diff options
| -rw-r--r-- | doc/book-enea-nfv-access-getting-started/doc/demo_usecases.xml | 303 | ||||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br.png | bin | 0 -> 7778 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br2.png | bin | 0 -> 13517 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_dpdk_int_bind.png | bin | 0 -> 6872 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fg_instantiation.png | bin | 0 -> 23383 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fortigate_onboard.png | bin | 0 -> 7298 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_lanbr.png | bin | 0 -> 12255 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution.png | bin | 0 -> 100793 bytes | |||
| -rwxr-xr-x | doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution_test.png | bin | 0 -> 134590 bytes |
9 files changed, 302 insertions, 1 deletions
diff --git a/doc/book-enea-nfv-access-getting-started/doc/demo_usecases.xml b/doc/book-enea-nfv-access-getting-started/doc/demo_usecases.xml index 31894dd..cdcb931 100644 --- a/doc/book-enea-nfv-access-getting-started/doc/demo_usecases.xml +++ b/doc/book-enea-nfv-access-getting-started/doc/demo_usecases.xml | |||
| @@ -1898,4 +1898,305 @@ Run: tail -f /opt/testpmd-out</programlisting> | |||
| 1898 | </note> | 1898 | </note> |
| 1899 | </section> | 1899 | </section> |
| 1900 | </section> | 1900 | </section> |
| 1901 | </chapter> | 1901 | |
| 1902 | <section id="inband_management"> | ||
| 1903 | <title>In-band Management</title> | ||
| 1904 | |||
| 1905 | <para>In the case of an NFV Access device installed on a network with | ||
| 1906 | limited access, In-band management can be a solution to manage the device | ||
| 1907 | and to pass data traffic (through only one physical interface). This demo | ||
| 1908 | use-case will show how to enable the In-band management on the NFV Access | ||
| 1909 | device and to access a VNF on the same physical interface.</para> | ||
| 1910 | |||
| 1911 | <figure> | ||
| 1912 | <title>NFV Access In-band management solution setup</title> | ||
| 1913 | |||
| 1914 | <mediaobject> | ||
| 1915 | <imageobject> | ||
| 1916 | <imagedata align="center" fileref="images/uc_ibm_solution.png" | ||
| 1917 | scale="50" /> | ||
| 1918 | </imageobject> | ||
| 1919 | </mediaobject> | ||
| 1920 | </figure> | ||
| 1921 | |||
| 1922 | <para>Setup uses the following network configuration:</para> | ||
| 1923 | |||
| 1924 | <itemizedlist> | ||
| 1925 | <listitem> | ||
| 1926 | <para>1 x Network Interface for WAN and management.</para> | ||
| 1927 | </listitem> | ||
| 1928 | |||
| 1929 | <listitem> | ||
| 1930 | <para>1 x Network Interface for LAN.</para> | ||
| 1931 | </listitem> | ||
| 1932 | </itemizedlist> | ||
| 1933 | |||
| 1934 | <para>For prerequisites and further details, please see <xref | ||
| 1935 | linkend="inband_management" /> and <xref | ||
| 1936 | linkend="vnf_fortigate" />.</para> | ||
| 1937 | |||
| 1938 | <section id="mg_activation"> | ||
| 1939 | <title>In-band management activation for FortiGate VNF | ||
| 1940 | Instantiation</title> | ||
| 1941 | |||
| 1942 | <para>In-band management activation is done by creating a special bridge | ||
| 1943 | which manages all traffic from the WAN interface. The active physical | ||
| 1944 | port of the device (used by the device manager to communicate with the | ||
| 1945 | uCPE Manager) will be connected to the In-band management bridge. Once | ||
| 1946 | the In-band management bridge is activated, communication to the uCPE | ||
| 1947 | Manager will be reactivated, passing through the bridge.</para> | ||
| 1948 | |||
| 1949 | <note> | ||
| 1950 | <para>No other physical port for In-band management can be | ||
| 1951 | used.</para> | ||
| 1952 | </note> | ||
| 1953 | |||
| 1954 | <orderedlist> | ||
| 1955 | <listitem> | ||
| 1956 | <para>Create an In-band management WAN Bridge:</para> | ||
| 1957 | |||
| 1958 | <itemizedlist> | ||
| 1959 | <listitem> | ||
| 1960 | <para>Select the <literal>Device</literal> menu.</para> | ||
| 1961 | </listitem> | ||
| 1962 | |||
| 1963 | <listitem> | ||
| 1964 | <para>In the Configuration tab select | ||
| 1965 | <literal>OpenVSwitch.</literal></para> | ||
| 1966 | </listitem> | ||
| 1967 | |||
| 1968 | <listitem> | ||
| 1969 | <para>Select <literal>Bridges</literal> and click | ||
| 1970 | <literal>Add</literal>.</para> | ||
| 1971 | </listitem> | ||
| 1972 | |||
| 1973 | <listitem> | ||
| 1974 | <para>Use <literal>dpdkWAN</literal> as the | ||
| 1975 | <literal>ovs-bridge-type</literal>.</para> | ||
| 1976 | </listitem> | ||
| 1977 | </itemizedlist> | ||
| 1978 | |||
| 1979 | <figure> | ||
| 1980 | <title>Create In-band management WAN bridge</title> | ||
| 1981 | |||
| 1982 | <mediaobject> | ||
| 1983 | <imageobject> | ||
| 1984 | <imagedata align="center" fileref="images/uc_ibm_br.png" | ||
| 1985 | scale="75" /> | ||
| 1986 | </imageobject> | ||
| 1987 | </mediaobject> | ||
| 1988 | </figure> | ||
| 1989 | </listitem> | ||
| 1990 | |||
| 1991 | <listitem> | ||
| 1992 | <para>Bind the physical port which will be used for LAN access to | ||
| 1993 | <literal>dpdk</literal>:</para> | ||
| 1994 | |||
| 1995 | <itemizedlist> | ||
| 1996 | <listitem> | ||
| 1997 | <para>Select the <literal>Device</literal> menu.</para> | ||
| 1998 | </listitem> | ||
| 1999 | |||
| 2000 | <listitem> | ||
| 2001 | <para>In the Configuration tab select | ||
| 2002 | <literal>OpenVSwitch</literal>.</para> | ||
| 2003 | </listitem> | ||
| 2004 | |||
| 2005 | <listitem> | ||
| 2006 | <para>Select the <literal>Host Interfaces</literal> menu and | ||
| 2007 | click <literal>Add</literal>.</para> | ||
| 2008 | </listitem> | ||
| 2009 | |||
| 2010 | <listitem> | ||
| 2011 | <para>Use <literal>dpdk</literal> as the | ||
| 2012 | <literal>ovs-bridge-type</literal>.</para> | ||
| 2013 | </listitem> | ||
| 2014 | </itemizedlist> | ||
| 2015 | |||
| 2016 | <figure> | ||
| 2017 | <title>Bind LAN physical port to dpdk</title> | ||
| 2018 | |||
| 2019 | <mediaobject> | ||
| 2020 | <imageobject> | ||
| 2021 | <imagedata align="center" | ||
| 2022 | fileref="images/uc_ibm_dpdk_int_bind.png" | ||
| 2023 | scale="75" /> | ||
| 2024 | </imageobject> | ||
| 2025 | </mediaobject> | ||
| 2026 | </figure> | ||
| 2027 | </listitem> | ||
| 2028 | |||
| 2029 | <listitem> | ||
| 2030 | <para>Create a LAN Bridge:</para> | ||
| 2031 | |||
| 2032 | <itemizedlist> | ||
| 2033 | <listitem> | ||
| 2034 | <para>Select the <literal>Device.</literal></para> | ||
| 2035 | </listitem> | ||
| 2036 | |||
| 2037 | <listitem> | ||
| 2038 | <para>In the Configuration menu select | ||
| 2039 | <literal>OpenVSwitch.</literal></para> | ||
| 2040 | </listitem> | ||
| 2041 | |||
| 2042 | <listitem> | ||
| 2043 | <para>Open the <literal>Bridges</literal> menu and click | ||
| 2044 | <literal>Add.</literal></para> | ||
| 2045 | </listitem> | ||
| 2046 | </itemizedlist> | ||
| 2047 | |||
| 2048 | <figure> | ||
| 2049 | <title>Create LAN bridge</title> | ||
| 2050 | |||
| 2051 | <mediaobject> | ||
| 2052 | <imageobject> | ||
| 2053 | <imagedata align="center" fileref="images/uc_ibm_lanbr.png" | ||
| 2054 | scale="75" /> | ||
| 2055 | </imageobject> | ||
| 2056 | </mediaobject> | ||
| 2057 | </figure> | ||
| 2058 | |||
| 2059 | <para>At this step the following bridges should exist:</para> | ||
| 2060 | |||
| 2061 | <figure> | ||
| 2062 | <title>Bridges</title> | ||
| 2063 | |||
| 2064 | <mediaobject> | ||
| 2065 | <imageobject> | ||
| 2066 | <imagedata align="center" fileref="images/uc_ibm_br2.png" | ||
| 2067 | scale="65" /> | ||
| 2068 | </imageobject> | ||
| 2069 | </mediaobject> | ||
| 2070 | </figure> | ||
| 2071 | |||
| 2072 | <note> | ||
| 2073 | <para>The WAN port of the very first VNF instantiated on the | ||
| 2074 | device must be connected to the <literal>ibm-wan-br | ||
| 2075 | bridge</literal>. All other VNFs must be connected in chain with | ||
| 2076 | the first VNF.</para> | ||
| 2077 | </note> | ||
| 2078 | </listitem> | ||
| 2079 | |||
| 2080 | <listitem> | ||
| 2081 | <para>Onboard the first VNF and instantiate it on the device:</para> | ||
| 2082 | |||
| 2083 | <itemizedlist> | ||
| 2084 | <listitem> | ||
| 2085 | <para>Select the <literal>Device.</literal></para> | ||
| 2086 | </listitem> | ||
| 2087 | |||
| 2088 | <listitem> | ||
| 2089 | <para>Select the <literal>VNF</literal> menu.</para> | ||
| 2090 | </listitem> | ||
| 2091 | |||
| 2092 | <listitem> | ||
| 2093 | <para>In the <literal>Descriptors</literal> menu, choose the | ||
| 2094 | <literal>VNF Package</literal> option.</para> | ||
| 2095 | </listitem> | ||
| 2096 | |||
| 2097 | <listitem> | ||
| 2098 | <para>Browse and select the Fortigate bundle you require, before | ||
| 2099 | pressing the <literal>Send</literal> button.</para> | ||
| 2100 | </listitem> | ||
| 2101 | </itemizedlist> | ||
| 2102 | |||
| 2103 | <figure> | ||
| 2104 | <title>Onboard Fortigate VNF</title> | ||
| 2105 | |||
| 2106 | <mediaobject> | ||
| 2107 | <imageobject> | ||
| 2108 | <imagedata align="center" | ||
| 2109 | fileref="images/uc_ibm_fortigate_onboard.png" | ||
| 2110 | scale="50" /> | ||
| 2111 | </imageobject> | ||
| 2112 | </mediaobject> | ||
| 2113 | </figure> | ||
| 2114 | </listitem> | ||
| 2115 | |||
| 2116 | <listitem> | ||
| 2117 | <para>Add the VNF instance:</para> | ||
| 2118 | |||
| 2119 | <itemizedlist> | ||
| 2120 | <listitem> | ||
| 2121 | <para>Select the <literal>Device.</literal></para> | ||
| 2122 | </listitem> | ||
| 2123 | |||
| 2124 | <listitem> | ||
| 2125 | <para>Select the <literal>VNF</literal> menu.</para> | ||
| 2126 | </listitem> | ||
| 2127 | |||
| 2128 | <listitem> | ||
| 2129 | <para>Choose the <literal>Instances</literal> option, select the | ||
| 2130 | VNF configuration you desire and press | ||
| 2131 | <literal>Add.</literal></para> | ||
| 2132 | </listitem> | ||
| 2133 | |||
| 2134 | <listitem> | ||
| 2135 | <para>Browse and select the Fortigate bundle you require, before | ||
| 2136 | pressing the <literal>Send</literal> button.</para> | ||
| 2137 | </listitem> | ||
| 2138 | </itemizedlist> | ||
| 2139 | |||
| 2140 | <figure> | ||
| 2141 | <title>Instantiate Fortigate VNF</title> | ||
| 2142 | |||
| 2143 | <mediaobject> | ||
| 2144 | <imageobject> | ||
| 2145 | <imagedata align="center" | ||
| 2146 | fileref="images/uc_ibm_fg_instantiation.png" | ||
| 2147 | scale="65" /> | ||
| 2148 | </imageobject> | ||
| 2149 | </mediaobject> | ||
| 2150 | </figure> | ||
| 2151 | </listitem> | ||
| 2152 | </orderedlist> | ||
| 2153 | |||
| 2154 | <para>Once the VNF is instantiated, the setup is complete and ready for | ||
| 2155 | testing. Connect the test machine to the LAN port. It will receive an IP | ||
| 2156 | address from the Fortigate VNF and be able to access the | ||
| 2157 | internet.</para> | ||
| 2158 | </section> | ||
| 2159 | |||
| 2160 | <section id="test_fortvnf_inband"> | ||
| 2161 | <title>Testing the Fortigate VNF In-band management activation</title> | ||
| 2162 | |||
| 2163 | <figure> | ||
| 2164 | <title>Test setup</title> | ||
| 2165 | |||
| 2166 | <mediaobject> | ||
| 2167 | <imageobject> | ||
| 2168 | <imagedata align="center" | ||
| 2169 | fileref="images/uc_ibm_solution_test.png" scale="50" /> | ||
| 2170 | </imageobject> | ||
| 2171 | </mediaobject> | ||
| 2172 | </figure> | ||
| 2173 | |||
| 2174 | <para>At this stage, three types of traffic are passing through the WAN | ||
| 2175 | port on the same IP address: </para> | ||
| 2176 | |||
| 2177 | <itemizedlist> | ||
| 2178 | <listitem> | ||
| 2179 | <para>Device management traffic from uCPE Manager.</para> | ||
| 2180 | </listitem> | ||
| 2181 | |||
| 2182 | <listitem> | ||
| 2183 | <para>Fortigate management interface traffic from a web | ||
| 2184 | browser.</para> | ||
| 2185 | </listitem> | ||
| 2186 | |||
| 2187 | <listitem> | ||
| 2188 | <para>Data traffic from the LAN to the internet.</para> | ||
| 2189 | </listitem> | ||
| 2190 | </itemizedlist> | ||
| 2191 | |||
| 2192 | <para>Having access from the uCPE Manager to the device as shown above, | ||
| 2193 | demonstrates that device management traffic passes through the in-band | ||
| 2194 | management WAN bridge successfully.</para> | ||
| 2195 | |||
| 2196 | <para>To access the management interface of the VNF, connect from a web | ||
| 2197 | browser to the public IP address of the device e.g. | ||
| 2198 | <literal>https://<IP></literal>. From a Test machine connected on | ||
| 2199 | LAN port, try a test ping to the internet e.g. "ping 8.8.8.8".</para> | ||
| 2200 | </section> | ||
| 2201 | </section> | ||
| 2202 | </chapter> \ No newline at end of file | ||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br.png new file mode 100755 index 0000000..f28678b --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br2.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br2.png new file mode 100755 index 0000000..72f8178 --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_br2.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_dpdk_int_bind.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_dpdk_int_bind.png new file mode 100755 index 0000000..ea1fef7 --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_dpdk_int_bind.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fg_instantiation.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fg_instantiation.png new file mode 100755 index 0000000..9b4d020 --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fg_instantiation.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fortigate_onboard.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fortigate_onboard.png new file mode 100755 index 0000000..6fa40bd --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_fortigate_onboard.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_lanbr.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_lanbr.png new file mode 100755 index 0000000..18e074e --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_lanbr.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution.png new file mode 100755 index 0000000..10ed27d --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution.png | |||
| Binary files differ | |||
diff --git a/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution_test.png b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution_test.png new file mode 100755 index 0000000..7006068 --- /dev/null +++ b/doc/book-enea-nfv-access-getting-started/doc/images/uc_ibm_solution_test.png | |||
| Binary files differ | |||
