Networking enhancements
This release includes the following networking enhancements:
- Flexible network containers that support the following operations:
- Toggling on/off the following components in a container blueprint:
- Networks directly from the user interface
- Load Balancer nodes/pairs directly from the user interface
- Firewall nodes/pairs indirectly when the networks that the firewall is serving are toggled
- Zones indirectly when networks in the zone are toggled
- Overlapping private IP addresses
- Input of network and NAT addresses in the UI when creating or editing a network container
For more information, see Managing-dynamic-components-for-network-containers.
- Toggling on/off the following components in a container blueprint:
- Dynamic pod scripts that support the following operations:
- Adding or deleting chained IP address range
- Adding chained IP address pool
- Adding or deleting chained VLAN pool
- The dynamic network container topology is displayed in a new graphical view, as described in Working in the graphical view of dynamic components - create mode.
- Zone constraints relaxation — Load balancers and firewalls in a container do not belong to a particular zone:
- A virtual load balancer (VLB) can balance traffic for network interface card (NIC) attach points which may or may not be in the same zone, and a zone can be served by multiple VLBs.
- Each firewall ACL can be tied to a particular endpoint that it controls traffic for, where an endpoint can either be a NIC attach point, a load balancer pool attach point, or an external network to which the container is connected.
- Multi-ACL firewall rules — You can now manage both inbound and outbound ACLs of each firewall network interface for each firewall in a network container. See Managing-multiple-ACLs-on-virtual-firewalls.
- Network path management — You can specify firewall updates between endpoints at a high level without having to worry about the underlying ACLs on which firewall network interfaces are actually involved. An endpoint can be internal (NIC/VIP address/subnet) or external (customer subnet).
- Virtual port types — You now have flexibility in naming virtual port types. Substitution parameters can now be used to name a virtual port type. See Virtual-port-type-names.
In service blueprints, network path creation has replaced firewall rule creation.
- Cloud end users can now add a new NIC and guide the network placement.
- Enhanced network address translation (NAT) support for server NICs and load balancer pool VIPs.
- Tenant administrators can now view Logical Hosting Environments (LHE) if the tenant that they belong to is the only tenant mapped to that LHE.
- Support for
- Cisco VMDC 2.0 - (VMDC 2.2 supported except for VSG)
- F5 load balancers
- Juniper SRX firewalls
- VMware DVS
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*