VMware NSX for Beginners, Part 1

VMware NSX for Beginners, Part 1

If you look at the configuration of any firewall, you will likely see a sheet full of IP addresses, ports, protocols, and subnets. This is how network security policies are traditionally implemented for user access to resources. Initially, the configuration is organized, but then employees start moving from department to department, servers proliferate and change their roles, access is granted for different projects where it shouldn't be, resulting in hundreds of unknown convoluted paths.

Regarding some rules, if you're lucky, there are comments like 'Requested by Vasya' or 'This is a pass in the DMZ.' The network administrator leaves, and everything becomes completely unclear. Then someone decided to clean up the configuration from Vasya's requests, and SAP fell, because at one time, Vasya requested that access to work with the production SAP.

VMware NSX for Beginners, Part 1

Today, I will talk about the VMware NSX solution that helps to apply network interaction and security policies precisely without the chaos in firewall configurations. I will show you what new features have been added compared to what VMware offered earlier in this area.

VMware NSX is a platform for virtualization and securing network services. NSX addresses routing, switching, load balancing, firewalling, and has many other interesting capabilities.

NSX is the successor of VMware's own product vCloud Networking and Security (vCNS) and the acquired Nicira NVP.

From vCNS to NSX

Previously, the client had a separate virtual machine vCNS vShield Edge in a cloud built on VMware vCloud. It served as a boundary gateway, where many network functions could be configured: NAT, DHCP, Firewall, VPN, load balancer, and more. vShield Edge restricted a virtual machine's interaction with the outside world according to the rules set in the Firewall and NAT. Within the network, virtual machines communicated freely with each other within subnets. If you really want to control traffic, you can create a separate network for different parts of applications (various virtual machines) and set corresponding rules in the firewall for their network interaction. But this is long, complicated, and tedious, especially when you have several dozen virtual machines.

In NSX, VMware has implemented the concept of micro-segmentation through a distributed firewall that is built into the hypervisor kernel. Security and network interaction policies are defined not only for IP and MAC addresses but also for other objects: virtual machines and applications. If NSX is deployed within an organization, objects can even include users or groups from Active Directory. Each of these objects becomes a micro-segment in its security perimeter, within the necessary subnet, complete with its own cozy DMZ.:)

VMware NSX for Beginners, Part 1
Previously, there was a single security perimeter for the entire resource pool, protected by an edge switch. With NSX, it's possible to isolate a single virtual machine from unnecessary interactions even within the same network.

Security and networking policies adapt if an object moves to another network. For example, if we migrate a database machine to a different network segment or even to another associated virtual data center, the rules specified for that virtual machine continue to apply regardless of its new location. The application server will still be able to interact with the database.

The previously used edge gateway vCNS vShield Edge has been replaced by NSX Edge. It includes all the features of the old Edge plus several new useful functions. The discussion will focus on these.

What's new in NSX Edge?

The functionality of NSX Edge depends on the edition of NSX. There are five editions: Standard, Professional, Advanced, Enterprise, Plus Remote Branch Office. All new and interesting features can only be seen starting from the Advanced edition. This includes the new interface, which will open in a new tab until the full transition of vCloud to HTML5 (VMware promises summer 2019).

Firewall. As objects to which rules will apply, you can select IP addresses, networks, gateway interfaces, and virtual machines.

VMware NSX for Beginners, Part 1

VMware NSX for Beginners, Part 1

DHCP. In addition to configuring the IP address range that will be automatically assigned to virtual machines in this network, NSX Edge now includes features for Binding and Relay.

In the tab Bindings you can bind a virtual machine's MAC address to an IP address if you want the IP address to remain unchanged. The only condition is that this IP address must not be part of the DHCP Pool.

VMware NSX for Beginners, Part 1

In the tab Relay DHCP message relay is configured to DHCP servers located outside your organization in vCloud Director, including physical infrastructure DHCP servers.

VMware NSX for Beginners, Part 1

Routing. With vShield Edge, only static routing could be configured. Now, dynamic routing is available with support for OSPF and BGP protocols. ECMP settings (Active-active) are also available, enabling active-active failover to physical routers.

VMware NSX for Beginners, Part 1
Configuring OSPF

VMware NSX for Beginners, Part 1
BGP Configuration

Another new feature is the ability to configure route exchange between different protocols,
route redistribution.

VMware NSX for Beginners, Part 1

L4/L7 Load Balancer. X-Forwarded-For for HTTPs headers has been introduced. Without it, everyone was struggling. For example, if you have a website that you are balancing, without forwarding this header everything works, but in your web server statistics, you saw not the visitors' IPs but the load balancer's IP. Now everything is correct.

Also, in the Application Rules tab, you can now add scripts to directly manage traffic balancing.

VMware NSX for Beginners, Part 1

VPN. In addition to IPSec VPN, NSX Edge supports:

  • L2 VPN, which allows networks to stretch across geographically separated sites. This VPN is necessary, for example, to ensure that when moving to another site, a virtual machine remains in the same subnet and retains its IP address.

VMware NSX for Beginners, Part 1

  • SSL VPN Plus, which allows users to connect remotely to the corporate network. This function existed at the vSphere level, but it is a novelty for vCloud Director.

VMware NSX for Beginners, Part 1

SSL Certificates. You can now install certificates on NSX Edge. This raises the question of who needed a load balancer without a certificate for https.

VMware NSX for Beginners, Part 1

Grouping Objects. In this tab, groups of objects are defined for which specific network interaction rules, such as firewall rules, will apply.

These objects can be IP and MAC addresses.

VMware NSX for Beginners, Part 1
 
VMware NSX for Beginners, Part 1

A list of services (protocol-port combinations) and applications is also provided here, which can be used when creating firewall rules. New services and applications can only be added by the vCD portal administrator.

VMware NSX for Beginners, Part 1
 
VMware NSX for Beginners, Part 1

Statistics. Connection statistics: traffic passing through the gateway, firewall, and load balancer.

Status and statistics for each IPSEC VPN and L2 VPN tunnel.

VMware NSX for Beginners, Part 1

Logging. In the Edge Settings tab, you can specify the server for logging. Logging works for DNAT/SNAT, DHCP, Firewall, routing, load balancer, IPsec VPN, and SSL VPN Plus.
 
For each object/service, the following types of notifications are available:

— Debug
— Alert
— Critical
— Error
— Warning
— Notice
— Info

VMware NSX for Beginners, Part 1

NSX Edge Sizes

Depending on the challenges and volumes, VMware recommends creates NSX Edge of the following sizes:

NSX Edge
(Compact)

NSX Edge
(Large)

NSX Edge
(Quad-Large)

NSX Edge
(X-Large)

vCPU

1

2

4

6

Memory

512MB

1GB

1GB

8GB

Disk

512MB

512MB

512MB

4.5GB + 4GB

Purpose

Single
application, test
data center

Small
or medium
data center

Heavy
firewall

Load Balancing
load at L7 level

Below in the table are the operational metrics of network services based on the size of NSX Edge.

NSX Edge
(Compact)

NSX Edge
(Large)

NSX Edge
(Quad-Large)

NSX Edge
(X-Large)

Interfaces

10

10

10

10

Sub Interfaces (Trunk)

200

200

200

200

NAT Rules

2,048

4,096

4,096

8,192

ARP Entries
Until Overwrite

1,024

2,048

2,048

2,048

FW Rules

2000

2000

2000

2000

FW Performance

3Gbps

9.7Gbps

9.7Gbps

9.7Gbps

DHCP Pools

20,000

20,000

20,000

20,000

ECMP Paths

8

8

8

8

Static Routes

2,048

2,048

2,048

2,048

LB Pools

64

64

64

1,024

LB Virtual Servers

64

64

64

1,024

LB Server / Pool

32

32

32

32

LB Health Checks

320

320

320

3,072

LB Application Rules

4,096

4,096

4,096

4,096

L2VPN Clients Hub to Spoke

5

5

5

5

L2VPN Networks per Client/Server

200

200

200

200

IPSec Tunnels

512

1,600

4,096

6,000

SSLVPN Tunnels

50

100

100

1,000

SSLVPN Private Networks

16

16

16

16

Concurrent Sessions

64,000

1,000,000

1,000,000

1,000,000

Sessions/Second

8,000

50,000

50,000

50,000

LB Throughput L7 Proxy)

2.2Gbps

2.2Gbps

3Gbps

LB Throughput L4 Mode)

6Gbps

6Gbps

6Gbps

LB Connections/s (L7 Proxy)

46,000

50,000

50,000

LB Concurrent Connections (L7 Proxy)

8,000

60,000

60,000

LB Connections/s (L4 Mode)

50,000

50,000

50,000

LB Concurrent Connections (L4 Mode)

600,000

1,000,000

1,000,000

BGP Routes

20,000

50,000

250,000

250,000

BGP Neighbors

10

20

100

100

BGP Routes Redistributed

No Limit

No Limit

No Limit

No Limit

OSPF Routes

20,000

50,000

100,000

100,000

OSPF LSA Entries Max 750 Type-1

20,000

50,000

100,000

100,000

OSPF Adjacencies

10

20

40

40

OSPF Routes Redistributed

2000

5000

20,000

20,000

Total Routes

20,000

50,000

250,000

250,000

Source

The table shows that load balancing on NSX Edge for productive scenarios is recommended to be organized only starting from the Large size.

That’s all for today. In the next parts, I will go into detail on the configuration of each network service of NSX Edge.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster