diff --git a/README.md b/README.md new file mode 100644 index 0000000..375826c --- /dev/null +++ b/README.md @@ -0,0 +1,64 @@ +# Quick Start + +This is a conceptual Demo Scenario that will help you to bring highly available and secured connectivity with dynamic routing between Cloud and On-Prem using regular Internet circuits. + +>Key idea of this scenario based on limitations coming from On-Prem side which as two Internet circuits (Main and Backup where Backup is the `Radio Bridge`) + +The materials from this repository will help you quickly build from the scratch the following network topology: + +[Target Topology](img/topology.svg) + +To prepare your admin workstation (desktop, laptop or maybe something else) follow these steps: + +1. Prepare your VK Cloud project (enable CLI and API access): [URL](https://cloud.vk.com/docs/en/tools-for-using-services/api/rest-api/enable-api) +2. Create and upload your SSH key into the cloud admin account: [URL](https://cloud.vk.com/docs/tools-for-using-services/vk-cloud-account/instructions/account-manage/keypairs#importing_existing_key) +3. Install Terraform components depending on your OS: [URL](https://cloud.vk.com/docs/en/tools-for-using-services/terraform/quick-start) +4. Install Ansible components depending on your OS: [URL](https://docs.ansible.com/projects/ansible/latest/installation_guide/intro_installation.html#pipx-install) +5. Install GIT components and copy this repo onto your admin workstation + +Additional Steps: + +- Use you private SSH key within Terraform and Ansible +- Use proper account credentials within Terraform + +# Under the Hood + +>Main part of thies scenario related to the routers (a pair of IaaS Virtual Machines (`IaaS Routers`) converted into traditional routers with advanced functionoality) + +**Terraform** + +Provisions a pair of `IaaS Routers` with internal and external ports. Includes supplimentary Shell script (which is a part of Terraform manifest) to maintain configuration across reboots. + +**Ansible** + +Configure `IaaS Routers` using role-based playbooks controlled via the [Inventory File](ansible/inventory.ini) + +**Additional Software Used:** + +- strongSwan (to manage IPsec) +- FRR (to manage BGP) +- Keepalived (VRRP) + +[Private and Public Ports](img/ports.svg) + +Each IaaS Router will use two secured connections to On-Prem environment through the Internet: + +- IPsec Site-to-Site in Transport Mode (to protect GRE Tunnels) +- GRE Tunnel (to transfer a data) + +[Secured Connections](img/connections.svg) + +GRE Tunnels topology clearly ecxplained in the following diagram: + +[GRE Tunnels](img/tunnels.svg) + +**High Availability Design** + +BGP peering eliminates single points of failure on the Cloud side through: + +- Bidirectional eBGP sessions from each `IaaS Router` to On-Premises +- Optimized route metrics reflecting circuit priority (Primary/Backup) +- Automatic failover during circuit failures (including Cloud Availability Zone failures) +- Asymmetric routing prevention via MED and Local Preference configuration + +[BGP Peering](img/bgp.svg) \ No newline at end of file diff --git a/img/bgp.svg b/img/bgp.svg new file mode 100644 index 0000000..01f4151 --- /dev/null +++ b/img/bgp.svg @@ -0,0 +1,4 @@ + + + +
CIDR: 10.200.0.0/24
MED: 200
Router1
Router Infra
Router2
Internet
ISP-1
ISP-2
10.200.10.0/24
CIDR: 10.200.0.0/24
MED: 100
CIDR: 10.200.0.0/24
MED: 300
CIDR: 10.200.0.0/24
MED: 400
CIDR: 192.168.1.0/24
MED: 200
CIDR: 192.168.1.0/24
MED: 100
CIDR: 192.168.1.0/24
MED: 300
CIDR: 192.168.1.0/24
MED: 400
192.168.1.0/24
BGP ASN Cloud:
65021
BGP ASN Infra:
65011
\ No newline at end of file diff --git a/img/connections.svg b/img/connections.svg new file mode 100644 index 0000000..82e4c0a --- /dev/null +++ b/img/connections.svg @@ -0,0 +1,4 @@ + + + +
Router
Infra
Router2
Router1
BGP
GRE I1R1
IPsec I1R1
BGP
GRE I2R1
IPsec I2R1
BGP
GRE I2R2
IPsec I2R2
BGP
GRE I1R2
IPsec I1R2
Internet
ISP-1
ISP-2
\ No newline at end of file diff --git a/img/ports.svg b/img/ports.svg new file mode 100644 index 0000000..7994bd7 --- /dev/null +++ b/img/ports.svg @@ -0,0 +1,4 @@ + + + +
Priv-SRV-01
Priv-SRV-02
Priv-SRV-03
Router2
Router1
VRRP
M
B
Private Network Port
Public Network Port
Internet
\ No newline at end of file diff --git a/img/topology.svg b/img/topology.svg new file mode 100644 index 0000000..8e554be --- /dev/null +++ b/img/topology.svg @@ -0,0 +1,4 @@ + + + +
VK Cloud
Зона доступности ME1
Зона доступности MS1
Priv-SRV-01
Priv-SRV-02
Priv-SRV-03
Router2
Router1
Приватная сеть в Облаке
Приватная подсеть в Облаке
Сети Облака с подключением к Internet
Инфраструктура
клиента
Сети в инфраструктуре клиента
Infra-SRV-01
Infra-SRV-02
Infra-SRV-03
Router
Infra
Internet
ISP-1
ISP-2
\ No newline at end of file diff --git a/img/tunnels.svg b/img/tunnels.svg new file mode 100644 index 0000000..33dff82 --- /dev/null +++ b/img/tunnels.svg @@ -0,0 +1,4 @@ + + + +
GRE I2R1:172.17.1.4/30
Router1
Router Infra
Router2
Internet
ISP-1
ISP-2
10.200.10.0/24
GRE I1R1: 172.17.1.0/30
GRE I1R2: 172.17.2.0/30
GRE I2R2: 172.17.2.4/30
192.168.1.0/24
.1.1
.1.5
.2.5
.2.1
.1.2
.1.6
.2.2
.2.6
.254
.253
.1
.1
\ No newline at end of file