Step 1 |
enable
|
Enables privileged EXEC mode.
|
Step 2 |
configure
terminal
Device# configure terminal
|
Enters global
configuration mode.
|
Step 3 |
interface
VirtualPortGroup
number
Device(config)# interface VirtualPortGroup 0
|
Configures an
interface and enters interface configuration mode.
- Configure a
VirtualPortGroup interface. This interface is used for management traffic when
the management interface GigabitEthernet0 is not used.
|
Step 4 |
ip
address
ip-address
mask
Device(config-if)# ip address 10.1.1.1 255.255.255.252
|
Sets a primary
IP address for an interface. This interface needs to be routable to the
signature update server and external log server.
|
Step 5 |
exit
|
Exits
interface configuration mode and returns to global configuration mode.
|
Step 6 |
interface
type
number
Device(config)# interface VirtualPortGroup 1
|
Configures
an interface and enters interface configuration mode.
- Configure a
VirtualPortGroup interface.
- This interface is used
for data traffic.
|
Step 7 |
ip
address
ip-address
mask
Device(config-if)# ip address 192.0.2.1 255.255.255.252
|
Sets a
primary IP address for an interface.
- This IP address should
not be routable to the outside network.
- The IP address is
assigned from the recommended 192.0.2.0/30 subnet.
|
Step 8 |
exit
|
Exits
interface configuration mode and returns to global configuration mode.
|
Step 9 |
virtual-service
name
Device(config)# virtual-service UTDIPS
|
Configures a
virtual container service and enters virtual service configuration mode.
- The
name
argument is the logical name that is used to identify the virtual container
service.
|
Step 10 |
profile
profile-name
Device(config-virt-serv)#profile high
Device(config-virt-serv)#profile multi-tenancy
|
(Optional) Configures a resource profile. If you do not configure the resource profile, the virtual service is activated with
its default resource profile. The options are: low, medium, high, and multi-tenancy. (For multi-tenancy mode (Cisco CSR 1000v
only), a profile multi-tenancy command must be configured.)
|
Step 11 |
vnic
gateway
VirtualPortGroup
interface-number
Device(config-virt-serv)# vnic gateway VirtualPortGroup 0
|
Creates a
virtual network interface card (vNIC) gateway interface for the virtual
container service, maps the vNIC gateway interface to the virtual port group,
and enters the virtual-service vNIC configuration mode.
- The interface referenced
in this command must be the one configured in Step 3. This command maps the
interface that is used for management purposes.
|
Step 12 |
guest
ip
address
ip-address
Device(config-virt-serv-vnic)# guest ip address 10.1.1.2
|
(Optional)
Configures a guest vNIC address for the vNIC gateway interface.
-
Note
|
Configure this command only if the
vnic
management
gigabitethernet0
command specified in Step 17 is not configured.
|
|
Step 13 |
exit
Device(config-virt-serv-vnic)# exit
|
Exits
virtual-service vNIC configuration mode and returns to virtual service
configuration mode.
|
Step 14 |
vnic
gateway
VirtualPortGroup
interface-number
Device(config-virt-serv)# vnic gateway VirtualPortGroup 1
|
Creates a
vNIC gateway interface for the virtual container service, maps the vNIC gateway
interface to the virtual port group, and enters the virtual-service vNIC
configuration mode.
- This interface referenced
in this command must be the one configured in Step 6. This command maps the
interface in the virtual container service that is used by Snort for monitoring
the user traffic.
|
Step 15 |
guest
ip
address
ip-address
Device(config-virt-serv-vnic)# guest ip address 192.0.2.2
|
Configures a
guest vNIC address for the vNIC gateway interface.
|
Step 16 |
exit
Device(config-virt-serv-vnic)# exit
|
Exits
virtual-service vNIC configuration mode and returns to virtual service
configuration mode.
|
Step 17 |
vnic
management
GigabitEthernet0
Device(config-virt-serv)# vnic management GigabitEthernet0
|
(Optional)
Configures the GigabitEthernet interface as the vNIC management interface.
-
The management interface must either be a VirtualPortGroup interface or GibagitEthernet0 interface.
-
If you do not configure the vnic management GigabitEthernet0 command, then you must configure the
guest
ip
address command specified in Step 12.
|
Step 18 |
guest
ip
address
ip-address
Device(config-virt-serv-vnic)# guest ip address 209.165.201.1
|
(Optional)
Configures a guest vNIC address for the vNIC management interface and it must
be in the same subnet as the management interface and GigabitEthernet0
configuration.
|
Step 19 |
exit
Device(config-virt-serv-vnic)# exit
|
Exits
virtual-service vNIC configuration mode and returns to virtual service
configuration mode.
|
Step 20 |
activate
Device(config-virt-serv)# activate
|
Activates an
application installed in a virtual container service.
|
Step 21 |
end
Device(config-virt-serv)# end
|
Exits virtual
service configuration mode and returns to privileged EXEC mode.
|