Creating an MVE Integrated with VMware
This topic describes how to create and configure a Megaport Virtual Edge (MVE) with VMware SD-WAN. Once you have a Megaport account, you use the VMware centralized management console called Orchestrator. In Orchestrator you create and configure the profile and edge device. In the Megaport Portal, you create, administer, maintain, monitor, and terminate MVE.
Before you begin, you need to create a Megaport account:
- New Megaport customers – Log in to the Megaport Portal, create your account, and proceed to your VMware SD-WAN Orchestrator account. For details on setting up a Megaport account, see Registering an Account.
- Existing Megaport customers – Proceed to Creating a VMware edge profile and device to start creating a new MVE.
VMware provides documentation for their SD-WAN product at VMware SD-WAN Documentation.
Before you create an MVE in the Megaport Portal, you need a valid license from VMware. For details on obtaining a VMware license, see Edge Licensing or ask your VMware Sales Associate or Reseller.
This section provides an overview of the configuration steps in VMware Orchestrator and the Megaport Portal.
The basic steps are:
- Create a VMware edge device profile and edge device in Orchestrator.
- Configure the VMware edge device and apply the profile to the device.
- Generate an SSH public key.
- Create an MVE instance in the Megaport Portal.
To get started, you create a default profile so that when the edge device registers to Orchestrator, it retrieves its base configuration, connects to Orchestrator, and enables some specific firewall rules. After that you can manage the MVE device through Orchestrator.
To create an edge profile in Orchestrator
Log in to the VMware SD-WAN Orchestrator.
Click the link for the Customer profile account.
Choose Configure > Profiles.
Click New Profile.
Enter a Profile Name and an optional Description. For example, megaport-default-profile.
To create a virtual edge device in Orchestrator
Select the Device tab.
Select Global Segment from the Configure Segment drop-down.
Enable Cloud VPN.
Unselect all device types, except for Virtual Edge.
Under Device Settings: Virtual Edge, click Edit next to GE1 and GE2 and disable those interfaces sequentially.
Ensure that GE3 is enabled.
GE3 becomes the first available routed interface. Other ports do not require to be disabled and can be left in their current state.
Configure the following options for the GE3 interface:
- Interface Enabled – Select this option.
- Capability – Choose Routed from the drop-down list.
- Addressing Type – Choose DHCP from the drop-down list.
- WAN Overlay – Enable this option and choose Auto-Detect Overlay from the drop-down list.
- All other interfaces – Leave the default values.
Click Update GE3.
Under Wi-Fi Radio, ensure that Radio Enabled is unselected (there are no wireless interfaces).
Click Save Changes in the upper-right corner.
Select the Firewall tab and enter comma-separated IP values for any customer-side management IPs that require access to the edge device.
Ensure that the Firewall Status option is set to On.
Next to Support Access, enter the trusted IP addresses that are allowed access to the device.
Next to SNMP Access, you can optionally allow SNMP access to the WAN public interface. Enter the trusted IP addresses to allow.
Next to Local Web UI Access, enter the trusted IP addresses to allow access to the WAN interface. This is important because you are configuring a VMware Virtual Edge device with no LAN ports and no console.
Accept 80 as the Local Web UI Port Number or change it to match your environment.
Click Save Changes in the upper-right corner.
The next step is to configure and assign the profile to the edge device.
Configuring the VMware edge device
After creating the profile, you will configure the edge device to get it connected to the internet.
To configure a VMware edge device in Orchestrator
In Orchestrator, click the link for the Customer profile account.
Choose Configure > Edges.
In the upper-right corner, click New Edge….
Populate the fields as required for your network.
- Name – Enter a name for the edge device.
- Model – Choose Virtual Edge from the drop-down list.
- Profile – Select the recently created profile to assign to the new edge device.
- Authentication – Choose an authentication option for the edge device. For details on the authentication options, see the VMware SD-WAN documentation.
- Edge License – Choose the license to apply to this edge device. The list displays the licenses assigned to your enterprise. Licenses are grouped by the edge device throughput limit (1 Gbps or 10 Gbps), region, and length of contract. For details on obtaining a VMware license, see Edge Licensing or ask your VMware Sales Associate or Reseller.
- Custom Info (optional) – Enter a description for the edge device.
- Contact Name and Contact Email – Enter a contact name and email address for this device.
The Edge Overview tab lists an activation key. Save the activation key for use in the Megaport Portal.
Make any device-specific changes to the Device, Business Policy, or Firewall parameters. Or, use a device-specific profile to use predefined profile settings.
Click Save Changes in the upper-right corner.
The next step is to generate an SSH key for authentication.
Administrative access to MVE
Megaport MVE and Orchestrator connect through a public/private SSH key pair to establish secure connections. The public SSH key allows you to SSH into Orchestrator and set the administrative password, enable HTTPS access, and optionally register the MVE to Orchestrator.
Megaport supports the 2048-bit RSA key type.
To generate an SSH key pair (Linux/Mac OSX)
- Run the SSH keygen command:
ssh-keygen -f ~/.ssh/megaport-mve-instance-1-2048 -t rsa -b 2048
The key generator command creates an SSH key pair and adds two files to your ~/.ssh directory:
- megaport-mve-instance-1-2048 - contains the private key.
- megaport-mve-instance-1-2048.pub - contains the public key that is authorized to log in to the VMware account.
To generate an SSH key pair (Windows, using PuTTYgen)
- Open PuTTYGen.
- In the Key section, choose RSA 2048 bit and click Generate.
- Move your mouse randomly in the small screen to generate the key pairs.
- Enter a key comment, which will identify the key.
This is convenient when you use several SSH keys.
- Enter a Key passphrase, and re-enter to confirm.
The passphrase is used to protect your key. You will be asked for it when you connect via SSH.
- Click Save private key, choose a location, and click Save.
- Click Save public key, choose a location, and click Save.
Public keys: You’ll copy and paste the contents of the public key file in the Megaport Portal later to distribute the public key to the edge device. Your private key will match the public key to grant access. Only a single private key has access to the edge device for SSH access.
Creating the VMware MVE in the Megaport Portal
Before you create an MVE, you need to determine the best location - one that supports MVE and one that is in the most compatible metro area. You can connect multiple locations to an individual MVE. For location details, see Planning Your Deployment.
You can deploy multiple MVEs within the same metropolitan area for redundancy or capacity reasons.
To create an MVE in the Megaport Portal
- In the Megaport Portal, go to the Services page.
Click Create MVE.
Select the MVE location.
Select a location geographically close to your target branch and/or on-premises locations.
The country you choose must be a market in which you have already registered. To search for your local market in the list, enter a country in the Country Filter or a metro region detail in the Search filter.
If you haven’t registered a billing market in the location where you will deploy the MVE, follow the procedure in Enabling a Billing Market.
Select VMware SD-WAN and the software version.
The MVE will be configured to be compatible with this software version from VMware.
Specify the MVE details:
MVE Name – Specify a name for the MVE that is easily identifiable, particularly if you plan on provisioning more than one. This name appears in the Megaport Portal.
Invoice Reference (optional) – Specify an identifying number for the MVE to be used for billing purposes, such as a purchase order or cost center number.
Size – Select a size from the drop-down list: Small, Medium, or Large. Three sizes are available to support varying numbers of concurrent connections. Individual partner product metrics vary slightly, but in general the small size can handle greater than 30 concurrent branch connections and up to 500 Mbps of traffic, a medium size up to 300 connections and 1 Gbps, and a large size approximately 600 connections and approximately 5 Gbps of traffic.
Orchestrator Address – Enter an FQDN (Fully Qualified Domain Name) or IPv4 or IPv6 address for the Orchestrator where you created the edge device.
Activation Code – Enter the activation key provided to you by Orchestrator after creating the edge device.
SSH Key – Copy and paste the contents of your public SSH key here. You can find the public key in the megaport-mve-instance-1-2048.pub file generated earlier.
Click Next to view the Summary screen.
The monthly rate is based on location and size.
Confirm the configuration and pricing and click Add MVE.
Click Create MVE to add more MVEs in other locations.
Review the Order Services agreement, and click Order Now.
- Click Save to save the configured MVE before placing the order.
- Click Add Promo Code to enter a promotional code, and click Add Code.
Ordering the MVE provisions the instance and assigns IP addresses from the Megaport SDN. The MVE provisioning takes only a few minutes to complete.
Viewing the MVE in the Megaport Portal
After creating the MVE, you can view it in the Megaport Portal.
To view an MVE in the Megaport Portal
- Go to the Services page.
As part of the MVE provisioning, Megaport creates a transit Virtual Cross Connect (VXC) to provide internet connectivity and to allow MVE to register and communicate with the SD-WAN overlay network. The overlay network is created and maintained by VMware SD-WAN to provide secure tunnels from the branch locations. The transit VXC is a fixed size, based on the size of the MVE. You cannot modify or delete the transit VXC. Click the gear icon to view its details. The transit VXC icon differs from a standard VXC icon in the Megaport Portal, as shown in the image.
The Public IP Addresses (IPv4 or IPv6) are the addresses of the MVE device. By this time, the new MVE should be registered to your Orchestrator and ready for additional configuration.
Validating your connection
- In Orchestrator under Test & Troubleshoot > Remote Diagnostics, select the MVE and click Run for Troubleshoot BGP - Show BGP Summary to verify the BGP session and ensure the edge device is up.
You can also check connectivity and BGP status from the CLI of the edge device. For details, see Reviewing your VMware MVE connection settings.
Viewing the MVE in Orchestrator
After creating the MVE, you can monitor the status in Orchestrator.
To view an MVE in Orchestrator
- Log in to Orchestrator.
- Choose Monitor > Network Overview.
Click the MVE edge device from the list.
The Link Status and Bandwidth Usage metrics are displayed.
Once the MVE is provisioned with an Active status, the next step is to create VXCs to connect the Megaport backbone to other MVEs or cloud service providers. You can optionally connect a physical Port to the MVE through a private VXC or connect to a service provider in the Megaport Marketplace.
For details, see Creating a VXC.
Before deleting an MVE, ensure that you delete all VXCs connected to the MVE. For details on deleting a VXC, see Deleting a VXC.
To delete an MVE
In the Megaport Portal, go to the Services page.
Click the trash can icon next to the MVE you want to delete.
A list of all services connected to the MVE appear.
Click Yes - Terminate Services to confirm the MVE termination, or click No, Keep Services to cancel.
In Orchestrator, choose Configure > Edges.
Select the edge device to delete.
Click Actions in the upper-right corner and then click Delete Edge.
Follow the prompts in Orchestrator to delete the edge.