Azure Network Manager

Configuration > Cloud Services > Azure Network Manager

Microsoft Azure optimizes routing, automates large scale connectivity from various branches to Azure workloads, and provides unified network and policy management within Orchestrator.

The Azure Network Manager feature simplifies connectivity between EC-Vs in Azure and Azure Networking services. It enables seamless integration with services such as the Standard Internal Load Balancer, Azure Route Server, and Azure Virtual WAN Hub. This feature allows you to streamline the horizontal scaling of EC-Vs in Azure, thereby enhancing resilience and redundancy for Azure-based mission-critical workloads.

IMPORTANT: For more detailed information and configuration options, including integration with services such as the Standard Internal Load Balancer and Azure Route Server, see the HPE Aruba Networking EdgeConnect SD-WAN Virtual (EC-V) in Microsoft Azure Deployment Guide.

Before you begin Microsoft Azure Virtual WAN configuration in Orchestrator, you need to use the Azure Virtual WAN portal to authenticate and authorize Orchestrator in Azure. You need to create the service principal, which focuses on single-tenant application to run within only one organization. To get started, see Register a Microsoft Entra app and create a service principal.

Microsoft Azure Prerequisites

  1. Create an application in Azure and note the following Subscription details from the Azure Active Directory:

    • Subscription ID

    • Directory (tenant) ID

    • Application (client) ID

    • Client secret value

  2. Create a storage account in Azure and get the following:

    • Storage Account Name

    • Storage Access Key

  3. Create a resource group.

  4. Create Azure Virtual WANs with hubs from your resource groups.

Orchestrator Prerequisites

Complete the following tasks in Orchestrator:

  1. Configure a VTI IP Pool.

    • Enter a valid IPv4 Subnet.

      NOTE: This is a unique address across the network. VTI interfaces created for Azure integration will be selected from this pool.

      NOTE: Azure VTI interface zone is set to WAN interface zone. Any change in deployment for the WAN interface zone is applied to Azure VTI as well.

      WARNING: Any change in the VTI pool after it is configured is networking affecting. This operation should be performed during a maintenance window as it can take several hours for some Cloud services to complete.

  2. Configure BGP ASN Global Pool.

    • Enter the start and end ranges for ASNs.

    • Add any reserved ASNs to exclude from being applied to appliances.

      NOTE: If not previously enabled, Orchestrator enables BGP.

Orchestrator Configuration

When you are finished with the Azure and Orchestrator prerequisites, navigate to Configuration > Cloud Services > Azure Network Manager.

Cloud Gateways

There are five buttons at the top of the table that are used to complete the Azure and Orchestrator integration for Cloud Gateways: Subscription, LAN interface labels, Azure resources, Appliance association, and Pause Orchestration.

Subscription

  1. Click Subscription.

  2. In the Subscription For Azure Cloud Gateways LAN-side Automation dialog box, select the Azure subscription you want to use.

    Under Connectivity status, Orchestrator displays the status for the load balancer, route server, and VWAN hub you connected through your Azure account.

    NOTE: If any modifications you make (such as creating or deleting subnets) in Azure are not reflected on the Orchestrator after you add the Azure subscription to Orchestrator, click the refresh icon to retrieve the latest Azure configuration on demand.

  3. Click Save.

LAN interface labels

  1. Click LAN interface labels.

  2. In the Establish Connectivity Using These Network Interfaces dialog box, drag and drop the LAN label into the Primary column.

  3. Click Save.

Azure resources

  1. Click Azure resources.

  2. In the Configure SD-WAN VNet Resources For Cloud-Deployed EdgeConnect Appliances dialog box, click Add.

  3. In the Configure Azure Resources dialog box, enter the following information:

    Field Description
    Rule name Enter a descriptive name to help identify the EC-V gateways and their VNet.
    Appliances Select the EC-V gateways that should be associated with the ILB. You can either enter the appliance names or click Use Tree Selection to browse and select them.
    Resource group From the drop-down menu, select the Azure resource group where the EC-V gateways are deployed.
    Region Select the Azure region that corresponds to the deployment location of the EC-V gateways.
    Virtual network Choose the VNet where the EC-V gateways reside. This ensures that the appliances are correctly associated with the ILB within the specified VNet.
  4. Click Done.

Appliance association

This step prompts you to select the EC-Vs and the services (vWAN hub, ARS, or ILB) that need to establish connectivity.

  1. In the appliance tree in Orchestrator, select each EC-V that you want to establish connectivity with.

  2. On the Azure Network Manager tab, click Appliance Association.

  3. Depending on what you are trying to connect, click Virtual WAN Hub, Azure Route Server, or Azure Standard Internal Load Balancer. You will see all vWAN hubs, ARSs, and ILBs the Orchestrator has access to. If you do not see the service that you want to associate your EC-Vs with, check the permissions assigned to the Orchestrator’s custom role on Azure Portal.

  4. From the left-side panel, select Add for each EC-V you want to associate.

  5. Click Save.

Pause Orchestration

Click this button to pause LAN-side orchestration. You will be prompted to confirm your selection.

Deploy Route Servers

You can create a new ARS or associate an existing one with EC-V gateways from Orchestrator. The following steps explain how to create a new ARS from Orchestrator within a transit VNet:

  1. In Orchestrator, navigate to Configuration > Cloud Services > Azure Network Manager.

  2. Under the Route Servers header, click Deploy route server.

  3. On the Azure Route Server Deployment Configuration dialog box, enter the following settings:

    Field Description
    Name Enter a descriptive name for the ARS.
    Azure account Select the Azure subscription for deployment.
    Resource group Select the resource group where the ARS is created.
    Region Select the Azure region for the EC-V gateways.
    Virtual network Select the transit VNet where the EC-Vs are deployed.

    NOTE: For Orchestrator to establish BGP between the EC-V and the ARS, they both must reside within the same VNet.
    Route server subnet If your transit VNet already has a RouteServerSubnet of /26 or larger, it will be auto-selected. This is useful for users deploying the subnet themselves and using Orchestrator only for BGP setup. If not, you will be asked to provide a CIDR block so Orchestrator can create the subnet for ARS deployment.
    Comment (Optional) Add comments for tracking purposes.
  4. Click Deploy.

    NOTE: Route Server creation can take up to 30 minutes. You can monitor progress in the audit logs in Orchestrator or the activity logs in the Azure Portal.

  5. Confirm that the ARS resource appears in the Azure resource group, and check its status and assigned IP addresses.

  6. Verify that the ARS is listed by clicking Appliance association, and then clicking Azure Route Server.

Deploy Load Balancers

You can deploy a new ILB or associate an existing one with EC-V gateways from Orchestrator. The following steps show how to create a new ILB from Orchestrator.

  1. From the Azure Network Manager tab, click Deploy load balancer.

  2. On the Azure Load Balancer Deployment Configuration dialog box, enter the following settings:

    Field Description
    Name Enter a descriptive name for the ILB.
    Azure account Select the Azure subscription for deployment.
    Resource group Select the resource group added to the Orchestrator.
    Region Select the Azure region that corresponds to the deployment location of EC-V gateways.
    Virtual network The VNet where EC-Vs are deployed. When deploying through Orchestrator, the ILB and EC-Vs must be in the same VNet. Deploying the ILB in a different VNet from the EC-Vs is not supported.
    New subnet If you want Orchestrator to create a new subnet for the ILB, select the check box. When you select the checkbox, two things happen:

    i. The Orchestrator displays all existing subnets within the VNet you selected. The Load balancer subnet CIDR field appears.

    ii. You must enter a subnet for the load balancer on this field. The subnet you enter must not overlap with any existing subnets in the virtual network and be /27 or bigger (such as /26 or /25). After the Orchestrator creates the ILB, it will use the fourth IP address of this subnet as the frontend IP address of the load balancer. For instance, if you enter 10.0.0.0/27 as the subnet mask, 10.0.0.4 is assigned as the frontend IP address of the load balancer.

    If the New subnet check box is not selected, you must choose an existing subnet in your VNet for the ILB. This option is available for users whose organizations do not allow a third-party application such as the Orchestrator to create new subnets in a VNet. Ensure that the subnet you select is /27 or bigger (such as /26 or /25) in size. The Orchestrator will not accept a /28 or smaller subnet. This option allows you to create a subnet manually but still use the Orchestrator to deploy the ILB within that subnet. When this option is selected, you must also enter a frontend IP address for the ILB, and the IP address must be available within the selected subnet.
    TCP health probe port Enter a port number that you want to use for the ILB health probe. Port 443 is recommended.
    Comment (Optional) Add a comment to identify your ILB deployment.
  3. Click Deploy.

    Orchestrator now deploys the ILB and creates a backend pool, a health probe (on TCP port 443 by default), and a load-balancing rule. The backend pool is empty because you have not associated any EC-V gateways to the ILB yet. After you associate EC-V gateways to the ILB, the Orchestrator adds the LAN interface IPs of the selected EC-Vs to the ILB’s backend address pool.

On-prem Gateways

There are seven buttons at the top of the table that are used to complete the Azure and Orchestrator integration for On-prem Gateways: Subscription, WAN Interface Labels, Tunnel Settings, VTI Subnet Pool, Zone/Role, Virtual WAN Association, and Pause Orchestration.

To begin, click Subscription.

Subscription

  1. In the Subscription for Azure dialog box, enter the following information to reflect your Azure portal account:

    Field Description
    Azure reachability Connection status of your account with Azure.
    Subscription ID ID of your subscription.
    Directory (tenant) ID Name of your Azure AD tenant.
    Application (client) ID Client ID of your Azure portal.
    Client secret value Secret key of your Azure application.
    Storage account Name Name of your storage account.
    Storage account Key Storage account key.
    Storage URL Storage account URL.*
    Configuration polling interval Indicates hows often Orchestrator should check for configuration changes in Azure. The default polling interval is 10 minutes.
  2. Click Save. The Azure field should appear as Connected.

Storage URL

The Storage URL is present on the Storage Accounts tab in your Azure portal. Complete the following steps to obtain your storage account URL.

  1. After your storage account is created in Azure, create a blob container.

  2. Get the blob container URL.

  3. Suffix the URL with a slash and add a file name in the Storage URL field.

    NOTE: Append the URL with a slash for the file name. Do not end the URL with a slash.

WAN Interface Labels

Select the order in which you want your interface labels to be used.

  1. Click the Interface Labels button. The Build Tunnels Using These Interfaces displays.

  2. Drag the Interface labels you want to use into the Preferred Interface Label Order column.

  3. Click Save.

Tunnel Settings

The Tunnel Settings button opens the Tunnel Settings dialog box, which enables you to define the tunnels associated with Azure and Orchestrator. It is recommended that you use the default tunnel settings for General, IKE, and IPSec; however, you can modify any field. The tunnel settings are set using the default VPN configuration parameters received from virtual WAN APIs located in your Azure portal account.

In your Azure Portal Account, navigate to the Azure Configuration table. This table displays the VPN site created for Orchestrator appliances associated to Azure virtual WANs. Additionally, manually associate sites to your hubs in Azure.

  1. Navigate to Azure Virtual WAN.

  2. Select Azure VPN site.

  3. Select New Hub Association.

VTI Subnet Pool

Enter a subnet IP and mask value in the provided fields, and then click Save.

Zone/Role

You can apply configured segments to your VTI interfaces associated for Azure. Click the Zone button and select the zone from the drop-down you want to apply.

Virtual WAN Association

Each appliance is associated with one virtual WAN. Use the Virtual Wan Association button to add or remove specific sites to your virtual WANs.

  1. Click the Virtual Wan Association button.

  2. Select an appliance from the tree in the left menu.

  3. Select the check box to Add or Remove the appliance to your virtual WAN in Azure.

Pause Orchestration

Click this button to pause LAN-side orchestration. You will be prompted to confirm your selection.

Verification

The Tunnel page displays that Azure and Orchestrator have an established connection with Azure by displaying a tunnel status of up - active.

For more information about Azure configuration, visit the following link: https://docs.microsoft.com/en-us/azure/virtual-wan/virtual-wan-site-to-site-portal.