Network Virtualization in The Hybrid Cloud Stanislav Zhelyazkov Microsoft MVP 21/11/2013
* VMM 2012 SP1 and R2 only supports creation of isolated PVLAN VMs
Load balancer back end and internet facing
Different subnets GRE Key 5001 MAC CA GRE Key 6001 MAC CA VSIDProvider AddressCustomer Address NVGRE Packet
Contoso VM Network Northwind VM Network Fabrikam VM Network Internet Hoster
Contoso VM Network Northwind VM Network Fabrikam VM Network Internet Hoster BGP
TCP/IP VM
TCP/IP VM
IKE Phase 1 Setup PropertySetting IKE VersionIKEv2 Diffie-Hellman GroupGroup 2 (1024 bit) Authentication MethodPre-Shared Key Encryption Algorithms AES256 3DES Hashing AlgorithmSHA1(SHA128) Phase 1 Security Association (SA) Lifetime (Time) 28,800 seconds IKE Phase 2 Setup PropertySetting IKE VersionIKEv2 Hashing AlgorithmSHA1(SHA128) Phase 2 Security Association (SA) Lifetime (Time) - Phase 2 Security Association (SA) Lifetime (Throughput) - IPsec SA Encryption & Authentication Offers (in the order of preference) See Dynamic Routing Gateway IPsec Security Association (SA) OffersDynamic Routing Gateway IPsec Security Association (SA) Offers Perfect Forward Secrecy (PFS)No Dead Peer DetectionSupported
Vendor Device FamilyMinimum OS Version Configuration Template CiscoASRIOS 15.2Cisco ASR templates CiscoISRIOS 15.1Cisco ISR templates JuniperSRXJunOS 11.4Juniper SRX templates JuniperJ-SeriesJunOS 11.4Juniper J-series templates JuniperISGScreenOS 6.3Juniper ISG templates JuniperISGScreenOS 6.3Juniper SSG templates Microsoft Routing and Remote Access Service Windows Server 2012Routing and Remote Access Service templates