Microsoft Azure Configuration



Similar documents
CenturyLink Cloud Configuration

How To Set Up A Vns3 Controller On An Ipad Or Ipad (For Ahem) On A Network With A Vlan (For An Ipa) On An Uniden Vns 3 Instance On A Vn3 Instance On

Google Compute Engine Configuration

HP Helion Configuration

VNS3 to Cisco ASA Instructions. ASDM 9.2 IPsec Configuration Guide

VNS3 Secure Network Appliance Service Defnition for G-Cloud 7

Cloud Security Best Practices

TechNote. Configuring SonicOS for MS Windows Azure

Configuration Procedure

Configuring IPsec VPN between a FortiGate and Microsoft Azure

How To Industrial Networking

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

How To Install Sedar On A Workstation

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

The VPNaaS Plugin for Fuel Documentation

This chapter describes how to set up and manage VPN service in Mac OS X Server.

Apache CloudStack 4.x (incubating) Network Setup: excerpt from Installation Guide. Revised February 28, :32 pm Pacific

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

Configuring an IPSec Tunnel between a Firebox & a Check Point FireWall-1

Fireware How To VPN. Introduction. Is there anything I need to know before I start? Configuring a BOVPN Gateway

TechNote. Configuring SonicOS for Amazon VPC

Scenario: Remote-Access VPN Configuration

How To Establish IPSec VPN between Cyberoam and Microsoft Azure

SHAREPOINT 2013 IN INFRASTRUCTURE AS A SERVICE

Configuring IPsec VPN with a FortiGate and a Cisco ASA

Management, Logging and Troubleshooting

Virtual Data Centre. User Guide

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

Introduction to Mobile Access Gateway Installation

VPN Configuration Guide. ZyWALL USG Series / ZyWALL 1050

Quick Start Guide: Utilizing Nessus to Secure Microsoft Azure

V310 Support Note Version 1.0 November, 2011

Biznet GIO Cloud Connecting VM via Windows Remote Desktop

Configuring a VPN between a Sidewinder G2 and a NetScreen

vcloud Director User's Guide

VELOCITY. Quick Start Guide. Citrix XenServer Hypervisor. Server Mode (Single-Interface Deployment) Before You Begin SUMMARY OF TASKS

Configure an IPSec Tunnel between a Firebox Vclass & a Check Point FireWall-1

Lab 4.4.8a Configure a Cisco GRE over IPSec Tunnel using SDM

D-Link Central WiFiManager Configuration Guide

Using IKEv2 on Juniper Networks Junos Pulse Secure Access Appliance

Interconnection between the Windows Azure

How To Configure A Kiwi Ip Address On A Gbk (Networking) To Be A Static Ip Address (Network) On A Ip Address From A Ipad (Netware) On An Ipad Or Ipad 2 (

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

Configuring a Check Point FireWall-1 to SOHO IPSec Tunnel

UTM - VPN: Configuring a Site to Site VPN Policy using Main Mode (Static IP address on both sites) i...

How To Set Up A Backupassist For An Raspberry Netbook With A Data Host On A Nsync Server On A Usb 2 (Qnap) On A Netbook (Qnet) On An Usb 2 On A Cdnap (

Networking Configurations for NetApp Cloud ONTAP TM for AWS

KeyControl Installation on Amazon Web Services

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

SSL VPN Technical Primer

SSL SSL VPN

NOC PS manual. Copyright Maxnet All rights reserved. Page 1/45 NOC-PS Manuel EN version 1.3

Overview and Deployment Guide. Sophos UTM on AWS

VPN Configuration Guide WatchGuard Fireware XTM

SonicOS Enhanced Release Notes

MacroLan Azure cloud tutorial.

Scenario: IPsec Remote-Access VPN Configuration

Deploying the Barracuda Link Balancer with Cisco ASA VPN Tunnels

VMware vcloud Air Networking Guide

Configuring Windows 2000/XP IPsec for Site-to-Site VPN

ISG50 Application Note Version 1.0 June, 2011

Contents. Pre-Installation Recommendations. Platform Compatibility. G lobal VPN Client SonicWALL Global VPN Client for 64-Bit Clients

Sophos UTM. Remote Access via SSL. Configuring UTM and Client

Application Note: Onsight Device VPN Configuration V1.1

LifeSize Transit Deployment Guide June 2011

How To Deploy Sangoma Sbc Vm At Amazon Cloud Service (Awes) On A Vpc (Virtual Private Cloud) On An Ec2 Instance (Virtual Cloud)

DEPLOYMENT GUIDE Version 1.0. Deploying the BIG-IP Edge Gateway for Layered Security and Acceleration Services

Windows XP VPN Client Example

ZyXEL ZyWALL P1 firmware V3.64

Cisco Intercloud Fabric Security Features: Technical Overview

Configuring a WatchGuard SOHO to SOHO IPSec Tunnel

Chapter 6 Virtual Private Networking Using SSL Connections

Global VPN Client Getting Started Guide

Configure IPSec VPN Tunnels With the Wizard

Netopia TheGreenBow IPSec VPN Client. Configuration Guide.

vcloud Air - Virtual Private Cloud OnDemand Networking Guide

Configuring SonicOS for Microsoft Azure

Chapter 4 Virtual Private Networking

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

Dell One Identity Cloud Access Manager How To Deploy Cloud Access Manager in a Virtual Private Cloud

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

Application Note: Integrate Juniper IPSec VPN with Gemalto SA Server. October

INTEGRATION GUIDE. DIGIPASS Authentication for Cisco ASA 5505

Ingate Firewall. TheGreenBow IPSec VPN Client Configuration Guide.

User Manual. Onsight Management Suite Version 5.1. Another Innovation by Librestream

Cisco SA 500 Series Security Appliance

VPN Configuration Guide. Juniper Networks NetScreen / SSG / ISG Series

1Y0-250 Implementing Citrix NetScaler 10 for App and Desktop Solutions Practice Exam

Creating a Gateway to Client VPN between Sidewinder G2 and a Mac OS X Client

How to Configure NetScaler Gateway 10.5 to use with StoreFront 2.6 and XenDesktop 7.6.

Guide to the LBaaS plugin ver for Fuel

How To Set Up Checkpoint Vpn For A Home Office Worker

Virtual Appliance Setup Guide

VPN. VPN For BIPAC 741/743GE

TheGreenBow IPsec VPN Client. Configuration Guide Cisco RV325 v1. Website: Contact:

VPN Quick Configuration Guide. Astaro Security Gateway V8

Who s Endian?

VPN Wizard Default Settings and General Information

Transcription:

Microsoft Azure Configuration Azure Setup for VNS3 2015 copyright 2015 1

Table of Contents Introduction 3 Create Azure Private VLAN 10 Launch VNS3 Image from Azure Marketplace 15 VNS3 Configuration Document Links 22 copyright 2015 2

Requirements copyright 2015 3

Requirements You have an Azure account. (For Free Azure trials visit http://azure.microsoft.com/en-us/pricing/free-trial/) You agree to the VNS3 Terms and Conditions Ability to configure a client (whether desktop based or cloud based) to use OpenVPN client software. You have a compliant IPsec firewall/router networking device that can use NAT- Traversal Encapsulation (Azure does not allow Protocol 50 ESP Endpoint Configuration) Preferred Most models from Cisco Systems*, Juniper, Watchguard, Dell SONICWALL, Netgear, Fortinet, Barracuda Networks, Check Point*, Zyxel USA, McAfee Retail, Citrix Systems, Hewlett Packard, D-Link, WatchGuard, Palo Alto Networks, OpenSwan, pfsense, and Vyatta. Best Effort Any IPsec device that supports: IKE1 or IKE2, AES256 or AES128 or 3DES, SHA1 or MD5. *Known Exclusions Checkpoint R65+ requires native IPSec connections as Checkpoint does not conform to NAT-Traversal Standards and Cisco ASA 8.4(2)-8.4(4) bugs prevent a stable connection from being maintained. copyright 2015 4

Getting Help with VNS3 This guide covers a very generic VNS3 setup in the Azure cloud. If you are interested in more custom use cases and would like Cohesive to advise and help set up the topology, contact sales@cohesive.net for services pricing. Please review the VNS3 Support Plans and Contacts before sending support inquiries. copyright 2015 5

Firewall Considerations VNS3 Controller instance use the following TCP and UDP ports. UDP port 1194 For client VPN connections; network cal or hypervisor access rule for the VNS3 Controller must allow UDP port 1194 from all servers that will join VNS3 topology as clients. UDP 1195-1197 For peering between VNS3 Controller peers; must be accessible from all peers in a given topology. Free Edition and Lite Edition will not require UDP ports 1195-1197 access as it is not licensed for Controller Peering (Single Controller Topologies). TCP port 8000 HTTPS admin interface; must be accessible from hosts where you will want to obtain runtime status or configure your VNS3 topology, also needs to be open to and from the Controllers at least for the peering process, and needs to be accessible when downloading credentials for installation on overlay network clients. UDP port 500, and UDP port 4500 IPsec connections to Azure support only NAT-Traversal encapsulation (UDP 500 and UDP 4500). Azure does not support native IPsec connections into their cloud. NOTE: If you need to negotiate a native IPsec tunnel to serve an Azure deployment, contact support@cohesive.net for bridging solutions. copyright 2015 6

Address Considerations Restrictions The Azure CIDR and Subnets cannot overlap with the VNS3 Overlay Network Subnet. The Azure public cloud does not currently allow virtual machine instances to act as networks gateways for unencrypted VLAN traffic. As a result when using Azure, you must use the Overlay Network when configuring your cloud servers. Contact support@cohesive.net for more information. copyright 2015 7

Sizing Considerations Image Size and Architecture VNS3 Controller Images are available as 64bit images to allow the greatest flexibility for your use-case. We recommend Controller instances be launched with at least 512MB of RAM. Smaller sizes are supported but the performance will depend on the use-case. Clientpack Key Size VNS3 Controllers currently generate 1024 bit keys for connecting the clients to the overlay network via the clientpacks. Smaller or larger encryption keys can be provided upon request (from 64 bit to 2048 bit). Future releases of VNS3 will provide the user control over key size and cipher during initialization and configuration. copyright 2015 8

Remote Support Note that TCP 22 (ssh) is not required for normal operations. Each VNS3 Controller is running a restricted SSH daemon, with access limited only to Cohesive for debugging purposes controlled by the user via the Remote Support toggle and key exchange generation. In the event Cohesive needs to observe runtime state of a VNS3 Controller in response to a tech support request, we will ask you to open Security Group access to SSH from our support IP range and Enable Remote Support via the Web UI. Cohesive will send you an encrypted passphrase to generate a private key used by Cohesive Support staff to access your Controller. Access to the restricted SSH daemon is completely controlled by the user. Once the support ticket has been closed you can disable remote support access and invalidate the access key. copyright 2015 9

Create Azure Private VLAN copyright 2015 10

Create VLAN Cohesive Networks recommends using a custom Azure Virtual Network or VLAN for all Azure cloud deployments. VLANs provide isolation and additional network configuration settings that may be needed for your use-case. The following VLAN setup is the recommended best practice that uses separate subnets for VNS3 Controller instances and cloud server instances. NOTE: The Azure VLAN CIDR you configure CANNOT overlap with the VNS3 Overlay Network you create during configuration of your VNS3 Controller instance. copyright 2015 11

Create VLAN - Virtual Network Details On the Azure Portal left menu, choose NEW at the bottom, then select NETWORK SERVICES > VIRTUAL NETWORK > CUSTOM CREATE. This will pop up a window allowing you to name your private VLAN. Give the VLAN a name and pick the Azure compute center for it to be created in. NOTE: While Azure VLANs cannot span compute centers, that is one of the key capabilities of VNS3. Create an encrypted VNS3 Overlay Network that spans regions as well as clouds. It can also safely peer Azure VLANs between regions, as well as VLANs between clouds. Click the arrow on the lower right to proceed. copyright 2015 12

Create VLAN - DNS Servers Unless you are setting up specific DNS servers, there are no needed configuration changes on this page. Click the arrow to proceed. copyright 2015 13

Create VLAN - Virtual Network Address Spaces On the next page you can specify any Address Space in the private IP Address ranges set by RFC 1918-10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16. NOTE: You cannot create VLANs with Public IPv4 addresses. VNS3 allows this with its encrypted virtual VLANs. You then create one or more subnets within that address space. In this example two were created. VLAN organization is outside the scope of this document, but there are often advantages to putting the VNS3 instance in a separate subnet from the rest of your deployment. Click the checkbox to finish creating your VLAN. copyright 2015 14

Launch VNS3 Image from Azure Marketplace copyright 2015 15

Launch VNS3 - Select VNS3 Image VNS3 Free and Lite Edition virtual machine images are available in the Azure Marketplace: VNS3:vpn Free Edition - https://azure.microsoft.com/en-us/marketplace/ partners/cohesive/cohesiveft-vns3-for-azure-cohesive-vns3-free/ VNS3:net Lite Edition - https://azure.microsoft.com/en-us/marketplace/ partners/cohesive/cohesiveft-vns3-for-azure-cohesive-vns3-lite/ To launch an instance of either, on the Azure Portal left menu, choose NEW at the bottom, then select COMPUTE > VIRTUAL MACHINE > FROM GALLERY. copyright 2015 16

Launch VNS3 - Select VNS3 Image The FROM GALLERY option pops up a window offering Choose an Image offering default Microsoft and Operating System vendor images. Scroll to the bottom of the Featured Image list and select the VNS3:vpn Free Edition or VNS3:net Lite Edition image. Click the arrow to proceed. copyright 2015 17

Launch VNS3 - Virtual Machine Configuration Give the instance a name, spaces are not allowed, so use hyphens to separate the words of an instance name. Choose your tier of service and instance size. VNS3 should have at least one core and 1.5 gigs of memory, so the A1 instance type is a good place to start. Depending on need, VNS3 can be run as a very large instance to provide more throughput for the virtual network, site-to-site connections, firewall rules, or other network functions. The Azure portal requires a username and a SSH key or password. Regardless of their entry - they will not provide shell access to VNS3 instances which run as appliances. The most straightforward approach would be to leave the default azureuser and enter a meaningless password. After these configuration elements are made use the proceed arrow inthe lower right of the web browser page. copyright 2015 18

Launch VNS3 - Virtual Machine Configuration The next page of configuration for the VNS3 instance sets up the network port access rules, as well as allows you to choose a VLAN for the instance to be launched in. Azure calls this element that holds this information a Cloud Service, allowing you to launch other (subsequent) instances with the same configuration parameters. You can create a new cloud service, naming it, or choose an existing one created previously. The cloud service name must be globally unique as it serves as a DNS name. The next drop town box lets you choose from a number of groups; either one of the Azure Cloud Computing Centers, or an element called an Affinity Group or a pre-defined VLAN. Most customers will want to have defined a virtual network VLAN for placing their instances in. The topic of Availability Sets is beyond the scope of this document. Endpoints are how Azure describes a set of TCP and UDP port rules. Only TCP and UDP are allowed, other protocols cannot be controlled, and as a rule are blocked by Azure. At minimum VNS3 needs port 8000 open for the API and the Administrative UI. When complete select the proceed arrow near the bottom of the web browser page. copyright 2015 19

Launch VNS3 - Virtual Machine Configuration The final page before instance launch should not need modification. Ensure that the VM Agent box is checked. Do NOT check the Chef button. Review the legal terms and summary information, and finalize the launch of the instance by clicking on the check box at the bottom right of the web browser page. copyright 2015 20

VNS3 Virtual Machine Details After clicking on the check box you will be returned to the virtual machines page, which shows the instance running in your account. In this example there is only one instance vns3-free. Click in the Name column on the vns3-free row to be taken to its detail page. If it is the first instance you have launched you will be taken to the summary Quick Start page with useful links to Azure APIs, SDKs and Documentation. Click on the Skip Quick Start the next time I visit to go straight to the instance detail page in future. copyright 2015 21

VNS3 Configuration Document Links copyright 2015 22

VNS3 Configuration Document Links VNS3 Product Resources - Documentation Add-ons VNS3 Configuration Instructions Instructions and screenshots for configuring a VNS3 Controller in a single or multiple Controller topology. Specific steps include, initializing a new Controller, generating clientpack keys, setting up peering, building IPsec tunnels, and connecting client servers to the Overlay Network. VNS3 Administration Document Covers the administration and operation of a configured VNS3 Controller. Additional detail is provided around the VNS3 Firewall, all administration menu items, upgrade licenses, other routes and SNMP traps. VNS3 Docker Instructions Explains the value of the VNS3 3.5 Docker integration and covers uploading, allocating and exporting application containers. VNS3 Troubleshooting Troubleshooting document that provides explanation issues that are more commonly experienced with VNS3. copyright 2015 23