- Preface
- New and Changed Information
- Overview of Application Containers
- Implementing Gateway
- Implementing Load Balancing
- Setting Up a Fenced Virtual Container
- Setting Up a Virtual Secure Gateway Application Container
- Setting Up a Fabric Container
- Setting Up a Cisco Application Policy Infrastructure Controller Container
- Managing Application Containers
- Self Service Management Options
Setting Up a
Virtual Secure Gateway Application Container
This chapter contains the following sections:
- Virtual Secure Gateway Application Containers
- Virtual Security Gateway Application Container Prerequisites
- Virtual Security Gateway Application Container Limitations
- VSG Application Container Creation Process
Virtual Secure Gateway Application Containers
Cisco Virtual Secure Gateway (VSG) container type is used to provide enhanced security in virtual environments. You can use Cisco UCS Director to configure a Prime Network Services Controller (PNSC) in addition to its internal firewall (Cisco Virtual Security Gateway), which is then integrated into an application container.
Cisco VSG is a virtual firewall appliance that provides trusted access to virtual data center and cloud environments. Cisco VSG enables a broad set of multi-tenant workloads that have varied security profiles to share a common compute infrastructure in a virtual data center private cloud or in a public cloud. By associating one or more virtual machines (VMs) into distinct trust zones, Cisco VSG ensures that access to trust zones is controlled and monitored through established security policies.
Cisco VSG provides the following benefits:
-
Trusted Multi-tenant Access—Granular, zone-based control and monitoring with context-aware security policies applied in a multi-tenant (scale-out) environment to strengthen regulatory compliance and simplify audits. Security policies are organized into security profile templates to simplify their management and deployment across many Cisco VSGs.
-
Dynamic operation—On-demand provisioning of security templates and trust zones during VM instantiation and mobility-transparent enforcement and monitoring as live migration of VMs occur across different physical servers.
-
Non-disruptive administration—Administrative segregation across security and server teams while enhancing collaboration, eliminating administrative errors, and simplifying audits.
Cisco VSG does the following:
-
Enhances compliance with industry regulations.
-
Simplifies audit processes in virtualized environments.
- Reduces cost by securely deploying a broad set of virtualized workloads across multiple tenants on a shared compute infrastructure, whether in virtual data centers or private/public cloud computing environments.
Virtual Security Gateway Application Container Prerequisites
The following is the prerequisite for the VSG Container configuration:
Virtual Security Gateway Application Container Limitations
VSG Application Container Creation Process
Adding a PNSC Account
PNSC is a virtual appliance, based on Red Hat Enterprise Linux, that provides centralized device and security policy management of Cisco virtual services. Designed for multiple-tenant operation, the PNSC provides seamless, scalable, and automation-centric management for virtualized data center and cloud environments. The PNSC essentially provides the security component (firewall) to your VSG and application container, and separates the VMs from each other. The PNSC enables the centralized management of Cisco virtual services to be performed by an administrator through Cisco UCS Director.
![]() Note | PNSCs are not tied to any specific pod. |
Viewing PNSC Reports
After creating a PNSC account, you can view related reports using Cisco UCS Director.
The following reports are available under the menu.
Integrating a VSG into an Application Container
You can use Cisco UCS Director to configure a PNSC in addition to its internal firewall (Cisco Virtual Security Gateway), which is then integrated into an application container.
The integration process consists of several stages:
-
Create a PNSC firewall policy (used to create a container with a PNSC).
- Create a virtual infrastructure policy. This policy defines which virtual account to use and what type of containers you want to provision.
- Create an application container template. This template uses the virtual infrastructure policy, computing policy, storage policy, and network policy as inputs into the template.
- Uploading OVA Files
- Creating a PNSC Firewall Policy
- Creating a Virtual Infrastructure Policy
- Creating an Application Template for a VSG
Uploading OVA Files
Cisco UCS Director allows an administrator, a group administrator, or an end user to upload OVA files to a predefined storage location.
![]() Note | Group administrators and end users are the only types with privileges to upload OVA files. |
Ensure that you have the proper access rights.
| Step 1 | Choose . | ||||||||||
| Step 2 | On the Integration page, click User OVF Management. | ||||||||||
| Step 3 | Click Upload File. | ||||||||||
| Step 4 | On the Upload File screen, complete the following fields:
| ||||||||||
| Step 5 | Click Submit. |
Creating a PNSC Firewall Policy
You use a firewall policy to enforce network traffic on a Cisco VSG. The Cisco VSG is the internal firewall used as part of PNSC. A key component of the Cisco VSG is the policy engine. The policy engine uses the policy as a configuration that filters the network traffic that is received on the Cisco VSG.
![]() Note | The PNSC firewall policy supports both standalone and high availability (HA) modes. |
| Step 1 | Choose . | ||||||||||||||||||||||||||||||||||||||
| Step 2 | Expand PNSC accounts listed under Multi-Domain Managers. | ||||||||||||||||||||||||||||||||||||||
| Step 3 | Click PNSC account for which you want to create a firewall policy. | ||||||||||||||||||||||||||||||||||||||
| Step 4 | Click PNSC Firewall Policies. | ||||||||||||||||||||||||||||||||||||||
| Step 5 | Click Add. | ||||||||||||||||||||||||||||||||||||||
| Step 6 | On the Create Firewall Policy screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||||
| Step 7 | Click Next. | ||||||||||||||||||||||||||||||||||||||
| Step 8 | Expand PNSC Zones and click Add (+) to create a zone. | ||||||||||||||||||||||||||||||||||||||
| Step 9 | On the Add Entry to PNSC Zones screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||||
| Step 10 | Click Submit. | ||||||||||||||||||||||||||||||||||||||
| Step 11 | Click Next. | ||||||||||||||||||||||||||||||||||||||
| Step 12 | Expand PNSC ACL Rules and click Add (+) to create a PNSC ACL rule entry. | ||||||||||||||||||||||||||||||||||||||
| Step 13 | On the Add Entry to PNSC ACL Rules screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||||
| Step 14 | Click Submit. | ||||||||||||||||||||||||||||||||||||||
| Step 15 | Click Next. | ||||||||||||||||||||||||||||||||||||||
| Step 16 | On the PNSC-VSG Configuration screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||||
| Step 17 | Click Submit. | ||||||||||||||||||||||||||||||||||||||
| Step 18 | Click OK. | ||||||||||||||||||||||||||||||||||||||
Creating a Virtual Infrastructure Policy
The virtual infrastructure policy defines which VM to use and what type of container you want to provision. This policy also defines which PNSC account you want to tie to this particular account.
![]() Note | Any gateway-related Linux based VM image parameters can be added to this policy. |
| Step 1 | Choose . | ||||||||||
| Step 2 | On the Application Containers page, click Virtual Infrastructure Policies. | ||||||||||
| Step 3 | Click Add Policy (+). | ||||||||||
| Step 4 | On the Create a virtual infrastructure policy screen, complete the following fields:
| ||||||||||
| Step 5 | Click Next. | ||||||||||
| Step 6 | On the Virtual Infrastructure Policy - PNSC Information screen, complete the following fields:
| ||||||||||
| Step 7 | Click Next. | ||||||||||
| Step 8 | On the Virtual Infrastructure Policy - Fencing Gateway screen, complete the following fields:
| ||||||||||
| Step 9 | Click Next. The Virtual Infrastructure Policy - Summary screen appears, displaying your current settings. | ||||||||||
| Step 10 | Click Submit. | ||||||||||
Creating an Application Template for a VSG
| Step 1 | Choose . | ||||||||||||||||||||||||||||||||||||
| Step 2 | On the Application Containers page, click Application Container Templates. | ||||||||||||||||||||||||||||||||||||
| Step 3 | Click Add Template. The Add Application Container Template page appears. Complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 4 | Click Next. The Application Container Template - Select a Virtual Infrastructure policy screen appears. In this screen, you choose the cloud on which the application container is deployed. Complete the following field:
| ||||||||||||||||||||||||||||||||||||
| Step 5 | Click Next. The Application Container: Template - Internal Networks screen appears.
| ||||||||||||||||||||||||||||||||||||
| Step 6 | Click Add (+) icon to add a network. The Add Entry to Networks screen appears. Complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 7 | Click
Submit.
Next, you can add and configure the gateway VM that will be provisioned in the application container. | ||||||||||||||||||||||||||||||||||||
| Step 8 | Click OK. | ||||||||||||||||||||||||||||||||||||
| Step 9 | Click Next. The Application Conatiner Template - VMs screen appears. | ||||||||||||||||||||||||||||||||||||
| Step 10 | Click Add (+) to add a VM. Complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 11 | (Optional)
Click
Add
(+) to add a new (multiple) VM network interface. Complete the
following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 12 | Click Next. | ||||||||||||||||||||||||||||||||||||
| Step 13 | Click Ok. The Application Container Template - External Gateway Security Configuration screen appears. You can specify the security configuration components, such as port mapping and outbound access control lists (ACLs). | ||||||||||||||||||||||||||||||||||||
| Step 14 | Click Add (+) to add a port mapping. Complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 15 | Click Submit. | ||||||||||||||||||||||||||||||||||||
| Step 16 | Click OK. | ||||||||||||||||||||||||||||||||||||
| Step 17 | Click Add (+) icon to add an Outbound ACL, in the Application Container Template - External Gateway Security Configuration screen. Complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 18 | Click Submit. | ||||||||||||||||||||||||||||||||||||
| Step 19 | Click OK. | ||||||||||||||||||||||||||||||||||||
| Step 20 | Click Next. | ||||||||||||||||||||||||||||||||||||
| Step 21 | On the Application Container Template - Deployment Policies screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 22 | Click Next. | ||||||||||||||||||||||||||||||||||||
| Step 23 | On the Application Container Template - Options screen, complete the following fields:
| ||||||||||||||||||||||||||||||||||||
| Step 24 | Click Next. | ||||||||||||||||||||||||||||||||||||
| Step 25 | Choose a workflow to setup the container. | ||||||||||||||||||||||||||||||||||||
| Step 26 | Expand the workflow list and select a workflow (for example, Workflow Id 431 Fenced Container Setup - VSG).
| ||||||||||||||||||||||||||||||||||||
| Step 27 | Click Select. | ||||||||||||||||||||||||||||||||||||
| Step 28 | Click Submit. |

Feedback