Return-Path: X-Original-To: apmail-cloudstack-users-archive@www.apache.org Delivered-To: apmail-cloudstack-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 38C0710BF0 for ; Sun, 1 Dec 2013 20:28:33 +0000 (UTC) Received: (qmail 90023 invoked by uid 500); 1 Dec 2013 20:28:32 -0000 Delivered-To: apmail-cloudstack-users-archive@cloudstack.apache.org Received: (qmail 89993 invoked by uid 500); 1 Dec 2013 20:28:31 -0000 Mailing-List: contact users-help@cloudstack.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: users@cloudstack.apache.org Delivered-To: mailing list users@cloudstack.apache.org Received: (qmail 89985 invoked by uid 99); 1 Dec 2013 20:28:31 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 01 Dec 2013 20:28:31 +0000 X-ASF-Spam-Status: No, hits=0.2 required=5.0 tests=FREEMAIL_ENVFROM_END_DIGIT,RCVD_IN_DNSWL_NONE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of nordlicht1984@hotmail.de designates 157.55.2.45 as permitted sender) Received: from [157.55.2.45] (HELO dub0-omc3-s36.dub0.hotmail.com) (157.55.2.45) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 01 Dec 2013 20:28:27 +0000 Received: from DUB109-W19 ([157.55.2.7]) by dub0-omc3-s36.dub0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675); Sun, 1 Dec 2013 12:28:05 -0800 X-TMN: [tAeg0kWNtd3Zmr4FkEJR4P+XYtFSPb0F] X-Originating-Email: [nordlicht1984@hotmail.de] Message-ID: From: Lisa B. To: "users@cloudstack.apache.org" Subject: RE: Replacing Virtual Router with a custom virtual appliance template Date: Sun, 1 Dec 2013 21:28:04 +0100 Importance: Normal In-Reply-To: <07af01ceee42$b05a6750$110f35f0$@cloudcentral.com.au> References: <07af01ceee42$b05a6750$110f35f0$@cloudcentral.com.au> Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginalArrivalTime: 01 Dec 2013 20:28:05.0239 (UTC) FILETIME=[D6F7B070:01CEEED3] X-Virus-Checked: Checked by ClamAV on apache.org hey michal=2C=0A= =0A= i am not sure if this is what you are looking for but i just came across th= is blog post while tracking down a different problem:=0A= =0A= http://blog.remibergsma.com/2012/08/30/going-beyond-cloudstack-advanced-net= working-how-i-replaced-the-virtual-router-with-my-own-physical-linux-router= /=0A= =0A= good luck!=0A= lisa=0A= =0A= ________________________________=0A= > From: michal.rodzos@cloudcentral.com.au =0A= > To: users@cloudstack.apache.org =0A= > Subject: Replacing Virtual Router with a custom virtual appliance templat= e =0A= > Date: Sun=2C 1 Dec 2013 14:09:02 +1100 =0A= > =0A= > =0A= > Is it possible to create a network offering=2C which would use a custom = =0A= > virtual appliance instead of the default Debian template? =0A= > =0A= > My understanding is currently only following network providers are =0A= > supported/available in ACS: =0A= > =0A= > - Citrix NetScaler =0A= > =0A= > - F5 =0A= > =0A= > - Juniper SRX =0A= > =0A= > - Virtual Router =0A= > =0A= > - Cisco ASA 100v (Citrix CloudPlatform only?) =0A= > =0A= > =0A= > =0A= > I=92ve found a wiki page =0A= > https://cwiki.apache.org/confluence/display/CLOUDSTACK/Palo+Alto+Firewall= +Integration& =0A= > that somebody managed to integrate the Palo Alto Firewall into ACS. =0A= > Plus some other people managed to get the midokura or Nicira to work ? = =0A= > =0A= > So it seems that custom network providers are feasible=85 =0A= > =0A= > I'd like to provide a premium network offering with a commercial =0A= > security gateway/UTM virtual appliance as a network provider. Ie the =0A= > FortiGate UTM provides VPN=2C NAT=2C DNS=2C DHCP=2C routing and other net= work =0A= > features similar to Virtual Router=2C but also offers security features = =0A= > like anitispam=2C virus scanning=2C deep packet inspection=2C IPS etc. So= the =0A= > question is how hard is=2C and how much dev effort is required? =0A= > =0A= > Other option is to create a network like this =0A= > Internet -> ACS VR-> FortiGate TM VM -> customer VMs =0A= > But not sure how can force all the public traffic from the VMs to go =0A= > via the FortiGate? =0A= > =0A= > The environment is XenServer 6.2 and ACS 4.2.1 with Advanced Networking = =0A= > =0A= > Thanks=2C =0A= > Michal =0A= > =0A= > =0A= > =0A= > Regards=2C =0A= > Michal Rodzos =0A= > Solutions Architect =0A= > =0A= > [CloudCentral - Secure Australian =0A= > Cloud] =0A= > Phone: 1300 144 007 | Mobile: +61 421 834 204 =0A= > [View Michal Rodzos' profile on =0A= > LinkedIn]| Skype: =0A= > michal.rodzos | Twitter =0A= > =0A= > =