Learn how to create, configure, and effectively manage your network (IP spaces, Edge gateways and providers, and private network) from the Public VCF as-a-Service control panel.
Requirements
If you are unsure how to log in to your organization's web portal, first refer to this guide.
- A web browser
- A Public VCF as-a-Service account with sufficient rights
- Have read the Public VCF as-a-Service guides:
Public VCF as-a-Service - Network concepts and best practices
Public VCF as-a-Service - The fundamentals of Public VCF as-a-Service
Public VCF as-a-Service - Logging in to your organization
Instructions
Before creating a network, the main concept to understand with Public VCF as-a-Service is the IP space. For example, consider the default one created with your Public VCF as-a-Service organization:
The internal scope represents the entire IP of your future network, e.g., 192.168.0.0/24.
- IP ranges are IPs that you can request individually for your services (VMs not using DHCP, for example).
- IP prefixes are the IP subnet that you can use in your Edge Gateway, for example.
- IP ranges and IP prefixes cannot overlap and must be within the Internal Scope.
Create the IP space (recommended)
You can use a new method of managing your IP space in Public VCF as-a-Service with the new IP space management subsystem.
To connect to your Public VCF as-a-Service environment, follow this guide.
Under the Networking section, select the IP Spaces tab and click NEW.
General
The Create IP Space window will appear, where you can choose a name for your space and add an optional description.
Click NEXT to continue.
Network Topology
Leave all options in the Network Topology section disabled (unchecked) and click NEXT to continue.
Scope
Choose the internal and external scopes with which you want to access your network.
- Internal Scope: Represents the IPs used in this local data center south of Provider Gateway. The IPs in this scope are used to configure services and networks.
- External Scope: Represents IPs used outside the data center north of Provider Gateway. This value is used when automatically generating default SNAT rules.
Be sure to click + ADD to add your scopes, and then click NEXT to continue.
IP Ranges
Click ADD.
The IP ranges must correspond to the internal scope of this IP space (the range of IPs you want to make available for your machines).
Example: 172.15.0.2-172.15.0.100.
Click NEXT to continue.
IP Prefixes
Click ADD.
IP prefixes must match the internal scope of this IP space.
Add your sequences and prefixes.
Example: 172.15.1.0/24 | 1.
The sequence addition is automatically added as a preview if it is conclusive.
Click NEXT to continue.
Review
In the final section, review all your settings. Once you have checked them, confirm your choices by clicking FINISH.
Create a data center group (optional)
This step is optional but recommended for the vast majority of use cases (e.g. when two VDC networks need to add up).
We will now create a data center group to optimize the management of our network with this new Public VCF as-a-Service feature.
Go to the Networking section, choose the Data Center Groups, tab, and click NEW.
Starting VDC
Select a vDC that will be part of the group. When you select a startup vDC, you can create a group in which this vDC can participate. Then, click on NEXT.
General
Choose the name of your data center group and a short description, then click NEXT.
Participating VDCs
Select the additional vDCs that you want to be part of the group, then click NEXT.
Review
Check your settings and confirm them by clicking FINISH.
Create an Edge Gateway (optional)
NOTE: At this time, it is not possible to create an Edge Gateway.
Create a private network
We will now create a new network and attach our preconfigured settings.
Choose the Networking section, select the Networks, tab, and click NEW.
Scope
- Organization Virtual Data Center: Provides connectivity for VMs in the selected vDC only.
- Data Center Group: Provides connectivity for the VMs of all virtual domain controllers participating in the data center group.
Select the Organization Virtual Data Center or the Data Center Group in which you want to create your network and click NEXT.
Network Type
Next, select the type of network you want to create.
You can create a routed or isolated Network type to suit your needs. The "routed" allows incoming traffic, while the "isolated" forbids it.
NOTE: At this time, it is not possible to create a routed network.
Public VCF as-a-Service definition:
- Routed: This type of network provides controlled access to machines and networks outside of the vDC or vDC group through an edge gateway.
- Isolated: This type of network provides a fully isolated environment, accessible only by this organization's vDC or vDC group.
For a routed network, if your vDC does not have an Edge Gateway available, you will get this error: The vDC “vdc-us-east-vin-XXX-XXX” has no Edge Gateway available.
You can either create another "Edge Gateway" or use the "Data Center Groups" available to provide connectivity for the VMs of all participating vDCs.
The Routed type of network provides controlled access to machines and networks outside of the vDC or vDC group through an edge gateway.
To continue, click NEXT.
General
In the general section, you can add the name of your network, a description, and the IP space created earlier.
If it has been created, it will automatically appear in the list (see the Gateway CIDR in the next screenshot).
Dual-Stack Mode: Enables the network to have one IPv4 subnet and one IPv6 subnet.
NOTE: You cannot undo the activation of dual stack networking mode.
In this tutorial, we will leave this option disabled.
To continue, click NEXT.
Static IP Pools
Here, you can allocate your network’s IP range. In this example, we will allocate 98 IPs:
Once your IP range has been allocated, check that there is no space before and after the dash between the two IP ranges as well as before and after your two IPs.
To continue, click NEXT.
DNS
In this section, add the DNS servers for your network.
Segment Profile Templates (Optional)
Segment profile templates can be defined here.
NOTE: At this time, segment profiles are not available in the US.
Ready to Complete
Do a final check of the settings you defined, then click FINISH.
Your network is now fully created and ready to use.
Go further
For more information and tutorials, please see our other Public VCF as-a-Service or Hosted Private Cloud guides. You can also explore the guides for other OVHcloud products and services.
If you need training or technical assistance to implement our solutions, contact your sales representative or click on this link to get a quote and ask our Professional Services experts for a custom analysis of your project.