Cisco Secure Access Help

PDF

Cisco Secure Access Help

Deploy VAs in VMware

Want to summarize with AI?

Log in

Describes Deploy VAs in VMware in Cisco Secure Access and explains Prerequisites and Configure Authentication for the Virtual Appliances. It summarizes the behavior, configuration context, and operational considerations presented throughout the topic.


Deploy Cisco Secure Access Virtual Appliances (VAs) in VMware.

Note
You must deploy at least two Virtual Appliances (VAs) in a Secure Access Site. It is critical that these VAs are not cloned or copied in any way. Configure and set up each VA manually.

Prerequisites

  • Full Admin user role. For more information, see Manage Accounts.
  • For information about the network requirements for deploying VAs, see Prerequisites for Virtual Appliances.
  • Basic knowledge of VMware ESXi. For more information, see the VMware documentation.

Configure Authentication for the Virtual Appliances

Before you can download the Virtual Appliance images in Secure Access, you must configure your Secure Access API keys for the Virtual Appliances in your organization. Secure Access enables the Download Components button only after the API keys for the VAs are configured. For more information, see Configure Authentication for Virtual Appliances.


Procedure for Deploying VAs in VMware


Step 1 – Download OVF Template

Procedure

  1. Navigate to Connect > DNS Forwarders and click Download Components.


    DNS Forwarders section with an option to download components
  2. Click Download next to VA for VMWare ESXi.

    Download Components section with an option to download a virtual machine

    Umbrella generates and downloads a .tar file unique to your deployment.

    This tar file includes:

    • an .ovf template containing the virtual hard disks that need to be deployed on VMware

    • a signature file

    • a Cisco public certificate to validate the signature

    • a readme file

  3. Extract the contents of the tar file using the command tar –xvf <tar filename> -C <Destination folder>.

    To verify the integrity of the downloaded file, validate the signature by following the instructions provided in the readme file. On successful signature validation, you should see a message saying “Verified OK."


Step 2 – Deploy OVF Template

Procedure

  1. Log into your VMware vSphere client and select the File tab.

  2. Click Deploy OVF Template, choosing the downloaded .ova template.


    File tab with an option to select the OVF template
  3. Follow the deployment wizard prompts, but be sure to follow these steps:

    • For the source, browse to the .ova file you just downloaded.
    • Specify a unique name and location for your VA.

    Browsing to the download folder to select the .ova file and specify the name and location for the virtual appliance
  4. Select the disks appropriate to your environment. It is recommended to select Thin Provision for the disk format, but it is not mandatory.


    Deploy OVF Template screen with an option to select the Thin Provision disk format
  5. Select or map a network.


    Deploy OVF Template screen with an option to map a network
  6. Click Finish.

    The system begins to deploy the VA. During the deployment, subsequent prompts update you about the status of the deployment.


Step 3 – Deploy a Second Virtual Appliance

While the first VA is deploying, repeat the previous two steps to configure your second VA.

Note
Two VAs are required per Umbrella site. It is critical that these VAs are not cloned or copied in any way. Each VA must be set up and configured manually.

Deploying a second virtual appliance

Step 4 – Power on the Virtual Machines