Provision AWS Compute and Networking Components
Set up EC2 instances, storage, networking, and load balancing for the cluster.
This topic explains how to configure security groups to control access to cluster nodes and services, and create and configure the core AWS infrastructure for the deployment. It includes launching EC2 instances, configuring storage and networking, and setting up target groups and load balancers. These components provide the compute capacity and connectivity required for the Routing Director cluster.
Perform the following steps:
Create the Security Groups
After importing the Routing Director image to Amazon Machine Image (AMI), you must create the security groups to allow traffic to and from the VMs and the load balancer.
Create EC2 Instance Security Group
| Rule | Direction | Protocol/Port | Source/Destination | Description |
|---|---|---|---|---|
|
Rule 1 |
Inbound |
TCP/22 |
0.0.0.0/0 |
For all SSh management |
|
Rule 2 |
Inbound |
TCP/30011-30024 |
0.0.0.0/0 |
NodePort; to allow connection from the routers and the source-IP addresses to connect to the GUI |
|
Rule 3 |
Inbound |
any |
VPC subnet IP range |
Allow all intra-VPC communication |
|
Rule 4 |
Outbound |
any |
any |
Allow all outbound traffic from the VMs |
To determine the VPC subnet IP range:
Navigate to the VPC Dashboard.
Click VPCs. The VPC that you plan to use is listed.
Scroll to the IPv4 CIDR column of the VPC you plan to use. Note down the IPv4 subnet displayed. You will need to enter this when creating Rule 3 of the security group.
To create a security group to allow the traffic detailed in Table 1, perform the following steps:
Navigate to the EC2 > Security Groups page. Click Create new security group at the top right corner of the page.
Enter basic details such as a name in Security group name and description for the security group in Description. For example, enter the security group name as EC2-sg.
Select the VPC on which you want to deploy the cluster node VMs.
Expand Inbound rules.
Enter information for the inbound rules by referring to the following table. After entering the values for a rule, click Add rule to enter the values for the next rule.
Table 2: Field Description Rule 1 Type
Select Custom TCP.
Port range
Enter 22.
Source
Select Anywhere-IPv4.
Description (Optional)
All SSH management
Rule 2 Type
Select Custom TCP.
Port range
Enter 30011-30024.
Source
Select Anywhere-IPv4.
Description (Optional)
To allow connection from the routers and the source-IP addresses to connect to the GUI
Rule 3 Type
Select All traffic.
Source
Enter the VPC subnet IP range in CIDR notation that you determined earlier.
Description (Optional)
Allow all intra-VPC communication
Expand Outbound rules.
Enter information for the outbound rule by referring to the following table.
Table 3: Field Description Rule 4 Type
Select All traffic.
Source
Select Anywhere-IPv4.
Description (Optional)
Allow all outbound traffic from the VMs
Click Create security group to create the group. The group EC2-sg is listed under EC2 > Security Groups.
Create Load Balancer Security Group
| Rule | Direction | Protocol/Port | Source/Destination | Description |
|---|---|---|---|---|
|
Rule 1 |
Inbound |
TCP/443 |
0.0.0.0/0 |
For access to the GUI Allow from everywhere |
|
Rule 2 |
Inbound |
TCP/2200 |
0.0.0.0/0 |
For NETCONF access |
|
Rule 3 |
Inbound |
TCP/4189 |
0.0.0.0/0 |
For PCEP |
| Rule 4 |
Inbound |
UDP/4739 |
0.0.0.0/0 |
For routing observability CRPD |
| Rule 5 |
Inbound |
TCP/5432 |
0.0.0.0/0 |
For routing observability IPFIX health-check |
|
Rule 6 |
Inbound |
TCP/6800 |
0.0.0.0/0 |
For active assurance TAGW |
|
Rule 7 |
Inbound |
TCP/17002 |
0.0.0.0/0 |
For routing observability IPFIX |
| Rule 8 | Inbound | UDP/162 |
0.0.0.0/0 |
For SNMP trap |
|
Rule 8 |
Outbound |
any |
any |
Allow all outbound traffic from the VMs |
To create a load balancer security group to allow the traffic detailed in Table 4, perform the following steps:
Navigate to the EC2 > Security Groups page. Click Create new security group at the top right corner of the page.
Enter basic details such as a name in Security group name and description for the security group in Description. For example, enter the security group name as Loadbalancer-sg.
Select the VPC on which you want to deploy the cluster node VMs.
Expand Inbound rules.
Enter information for the inbound rules by referring to the following table. After entering the values for a rule, click Add rule to enter the values for the next rule.
Table 5: Field Description Rule 1 Type
Select Custom TCP.
Port range
Enter 443.
Source
Select Anywhere-IPv4.
Description (Optional)
For access to the GUI
Rule 2 Type
Select Custom TCP.
Port range
Enter 2200.
Source
Select Anywhere-IPv4.
Description (Optional)
For NETCONF access
Rule 3 Type
Select Custom TCP.
Port
Enter 4189.
Source
Select Anywhere-IPv4.
Description (Optional)
For PCEP
Rule 4 Type
Select Custom UDP.
Port
Enter 4739.
Source
Select Anywhere-IPv4.
Description (Optional)
For routing observability IPFIX
Rule 5 Type
Select Custom TCP.
Port
Enter 5432.
Source
Select Anywhere-IPv4.
Description (Optional)
For routing observability IPFIX health-check
Rule 6 Type
Select Custom TCP.
Port range
Enter 6800.
Source
Select Anywhere-IPv4.
Description (Optional)
For active assurance TAGW
Rule 7
Type
Select Custom TCP.
Port range
Enter 17002.
Source
Select Anywhere-IPv4.
Description (Optional)
For routing observability CRPD
Rule 8 Type
Select Custom UDP.
Port
Enter 162.
Source
Select Anywhere-IPv4.
Description (Optional)
For SNMP trap.
Expand Outbound rules.
Enter information for the outbound rule by referring to the following table.
Table 6: Field Description Rule 9 Type
Select All traffic.
Source
Select Anywhere-IPv4.
Alternatively, you can also enter the VPC subnet IP range in CIDR notation.
Description (Optional)
Allow all outbound traffic from the VMs
Click Create security group to create the group. The group Loadbalancer-sg is listed under EC2 > Security Groups.
Create and launch the cluster nodes. Go to Launch the EC2 VMs.
Launch the EC2 VMs
-
Select the VM flavor—The VM flavor must be at least c5.4xlarge and meet the specified minimum requirements for vCPU and memory described in Hardware Requirements.
-
Configure the network settings:
-
If the VMs do not have public IP addresses assigned, the VMs must run on a subnet with NAT gateway enabled.
-
If the VMs have elastic public IP addresses assigned, the VMs should run on a subnet with internet gateway (IGW) enabled.
-
-
Configure the following storage specifications:
-
The bare minimum requirement is 400-GB for the primary disk and 100-GB for the Ceph disk.
-
Volume type must be General purpose SSD (gp3).
-
IOPS must be minimum 5000.
-
Throughput must be minimum 1000 MiB/s.
-
To launch the EC2 VMs.
You have completed the node preparation steps and are ready to configure the loadbalancer and deploy the cluster. Go to Create the Target Groups and Load Balancers.
Create the Target Groups and Load Balancers
After the VMs are created, configure the target groups and the corresponding load balancers.
Create a Target Group
Targets groups define the target endpoints for the load balancer. Target groups include all cluster VMs and all the defined ports. Each application requires its own target group.
The following table details the target group for each application.| Target Group Name | Protocol | Port | Health Checks | Port for Selected Instances |
|---|---|---|---|---|
|
routing-dir-ui |
TCP |
30011 |
TCP |
30011 |
|
routing-dir-ui-https |
TCP |
30012 |
TCP |
30012 |
|
routing-dir-netconf |
TCP |
30013 |
TCP |
30013 |
|
routing-dir-paa-https |
TCP |
30016 |
TCP |
30016 |
|
routing-dir-pce |
TCP |
30018 |
TCP |
30018 |
|
routing-dir-rb-crpd |
TCP |
30019 |
TCP |
30019 |
|
routing-dir-rb-ipfix |
UDP |
30020 |
TCP (port 30023) |
30020 |
| routing-dir-trap |
UDP |
30021 |
TCP (port 30012) |
30021 |
To create a target group for applications detailed in Target groups for the load balancer, perform the following steps:
Navigate to the EC2 > Target Groups page. Click Create new target group at the top right corner of the page.
Select Instances under Choose a target type.
Enter routing-dir-ui as the Target group name.
Select TCP as the Protocol : Port. Enter 30011 as the port number.
Select the VPC on which the cluster is deployed.
Under Health Checks, select TCP as the Health check protocol.
Click Next. The Register Targets page appears.
All the available EC2 instances in your VPC are listed. Select all and only your VMs.
Click Include as pending below. The VMs are registered as the targets and listed under Review targets.
Click Create target group to create the group. The summary of the newly created target group is displayed.
Repeat step 1 through step 10 for all the other target groups listed in Target groups for the load balancer. Enter the appropriate names (3) and port numbers (4) for each target group.
In step 6, for the routing-dir-rb-ipfix target group, under Health Checks select TCP. Under Health check port, click Override and enter 30023.
Similarly, for the routing-dir-trap target group, under Health Checks select TCP. Under Health check port, click Override and enter 30012.
Create the Load Balancer
Click EC2 > Load Balancers. The Load balancers page appears.
To create a load balancer to be used for the GUI and NETCONF access, click Create Load balancer at the top right corner of the page. The Compare and select load balancer type page appears.
Click Create under Network Load Balancer.
Enter a name for the load balancer.
Select the VPC on which the VMs are created.
Under Availability Zones and subnets, select the subnet on which the VMs are created. You can also select multiple subnets if your VMs are located in different subnets.
Under Security groups, select the security group that you want to apply on this load balancer. In our example, we select Loadbalancer-sg to apply on the load balancer.
Also, clear the pre-selected default security group.
Under Listeners and routing, enter the following information.
Select TCP as the Protocol. Enter 80 as the Port number. Select routing-dir-ui as the target group to forward traffic to. For target group names, refer to Target groups for the load balancer.
Click Add listener to add another listener.
Select TCP as the Protocol. Enter 443 as the Port number. Select routing-dir-ui-https as the target group to forward traffic to.
Click Add listener to add another listener.
Select TCP as the Protocol. Enter 2200 as the Port number. Select routing-dir-netconf as the target group to forward traffic to.
Click Create load balancer to create the load balancer.
To create a load balancer for the active assurance test agent gateway (TAGW) repeat steps 2 through 7.
Under Listeners and routing, enter following information.
Select TCP as the Protocol. Enter 443 as the Port number. Select routing-dir-paa-https as the target group to forward traffic to. For target group names, refer to Target groups for the load balancer.
Click Add listener to add another listener.
Select TCP as the Protocol. Enter 6800 as the Port number. Select routing-dir-paa-https as the target group to forward traffic to.
Click Create load balancer to create the load balancer for the active assurance TAGW.
To create a load balancer for the PCE server repeat steps 2 through 7.
Under Listeners and routing, enter following information.
Select TCP as the Protocol. Enter 4189 as the Port number. Select routing-dir-pce as the target group to forward traffic to. For target group names, refer to Target groups for the load balancer.
Click Create load balancer to create the load balancer for the PCE server.
To create a load balancer for the routing observability repeat steps 2 through 7.
Under Listeners and routing, enter following information.
Select TCP as the Protocol. Enter 17002 as the Port number. Select routing-dir-rb-crpd as the target group to forward traffic to. For target group names, refer to Target groups for the load balancer.
Click Add listener to add another listener.
Select UDP as the Protocol. Enter 4739 as the Port number. Select routing-dir-rb-ipfix as the target group to forward traffic to. For target group names, refer to Target groups for the load balancer.
Click Create load balancer to create the load balancer for the routing observability use case.
The newly created load balancers are listed on the Load balancers (EC2 > Load balancers) page. Note down the network load balancer URLs listed in the DNS name column. You must enter these hostnames when you deploy the cluster.
You can also create an alias or a custom domain name for a generated DNS name. If you create an alias, you must use the alias during deployment of the cluster. For more information on creating custom domain names, see https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/using-domain-names-with-elb.html.
Resolve the DNS name of the PCE server network load balancer using the
nslookup DNS-name-for-PCE-servercommand on any command line terminal to determine the corresponding IP address.Similarly, resolve the DNS names for routing observability CRPD service and IPFIX term.
You must enter these VIP addresses when you deploy the cluster.
What's Next
Configure the cluster nodes and deploy the cluster. Go to Deploy the Cluster.