W 1D 0: 5:11 0
                                  ----------------------------------------------------------------------
                                  Feature Status Configuration
                                  ----------------------------------------------------------------------
                                  Restful API Enabled, UP port: 55443
                                  (GET only) autosave-timer: 30 seconds
                                  socket: unix:/usr/local/nginx/csrapi-fcgi.sock;
                                  
                                  PNSC Enabled, UP host: 10.4.36.12
                                  port: 58443
                                  socket: unix:/usr/local/cpa-fcgi.sock;
                                  
                                  Network stats:
                                  eth0: RX packets:43346, TX packets:6
                                  eth1: RX packets:22112, TX packets:20330
                                  
                                  Coredump file(s): lost+found