The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Installing Cisco ICFP at a cloud provider site enables you to support a hybrid cloud environment with Cisco Intercloud Fabric for Business. For VMware vCloud Director (VCD) environments, Cisco ICFP includes a built-in VCD adapter that enables Cisco ICFP to integrate with the VCD platform. This VCD-Cisco ICFP integration can be viewed as the infrastructure that binds the enterprise virtualization platform, such as VMware vCenter, to the provider cloud platform, VCD.
The following illustration depicts how Cisco Intercloud Fabric interfaces with the provider VCD platform through Cisco ICFP.
The secure site-to-site tunnel illustrated in the image is created between an Intercloud Fabric Switch (ICS) on the provider cloud and an Intercloud Fabric Extender (ICX) on the private cloud. In addition to providing secure communications between the private and provider clouds, this site-to-site tunnel enables Cisco Intercloud Fabric Secure Extender to integrate with VCD for each tenant network.
Before the ICS and ICX can communicate via the Internet, you must:
Assign a public IP address to the ICS so that the ICX can reach the ICS.
Ensure that the vShield Edge Gateway provides NAT functionality so that the ICS can connect to the Internet.
The following figure shows an example deployment:
A vShield Edge Gateway is an interconnecting appliance that provides many edge network service features, including:
The following figure shows how Organization X connects the Org Network to an external network through a vShield Edge Gateway and directly to vApp networks.
To integrate VCD with Cisco ICFP, you must provision certain infrastructure resources in the target VCD platform. The following table identifies the tasks required to provision these resources:
Step |
Task |
Related Information |
---|---|---|
1. |
Ensure that the following prerequisites are met: |
VMware VCD documentation |
2. |
Create an external network. |
|
3. |
Deploy the vShield Edge Gateway. |
|
4. |
Create an Org VDC network. |
|
5. |
Create a catalog. |
|
6. |
Ensure that NAT and firewall services are configured on the vShield Edge Gateway. |
For additional information on any of these topics, see your VMware documentation.
After you have successfully integrated VCD with Cisco ICFP, you can configure a cloud instance and add a tenant as described in Configuring Cisco ICFP for Cisco Intercloud Fabric.
This procedure describes how to create an external network in a virtual data center (VDC).
You must add a vShield Edge Gateway to integrate the Provider VDC and Org VDC with Cisco ICFP.
Confirm that the following have been configured:
Step 1 | In the VCD GUI, choose . |
Step 2 | In the Organization VDCs table, double-click the Org VDC where the vShield Edge Gateway is to be added. The screen is refreshed with information about the selected VDC. |
Step 3 | Choose the Edge Gateways tab and click Add. The New Edge Gateway wizard opens, guiding you through the configuration process. |
Step 4 | In the Configure Edge Gateway screen, configure the vShield Edge Gateway for connectivity with the external network as follows, and then click Next: |
Step 5 | In the
External
Networks screen, choose the external network that you created in
Creating an External Network
and click
Add. If the external network is not listed, create a
new external network.
|
Step 6 | After the external network is added to the list of networks in the lower portion of the screen, click Next. |
Step 7 | In the Sub-Allocate IP Pools screen, identify the range of IP addresses allocated for each externally-connected interface on the external network, and click Next. |
Step 8 | In the Name and Description screen, enter the edge gateway name and description, and then click Next. |
Step 9 | In the Summary screen, review the information for accuracy and click Finish. |
Use this procedure to create an internal network for the Org VDC.
A catalog enables you to upload images from Cisco ICFP to VCD.
For additional information about creating catalogs and selecting options, see your VMware vCloud Director documentation.
When VCD is integrated with Cisco ICFP, NAT and firewall services are configured automatically, enabling the vShield Edge Gateway to communicate with the external network. This procedure enables you to confirm that NAT and firewall services have been configured on the vShield Edge Gateway as expected.
Step 1 | In the VCD GUI, choose . |
Step 2 | In the Organization VDCs table, double-click the Org VDC where you created the vShield Edge Gateway (Adding a vShield Edge Gateway on an Org VDC). The screen is refreshed with information about the selected VDC. |
Step 3 | In the Edge Gateways tab, right-click the required edge gateway and choose Edge Gateway Services. |
Step 4 | In the Configure
Services dialog box, confirm the following: |
After you have installed Cisco ICFP on a VMware server and launched a Cisco ICFP instance, you can configure Cisco ICFP for use with Cisco Intercloud Fabric.
Confirm the following:
Cisco ICFP has been installed on a VMware server and an instance has been launched.
You know the Cisco ICFP public IP address.