Translate

Total Pageviews

My YouTube Channel

Sunday, 24 March 2019

NSX-T 2.2 Uplink Profile

An uplink profile defines policies for the links
  1. from Hypervisor hosts to NSX-T logical switches or 
  2. from NSX Edge nodes to top-of-rack switches.
The settings defined by uplink profiles might include teaming policies, active/standby links, the transport VLAN ID, and the MTU setting.
Uplink profiles allow you to consistently configure identical capabilities for network adapters across multiple hosts or nodes. Uplink profiles are containers for the properties or capabilities that you want your network adapters to have. Instead of configuring individual properties or capabilities for each network adapter, you can specify the capabilities in uplink profiles, which you can then apply when you create NSX-T transport nodes.
Standby uplinks are not supported with VM/appliance-based NSX Edge. When you install NSX Edge as a virtual appliance, use the default uplink profile. For each uplink profile created for a VM-based NSX Edge, the profile must specify only one active uplink and no standby uplink.

Prerequisites
  1. Each uplink in the uplink profile must correspond to an up and available physical link on your hypervisor host or on the NSX Edge node.For example, your hypervisor host has two physical links that are up: vmnic0 and vmnic1. Suppose vmnic0 is used for management and storage networks, while vmnic1 is unused. This might mean that vmnic1 can be used as an NSX-T uplink, but vmnic0 cannot. To do link teaming, you must have two unused physical links available, such as vmnic1 and vmnic2.
  2. For an NSX Edge, tunnel endpoint and VLAN uplinks can use the same physical link. For example, vmnic0/eth0/em0 might be used for your management network and vmnic1/eth1/em1 might be used for your fp-ethX links.
When you install NSX Edge as a virtual appliance or VM, internal interfaces are created, called fp-ethX, where X is 0, 1, 2, and 3. These interfaces are allocated for uplinks to a top-of-rack (ToR) switches and for NSX-T overlay tunneling.

When you create the NSX Edge transport node, you can select fp-ethX interfaces to associate with the uplinks and the overlay tunnel. You can decide how to use the fp-ethX interfaces. 


How to Create Custom Uplink Profile
1. Login to NSX Manager UI
 
2.  Fabric > Profiles > Uplink Profils > Click on Add Button > Configure the required details > Add
LAG = For LACP, multiple LAG is not supported on KVM hosts.
Teaming = The teaming policy defines how the N-VDS uses its uplink for redundancy and traffic load balancing. There are two teaming policy modes to configure teaming policy:

Failover Order: An active uplink is specified along with an optional list of standby uplinks. If the active uplink fails, the next uplink in the standby list replaces the active uplink. No actual load balancing is performed with this option.

Load Balanced Source: A list of active uplinks is specified, and each interface on the transport node is pinned to one active uplink. This configuration allows use of several active uplinks at the same time.

Note:On KVM hosts, only failover order teaming policy is supported. Load balance source teaming policy is not supported.


 

NSX-T 2.2 Switching Profiles

Switching profiles include Layer 2 networking configuration details for logical switches and logical ports. NSX Manager supports several types of switching profiles, and maintains one or more system-defined default switching profiles for each profile type.

Note:- You cannot edit or delete the default switching profiles in the NSX Manager. You can create custom switching profiles instead.

These are the default switching profiles in NSX-T 2.2


QoS
QoS provides high-quality and dedicated network performance for preferred traffic that requires high bandwidth. The QoS mechanism does this by prioritizing sufficient bandwidth, controlling latency and jitter, and reducing data loss for preferred packets even when there is a network congestion. This level of network service is provided by using the existing network resources efficiently.
For this release, shaping and traffic marking namely, CoS and DSCP is supported. The Layer 2 Class of Service (CoS) allows you to specify priority for data packets when traffic is buffered in the logical switch due to congestion. The Layer 3 Differentiated Services Code Point (DSCP) detects packets based on their DSCP values. CoS is always applied to the data packet irrespective of the trusted mode.
NSX-T trusts the DSCP setting applied by a virtual machine or modifying and setting the DSCP value at the logical switch level. In each case, the DSCP value is propagated to the outer IP header of encapsulated frames. This enables the external physical network to prioritize the traffic based on the DSCP setting on the external header. When DSCP is in the trusted mode, the DSCP value is copied from the inner header. When in the untrusted mode, the DSCP value is not preserved for the inner header.

Note:- DSCP settings work only on tunneled traffic. These settings do not apply to traffic inside the same hypervisor.

You can use the QoS switching profile to configure the average ingress and egress bandwidth values to set the transmit limit rate. The peak bandwidth rate is used to support burst traffic a logical switch is allowed to prevent congestion on the northbound network links. These settings do not guarantee the bandwidth but help limit the use of network bandwidth. The actual bandwidth you will observe is determined by the link speed of the port or the values in the switching profile, whichever is lower.

The QoS switching profile settings are applied to the logical switch and inherited by the child logical switch port.

How to Create Custom QoS Switching Profile
1. Login to NSX Manager UI
2. Switching > Switching Profiles > Add > QoS

3. Now configure the details as required

DSCP = Select either a Trusted or Untrusted option from the Mode drop-down menu.
When you select the Trusted mode the inner header DSCP value is applied to the outer IP header for IP/IPv6 traffic. For non IP/IPv6 traffic, the outer IP header takes the default value. Trusted mode is supported on an overlay-based logical port. The default value is 0.

Untrusted mode is supported on overlay-based and VLAN-based logical port. For the overlay-based logical port, the DSCP value of the outbound IP header is set to the configured value irrespective to the inner packet type for the logical port. For the VLAN-based logical port, the DSCP value of IP/IPv6 packet will be set to the configured value. The DSCP values range for untrusted mode is between 0 to 63. 0 has highest priority.

CoS = CoS is supported on VLAN-based logical port. CoS groups similar types of traffic in the network and each type of traffic is treated as a class with its own level of service priority. The lower priority traffic is slowed down or in some cases dropped to provide better throughput for higher priority traffic. CoS can also be configured for the VLAN ID with zero packet.

The CoS values range from 0 to 7, where 0 is the best effort service.


Ingress = Set custom values for the outbound network traffic from the VM to the logical network.

You can use the average bandwidth to reduce network congestion. The peak bandwidth rate is used to support burst traffic and the burst duration is set in the burst size setting. You cannot guarantee the bandwidth. However, you can use the setting to limit network bandwidth. The default value 0, disables the ingress traffic.

Ingress Broadcast = Set custom values for the outbound network traffic from the VM to the logical network based on broadcast.

The default value 0, disables the ingress broadcast traffic.

Egress = Set custom values for the inbound network traffic from the logical network to the VM.

The default value 0, disables the egress traffic.

IP Discovery
IP Discovery uses DHCP snooping, ARP snooping, or VM Tools to learn the VM MAC and IP addresses. After the MAC and IP addresses are learnt, the entries are shared with the NSX Controller to achieve ARP suppression. ARP suppression minimizes ARP traffic flooding within VMs connected to the same logical switch.

DHCP snooping inspects the DHCP packets exchanged between the VM DHCP client and the DHCP server to learn the VM IP and MAC addresses.

ARP snooping inspects the outgoing ARPs and GARPs of the VM to learn the IP and MAC addresses. ARP snooping is applicable if the VM uses a static IP address instead of DHCP.

VM Tools is software that runs on an ESXi-hosted VM and can provide the VM's configuration information including MAC and IP addresses. This IP discovery method is available for VMs running on ESXi hosts only.



Switch Security
Switch security provides stateless Layer2 and Layer 3 security by checking the ingress traffic to the logical switch and dropping unauthorized packets sent from VMs by matching the IP address, MAC address, and protocols to a set of allowed addresses and protocols. You can use switch security to protect the logical switch integrity by filtering out malicious attacks from the VMs in the network.

You can configure the Bridge Protocol Data Unit (BPDU) filter, DHCP Snooping, DHCP server block, and rate limiting options to customize the switch security switching profile on a logical switch.

BPDU Filter = When the BPDU filter is enabled, all of the traffic to BPDU destination MAC address is blocked. The BPDU filter when enabled also disables STP on the logical switch ports because these ports are not expected to take part in STP.
BPDU Filter Allow List = Click the destination MAC address from the BPDU destination MAC addresses list to allow traffic to the permitted destination.
DHCP Server Filter = DHCP Server Block blocks traffic from a DHCP server to a DHCP client. Note that it does not block traffic from a DHCP server to a DHCP relay agent.
DHCP Client Block prevents a VM from acquiring a DHCP IP address by blocking DHCP requests.
Block Non-IP Traffic = Toggle the Block Non-IP Traffic button to allow only IPv4, IPv6, ARP, GARP and BPDU traffic.
The rest of the non-IP traffic is blocked. The permitted IPv4, IPv6, ARP, GARP and BPDU traffic is based on other policies set in address binding and SpoofGuard configuration.
By default, this option is disabled to allow non-IP traffic to be handled as regular traffic.
Set a rate limit for the ingress or egress Broadcast and Multicast traffic.
Rate limits = Rate limits are configured to protect the logical switch or the VM from for example, broadcast traffic storms.
To avoid any connectivity problems, the minimum rate limit value must be >= 10 pps.


SpoofGuard
A SpoofGuard policy blocks traffic determined to be spoofed.
SpoofGuard is a tool that is designed to prevent virtual machines in your environment from sending traffic with an IP address it is not authorized to end traffic from. In the instance that a virtual machine’s IP address does not match the IP address on the corresponding logical port and switch address binding in SpoofGuard, the virtual machine’s vNIC is prevented from accessing the network entirely. SpoofGuard can be configured at the port or switch level.
  
There are several reasons SpoofGuard might be used in your environment:
  • Preventing a rogue virtual machine from assuming the IP address of an existing VM.
  • Ensuring the IP addresses of virtual machines cannot be altered without intervention – in some environments, it’s preferable that virtual machines cannot alter their IP addresses without proper change control review. SpoofGuard facilitates this by ensuring that the virtual machine owner cannot simply alter the IP address and continue working unimpeded.
  • Guaranteeing that distributed firewall (DFW) rules will not be inadvertently (or deliberately) bypassed – for DFW rules created utilizing IP sets as sources or destinations, the possibility always exists that a virtual machine could have it’s IP address forged in the packet header, thereby bypassing the rules in question.
SpoofGuard helps prevent a form of malicious attack called "web spoofing" or "phishing." NSX-T SpoofGuard configuration covers the following:
  1. MAC SpoofGuard - authenticates MAC address of packet
  2. IP SpoofGuard - authenticates MAC and IP addresses of packet
  3. Dynamic Address Resolution Protocol (ARP) inspection, that is, ARP and Gratuitous Address Resolution Protocol (GARP) SpoofGuard and Neighbor Discovery (ND) SpoofGuard validation are all against the MAC source, IP Source and IP-MAC source mapping in the ARP/GARP/ND payload. 



MAC Management
The MAC management switching profile supports two functionalities: 
  1. MAC learning and 
  2. MAC address change.
The MAC address change feature allows a VM to change its MAC address. A VM connected to a port can run an administrative command to change the MAC address of its vNIC and still send and receive traffic on that vNIC. This feature is supported on ESXi only and not on KVM. This property is disabled by default.
MAC learning provides network connectivity to deployments where multiple MAC addresses are configured behind one vNIC, for example, in a nested hypervisor deployment where an ESXi VM runs on an ESXi host and multiple VMs run inside the ESXi VM. Without MAC learning, when the ESXi VM's vNIC connects to a switch port, its MAC address is static. VMs running inside the ESXi VM do not have network connectivity because their packets have different source MAC addresses. With MAC learning, the vSwitch inspects the source MAC address of every packet coming from the vNIC, learns the MAC address and allows the packet to go through. If a MAC address that is learned is not used for a certain period of time, it is removed. This aging property is not configurable.
If you enable MAC learning or MAC address change, to improve security, configure SpoofGuard as well.

 For More Info Click Here

Friday, 22 March 2019

Top vBlog 2018 Results - Finally My Blog is in Top 75

Yesterday Eric Siebert From vSphere-land announced the results of Top vBlog 2018. You can check my previous blogpost to know more about Top vBlog 2018. Thanks to everyone who voted for my blog. This Year my Blog Rank is 65. You can find the full results here


As well as my blog is listed in different categories too:-

1. Favorite Female Blogger


2. Favorite Scripting/Automation Blog


 3.  Favorite Independent Blogger


Wednesday, 20 March 2019

NSX-T Roles Assignments

You can add, change, and delete role assignments to users or user groups if VMware Identity Manager is integrated with NSX-T.
vIDM = VMware Identity Manager
Prerequisites
Verify that a vIDM host is associated with NSX-T. For more information.

How to Assign NSX-T Roles
1. Add an AD Domain to vIDM
  • Login to vIDM
  • Identity and Access Management > Directories > Add Directory > Add Active Directory over LDAP/IWA
  •  Configure Domain Details > Save and Next
     
  •  Click Next

  • Click Next
  • Search For Group in specific OU or complete Domain > Click on Next
  •  Search Specific Users that you want to sync > Click on Next
  • Click on Add Directory > Sync Will Start
  • To know the sync status > Click on Refresh Page 




2. Create OAuth Client for NSX Manager in vIDM
  • Catalog > Settings

  • Remote App Access > Create Client

  • Configure the client details > Add > Copy Client ID and Shared Secret (It's needed in the next step)



3. Gather vIDM Appliance Thumbprint
Login to vIDM Appliance
sudo -s
enter root account password
cd /usr/local/horizon/conf
openssl x509 -in (vidm appliance fqdn)_cert.pem -noout -sha256 -fingerprint
copy the fingerprint, It's needed in next step 

4. Integrate vIDM with NSX Manager

Login to NSX Manager UI > Systems Category > Users > Configuration > Edit > Enter
vIDM Appliance FQDN, Client ID, Shared Secret, Thumprint that we have discussed in previous step > Click on SAVE


5. Assign NSX Roles to AD User
System > Users > Role Assignments > Search User > Select Role > Add
NSX-T has the following built-in roles. You cannot add any new roles.
  1. Enterprise Administrator
  2. Auditor
  3. Network Engineer
  4. Network Operations
  5. Security Engineer
  6. Security Operations
  7. Cloud Service Administrator
  8. Cloud Service Auditor
  9. Load Balancer Administrator
  10. Load Balancer Auditor
Cloud Service Roles are available only when you have NSX Cloud.

After an Active Directory (AD) user is assigned a role, if the username is changed on the AD server, you need to assign the role again using the new username.

For more info about roles click here



6. Now verify the role assignment,
Logout from existing user > Login from new user to verify role assignment is done correctly or not




Tuesday, 19 March 2019

VMC on AWS - What's New - March 2019

Information Source for detailed Information Click here >>>>> VMware Doc 

New Regions: Asia Pacific (Singapore), Canada (Central), and Europe (Paris)
Customers can now deploy SDDCs in the Asia Pacific (Singapore), Canada (Central), and Europe (Paris) regions. Please note that the Canada (Central) region does not support stretched clusters.

VMware Network Insight
VMware Network Insight helps customers build an optimized, highly available and secure network infrastructure across multi-cloud environments. It accelerates micro-segmentation deployment, minimizes business risk during application migration and enables customers to confidently manage and troubleshoot application networking and security across their on-premise and VMware Cloud on AWS environments. VMware Network Insight now supports integration of VMware Cloud on AWS as a data source. VMware Network Insight integration with VMware Cloud on AWS provides the following key capabilities to VMware Cloud on AWS users:
  • Traffic analysis and micro-segmentation planning for VMware Cloud on AWS workloads
  • Migration planning from workloads from on-premises SDDC to VMware Cloud on AWS
  • Hybrid network path troubleshooting that includes VMware Cloud on AWS to on-premises path through gateways and VP
Direct Connect BGP Local ASN change
Direct Connect connection to SDDC now uses BGP Local ASN as 64512. This BGP local ASN is editable and any private ASN from the range 64512 – 65534 can be used. If the selected ASN 64512 is already used on-premises, a different ASN number must be used. Before this change, AWS Public ASN was used as BGP local ASN. The following public ASNs were used - 17493 in the Asia Pacific (Singapore) region, 10124 in the Asia Pacific (Tokyo) region, 9059 in the EU (Ireland) region, and 7224 in other regions. Important note around deployments:
  • If you are creating a new Direct Connect virtual interface (VIF), you will only be able to use a private local ASN with VMware Cloud on AWS.
  • If you want to change an existing public ASN to a private ASN, you must delete any AWS Direct Connect VIF that uses the existing public ASN.
  • If you change to a private ASN, you will not be able to change back to a public ASN later.
  • If you have an SDDC that is using the prior default public ASN, you can continue using the public ASN for the SDDC.
Language and Regional Format Support (French, Spanish, Korean, Simplified Chinese and Traditional Chinese)​
VMware Cloud on AWS now supports language and regional format settings in French, Spanish, Korean, Simplified Chinese and Traditional Chinese, in addition to German and Japanese. These languages are supported in the VMware Cloud on AWS console and in Cloud Service Platform features such as Identity & Access Management, Billing & Subscriptions, and some areas of the Support Center. You can change your display language before you login to the VMware Cloud on AWS console or in your account settings.

NSX-T Licensing Editions

Standard Edition: For organizations needing agility and automation of the network.
Professional Edition: For organizations needing Standard, plus micro-segmentation, and may have public cloud endpoints.
Advanced Edition: For organizations needing Professional, plus advanced networking and security services, and may have multiple sites.
Enterprise Plus Edition: For organizations needing the most advanced capabilities NSX Data Center has to offer, plus network visibility and security operations with vRealize Network Insight™, and hybrid cloud mobility with NSX Hybrid Connect.

If you want to Features supported in Each Edition check this VMware KB 52462

Monday, 18 March 2019

NSX-T Configuring eBGP in Tier-0 Router - Part 16

To enable access between your VMs and the outside world, you can configure an external BGP (eBGP) connection between a tier-0 logical router and a router in your physical infrastructure.
When configuring BGP, you must configure a local Autonomous System (AS) number for the tier-0 logical router.  You must also configure the remote AS number of the physical router. The remote neighbor IP address. The neighbor must be in the same IP subnet as the uplink on the tier-0 logical router. BGP multihop is supported.

Prerequisites
  • Verify that the tier-1 router is configured to advertise connected routes.  This is not strictly a prerequisite for BGP configuration, but if you have a two-tier topology and you plan to redistribute your tier-1 networks into BGP, this step is required.
  • Verify that a tier-0 router is configured.
  • Make sure the tier-0 logical router has learned routes from the tier-1 logical router.  
If you missed previous parts in this blogpost series. Here is the Links:-
Part - 1
Part - 2
Part - 3
Part - 4
Part - 5
Part - 6
Part - 7
Part - 8
Part - 9
Part - 10
Part - 11
Part - 12
Part - 13
Part - 14
Part - 15 
  
How to Configure eBGP

1. Login to NSX Manager UI


 2. Routing > Routers > Select Tier-0 Router > Routing  > BGP



3. Enable the Status > Save

4. Under Neighbors > Click on Add > Configure Neighbor Address  and Remote AS


5. Configure Local Address > Add

6. Now Add the Second Address of Neighbor in same way as done in above steps


7. Now configure the Route Advertisement on Tier-1 Router
Select Tier-1 Router > Routing Tab > Route Advertisement

To provide Layer 3 connectivity between VMs connected to logical switches that are attached to different tier-1 logical routers, it is necessary to enable tier-1 route advertisement towards tier-0. You do not need to configure a routing protocol or static routes between tier-1 and tier-0 logical routers. NSX-T creates NSX-T static routes automatically when you enable route advertisement.

For example, to provide connectivity to and from the VMs through other peer routers, the tier-1 logical router must have route advertisement configured for connected routes. If you don't want to advertise all connected routes, you can specify which routes to advertise.

Prerequisites
  • Verify that VMs are attached to logical switches.
  • Verify that downlink ports for the tier-1 logical router are configured.


8. Enable Route Advertisement > Save

9. Now configure the Route Redistribution on Tier-0 Router.
Select Tier-0 > Route Redistribution

Prerequisites
  • Verify that the tier-0 and tier-1 logical routers are connected so that you can advertise the tier-1 logical router networks to redistribute them on the tier-0 logical router.
  • If you want to filter specific IP addresses from route redistribution, verify that route maps are configured. 

10. Edit > Enable Route Redistribution > Save


11. Click on Add > Configure what are routes you want to redistribute > Add

Select the source route check boxes you want to redistribute.
  1. Static - Tier-0 static routes.
  2. NSX Connected - Tier-1 connected routes.
  3. NSX Static - Tier-1 static routes. These static routes are created automatically.
  4. Tier-0 NAT - Routes generated if NAT is configured on the tier-0 logical router.
  5. Tier-1 NAT - Routes generated if NAT is configured on the tier-1 logical router.


NSX-T Connect Tier-1 Logical Router with Tier-0 Logical Router - Part 15

If you missed previous parts in this blogpost series. Here is the Links:-
Part - 1
Part - 2
Part - 3
Part - 4
Part - 5
Part - 6
Part - 7
Part - 8
Part - 9
Part - 10
Part - 11
Part - 12
Part - 13
Part - 14

In my previous posts i have discussed how to add Tier-1 and Tier-0 Router. Now in this post i will discuss how to connect Tier-1 to Tier-0, this is needed for connecting your Workloads (connected with Logical Switch) with Physical Infrastructure.

How to Connect Tier-1 to Tier-0

1. Login to NSX Manager UI

 
2.  Routing > Routers > Select Tier-1 Router > Click on Gear Icon > Connect to Tier-0 Router


3. Select Tier-0 Router > Click on Connect