SlideShare ist ein Scribd-Unternehmen logo
1 von 17
Downloaden Sie, um offline zu lesen
© 2016
VNS3 3.5
Upgrade Instructions
Version 2.x/3.x to 3.5
2016
© 2016
Table of Contents
2
Introduction 3
Upgrade Steps 7
1. Create a Snapshot of the 2.x/3.x Manager 8
2. Launch a 3.5 Controller Instance 9
3. Log into the 3.5 Controller 10
4. Upload the Snapshot to 3.5 Controller 11
5. Set the 2.x/3.x Manager to only receive IPsec 12
Review the 3.5 Controller’s Imported
Configuration
13
6. Swap the Public IP or Reconfigure the
Overlay
14
7. Reboot the 2.x/3.x Manager 15
© 2016
Introduction
3
© 2016
Upgrade Requirements
4
You have an existing VPN3 version 2.x or VNS3 version 3.x Manager launched and
configured.
You have access to a new VNS3:net version 3.x Image provided by Cohesive or via public
catalog.
You have scheduled an operational window with any parties connected to or using the
existing Overlay Network (see downtime considerations on the following page).
© 2016
Upgrade Downtime Considerations
5
Upgrading between versions of VPN3/VNS3 requires launching and configuring a new
Controller server instance. While steps 1-5 in the following document can be done with no
impact to an existing VPN3 topology, cutting over to the new 3.5 Controller will interrupt service
to the Overlay Network.
Downtime can be greatly reduced if the existing Controller and the Overlay Network topology
has been configured using a user controlled and assignable static Public IP like AWS Elastic IPs.
Step 6 of this document shows the assignment of the Public IP to the new 3.5 Controller
allowing the IPsec tunnels and the Overlay Network client servers to automatically reconnect.
If you cannot control the Public IP address of the new 3.5 Controller, you will need to
reconfigure any IPsec devices connecting to the 3.5 Controller and Overlay Network client
servers to point to the 3.5 Controller’s Public IP address.
© 2016
Getting Help with VNS3
6
Cohesive Networks offer support and services for VNS3 version upgrades. Audits,
snapshot reviews, and chaperoned upgrade windows can be scheduled with your account
representative or by emailing us at support@cohesive.net


Please review the VNS3 Support Plans and Contacts before sending support inquiries. If
you need specific help with project planning, POCs, or audits, contact our professional
services team via sales@cohesive.net for details.
© 2016
VNS3 Upgrade Steps
7
© 2016
1. Create a VPN3 Snapshot of the 2.x/3.x Manager
8
This Upgrade example will use a VNS3 3.0 Snapshot
to import the running configuration of a 3.0 Manager
to a 3.5 Controller.
Create the VPN3 Snapshot that will be used to import
the running configuration of the existing Manager to
the 3.5 Controller.
From the existing Manager UI, click the View and
Create left column menu item under the Snapshots
section.
On the resulting Runtime Snapshots page, click Take
New Snapshot Now.
The Controller will create a new Snapshot and
present a download link. Click the download link and
save locally.
© 2016
2. Launch a 3.5 Controller instance
9
Use the 3.5 Controller AMI IDs available in the cloud’s public catalog
or those provided by Cohesive Networks. Launch the 3.5 Controller
in the same Region/Datacenter/Availability Zone as the existing
Manager using the cloud’s console or the command line. Below are
some examples of the launch command in AWS EC2.
Launch your 3.x Controller in US region, in vnscubed-mgr security
group:
ec2run -U https://us-east-1.ec2.amazonaws.com
AMI_ID_US -n 1 -g vnscubed-mgr
OR
Launch VNS3 Controller in EU region:
ec2run -U https://eu-west-1.ec2.amazonaws.com
AMI_ID_EU -n 1 -g vnscubed-mgr


IMPORTANT: 3.5 Controller AMIs do not need to be launched with a
different kernel or ramdisk parameter as with previous VPN3 AMI
versions.
© 2016
3. Log into the 3.5 Controller
10
Log into the new 3.5 Controller instance using the
following log in credentials:
username: vnscubed
password: either AWS instance ID (i-xxxxxxxx) or
vnscubed depending on the deployment
environment
You will be prompted to change both the UI and API
password when logging into a 3.5 VNS3 Controller
for the first time. The passwords you enter in this
step will be used by the 3.5 after the snapshot from
the old Manager is uploaded.
© 2016
4. Upload the Snapshot to the 3.5 Controller
11
Click the Upload Snapshot left column menu item
under the Initialization section.
Browse and specify the VPN3 Snapshot saved
locally in Step 1.
Click Submit and reboot.
Click OK on the popup window informing you the
3.5 Controller will reboot once the Snapshot is
uploaded.
© 2016
5. Set the 2.x/3.x Manager only to receive IPsec
12
Add the following Extra Parameters on the 2.x
Manager to prevent the 2.x Manager from
trying to connect after the Upgrade has been
completed.
auto=add

rekey=no
This allows you to keep the 2.x Manager
running in order to rollback if necessary
without additional downtime.
© 2016
Review the 3.5 Controller’s Imported Configuration
13
No Changes have been made to your existing Controller, cloud-deployment, or negotiated IPsec tunnels in the previous steps 1-5. Validate the Snapshot Upload was
successful (review Peering setup, IPsec configurations, Firewall configurations, Clientpacks, and Topology Name).
Extra Configuration Parameters

The 3.x release introduced a new set of arguments for the Extra Configuration Parameters field on the IPsec Endpoint page (see the 3.5 Configuration Guide |
Administration Guide for more information). 3.x Controller are backward compatible with 2.x Extra Configuration Parameters entries using the compat: prefix.
CloudWAN Tunnels

The 3.x release changed the way CloudWAN features are surfaced to the customer. 3.x release introduced the concept of tunnels where you define the source and
destination subnets allowing complete control over the IPsec connections. Previously configured CloudWAN subnets will be surfaced as new tunnels as part of the
Snapshot Upgrade. Note: the default tunnels for each Endpoint, with source subnet of the entire Overlay Subnet, will also be automatically created.
Firewall Rules
If you are using negation rules, the underlying VNS3 Firewall Rule syntax has changed. Previously the exclamation mark was used after the -d or -s. for an address
space to be excluded. In VNS3 3.5 the exclamation mark is now used before the -d or -s.
Old Syntax - INPUT_CUST -s ! 192.168.1.0/24 -j ACCEPT
New Syntax - INPUT_CUST ! -s 192.168.1.0/24 -j ACCEPT
The Next step will initiate the Operational Window and briefly bring both the IPsec and Overlay connections down. Before preceding make sure all parties
involved are aware of the temporary connectivity outage.
© 2016
6. Swap the Public IP or Reconfigure the Overlay
14
As previously mentioned Steps 1-5 have no impact on your existing
VPN3 deployment.
If your old Manager and the Overlay Network topology is configured
using a user controlled and assignable static Public IP like AWS
Elastic IPs, switching the Public IP from the old Manager to the 3.5
Controller will force the IPsec connection and Overlay Network client
connections to reconnect with the new 3.5 Controller automatically.
If you do not have control over the Public IP address of the old
Manager you will need to reconfigure both the IPsec connection and
Overlay Network client server connections (vpncubed.conf/
vpncubed.ovpn) to point to the 3.5 Controller’s Public IP address.
For this example the use of Elastic IPs is demonstrated.
From the AWS console click the Elastic IPs left column menu item
under the Network & Security section.
Select the Elastic IP currently associated with the 2.x Manager and
click Disassociate then Yes, Disassociate in the popup window.
With the same Elastic IP selected click Associate and select the 3.x
Controller instance then click Yes, Associate in the popup window.
© 2016
7. Reboot the 2.x/3.x Manager
15
Once the Elastic IP has been associated with
the 3.5 Controller active tunnels (both IPsec
and Overlay Network client servers) will still be
connected to the old Manager. To force the
automatic connect to the new 3.5 Controller
reboot the old Manager from the VPN3/VNS3
Manager UI.
Click the Reboot left column menu item under
the Admin section and confirm you want to
reboot the old Manager by clicking OK on the
popup window.
The reboot will bounce the active tunnels and
force them to reconnect. The total time to
reconnect is ~1-2 minutes.
© 2016
8. Review the 3.5 Controller Configuration
16
Once the connections have migrated to the 3.5
Controller validate traffic flow and final
configuration of the 3.5 Controller.
It is recommended you leave the old Manager
running for a 24 hour period in the case you wish
to roll back.
In the event you need to roll back, follow the
steps below.
1.Disassociate the Elastic IP from the 3.5
Controller
2.Associate the Elastic IP with the 2.x/3.x Manager
3.Reboot the 3.5 Controller
© 2016
VNS3 Configuration Document Links
17
VNS3 Product Resources - Documentation | Add-ons
VNS3 Configuration Instructions

Instructions and screenshots for configuring a VNS3 Controller in a single or multiple Controller topology.
Specific steps include, initializing a new Controller, generating clientpack keys, setting up peering, building
IPsec tunnels, and connecting client servers to the Overlay Network. 

VNS3 Administration Document

Covers the administration and operation of a configured VNS3 Controller. Additional detail is provided around
the VNS3 Firewall, all administration menu items, upgrade licenses, other routes and SNMP traps.

VNS3 Troubleshooting

Troubleshooting document that provides explanation issues that are more commonly experienced with VNS3.


Weitere ähnliche Inhalte

Was ist angesagt?

Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud
Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud
Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud Cohesive Networks
 
Configuring GRE Tunnel Through a Cisco ASA Firewall
Configuring GRE Tunnel Through a Cisco ASA FirewallConfiguring GRE Tunnel Through a Cisco ASA Firewall
Configuring GRE Tunnel Through a Cisco ASA FirewallHarris Andrea
 
Cohesive networks Support Docs: VNS3:turret WAF Guide
Cohesive networks Support Docs: VNS3:turret WAF GuideCohesive networks Support Docs: VNS3:turret WAF Guide
Cohesive networks Support Docs: VNS3:turret WAF GuideCohesive Networks
 
PuppetConf 2013 vCloud Hybrid Service and Puppet
PuppetConf 2013 vCloud Hybrid Service and PuppetPuppetConf 2013 vCloud Hybrid Service and Puppet
PuppetConf 2013 vCloud Hybrid Service and PuppetNan Liu
 
Air max5 and_mikrotik_router_board_connection_guide_revised
Air max5 and_mikrotik_router_board_connection_guide_revisedAir max5 and_mikrotik_router_board_connection_guide_revised
Air max5 and_mikrotik_router_board_connection_guide_revisedSlamet Achwandy
 

Was ist angesagt? (6)

Remote VPN
Remote VPNRemote VPN
Remote VPN
 
Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud
Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud
Cohesive Networks Support Docs: VNS3 Configuration for CenturyLink Cloud
 
Configuring GRE Tunnel Through a Cisco ASA Firewall
Configuring GRE Tunnel Through a Cisco ASA FirewallConfiguring GRE Tunnel Through a Cisco ASA Firewall
Configuring GRE Tunnel Through a Cisco ASA Firewall
 
Cohesive networks Support Docs: VNS3:turret WAF Guide
Cohesive networks Support Docs: VNS3:turret WAF GuideCohesive networks Support Docs: VNS3:turret WAF Guide
Cohesive networks Support Docs: VNS3:turret WAF Guide
 
PuppetConf 2013 vCloud Hybrid Service and Puppet
PuppetConf 2013 vCloud Hybrid Service and PuppetPuppetConf 2013 vCloud Hybrid Service and Puppet
PuppetConf 2013 vCloud Hybrid Service and Puppet
 
Air max5 and_mikrotik_router_board_connection_guide_revised
Air max5 and_mikrotik_router_board_connection_guide_revisedAir max5 and_mikrotik_router_board_connection_guide_revised
Air max5 and_mikrotik_router_board_connection_guide_revised
 

Andere mochten auch

Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...Cohesive Networks
 
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...Cohesive Networks
 
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASA
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASACohesive Networks Support Docs: VNS3 Setup for Cisco ASA
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASACohesive Networks
 
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts Cohesive Networks
 
Cohesive Networks Support Docs: VNS3 Configuration for IBM Softlayer
Cohesive Networks Support Docs: VNS3 Configuration for IBM SoftlayerCohesive Networks Support Docs: VNS3 Configuration for IBM Softlayer
Cohesive Networks Support Docs: VNS3 Configuration for IBM SoftlayerCohesive Networks
 
Cohesive Networks Support Docs: VNS3 Setup for Juniper
Cohesive Networks Support Docs: VNS3 Setup for JuniperCohesive Networks Support Docs: VNS3 Setup for Juniper
Cohesive Networks Support Docs: VNS3 Setup for JuniperCohesive Networks
 
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlow
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlowCloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlow
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlowCohesive Networks
 
Cohesive Networks Support Docs: VNS3 Trend Micro Agent
Cohesive Networks Support Docs: VNS3 Trend Micro Agent Cohesive Networks Support Docs: VNS3 Trend Micro Agent
Cohesive Networks Support Docs: VNS3 Trend Micro Agent Cohesive Networks
 
API Days - API Security & the Audit Paradox by Chris Swan
API Days - API Security & the Audit Paradox by Chris SwanAPI Days - API Security & the Audit Paradox by Chris Swan
API Days - API Security & the Audit Paradox by Chris SwanCohesive Networks
 
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...Cohesive Networks
 
Cohesive Networks Support Docs: VNS3 Setup for Sonicwall
Cohesive Networks Support Docs: VNS3 Setup for SonicwallCohesive Networks Support Docs: VNS3 Setup for Sonicwall
Cohesive Networks Support Docs: VNS3 Setup for SonicwallCohesive Networks
 
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlow
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlowCohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlow
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlowCohesive Networks
 
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례Docker + Kubernetes를 이용한 빌드 서버 가상화 사례
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례NAVER LABS
 

Andere mochten auch (13)

Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
 
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
Patrick Kerpan's CSA EMEA Congress presentation "Overlay Networks: Connecting...
 
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASA
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASACohesive Networks Support Docs: VNS3 Setup for Cisco ASA
Cohesive Networks Support Docs: VNS3 Setup for Cisco ASA
 
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
Cohesive Networks Support Docs: VNS3 Configuration for ElasticHosts
 
Cohesive Networks Support Docs: VNS3 Configuration for IBM Softlayer
Cohesive Networks Support Docs: VNS3 Configuration for IBM SoftlayerCohesive Networks Support Docs: VNS3 Configuration for IBM Softlayer
Cohesive Networks Support Docs: VNS3 Configuration for IBM Softlayer
 
Cohesive Networks Support Docs: VNS3 Setup for Juniper
Cohesive Networks Support Docs: VNS3 Setup for JuniperCohesive Networks Support Docs: VNS3 Setup for Juniper
Cohesive Networks Support Docs: VNS3 Setup for Juniper
 
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlow
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlowCloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlow
Cloud Expo New York: OpenFlow Is SDN Yet SDN Is Not Only OpenFlow
 
Cohesive Networks Support Docs: VNS3 Trend Micro Agent
Cohesive Networks Support Docs: VNS3 Trend Micro Agent Cohesive Networks Support Docs: VNS3 Trend Micro Agent
Cohesive Networks Support Docs: VNS3 Trend Micro Agent
 
API Days - API Security & the Audit Paradox by Chris Swan
API Days - API Security & the Audit Paradox by Chris SwanAPI Days - API Security & the Audit Paradox by Chris Swan
API Days - API Security & the Audit Paradox by Chris Swan
 
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
Chris Purrington's talk from CLOUDSEC 2016 "Defense in depth: practical steps...
 
Cohesive Networks Support Docs: VNS3 Setup for Sonicwall
Cohesive Networks Support Docs: VNS3 Setup for SonicwallCohesive Networks Support Docs: VNS3 Setup for Sonicwall
Cohesive Networks Support Docs: VNS3 Setup for Sonicwall
 
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlow
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlowCohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlow
Cohesive SDN Summit Presentation: OpenFlow is SDN, SDN is not OpenFlow
 
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례Docker + Kubernetes를 이용한 빌드 서버 가상화 사례
Docker + Kubernetes를 이용한 빌드 서버 가상화 사례
 

Ähnlich wie Cohesive networks Support Docs: VNS3 3.5 Upgrade Guide

Cohesive Networks Support Docs: VNS3 Administration
Cohesive Networks Support Docs: VNS3 AdministrationCohesive Networks Support Docs: VNS3 Administration
Cohesive Networks Support Docs: VNS3 AdministrationCohesive Networks
 
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC Cohesive Networks
 
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 Classic
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 ClassicCohesive Networks Support Docs: VNS3 Configuration for AWS EC2 Classic
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 ClassicCohesive Networks
 
Cohesive Networks Support Docs: VNS3:turret Base Container Guide
Cohesive Networks Support Docs: VNS3:turret Base Container GuideCohesive Networks Support Docs: VNS3:turret Base Container Guide
Cohesive Networks Support Docs: VNS3:turret Base Container GuideCohesive Networks
 
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide Cohesive Networks
 
Cohesive Networks Support Docs: VNS3 Setup for Fortigate
Cohesive Networks Support Docs: VNS3 Setup for FortigateCohesive Networks Support Docs: VNS3 Setup for Fortigate
Cohesive Networks Support Docs: VNS3 Setup for FortigateCohesive Networks
 
Aruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guideAruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guideDave Norris
 
The endian vpn menu
The endian vpn menuThe endian vpn menu
The endian vpn menujanil_kumar
 
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2Alfonso Martino
 
Amazon AWS Workspace Howto
Amazon AWS Workspace HowtoAmazon AWS Workspace Howto
Amazon AWS Workspace Howtomailbhargav
 
How To Configure VNC Server on CentOS 7
How To Configure VNC Server on CentOS 7How To Configure VNC Server on CentOS 7
How To Configure VNC Server on CentOS 7VCP Muthukrishna
 
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...NETWAYS
 
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide Cohesive Networks
 
Liberty Scalability and Elasticity Locally and in the IBM Cloud
Liberty Scalability and Elasticity Locally and in the IBM CloudLiberty Scalability and Elasticity Locally and in the IBM Cloud
Liberty Scalability and Elasticity Locally and in the IBM CloudBrian S. Paskin
 
L2 tp i-psec vpn on windows server 2016 step by step
L2 tp i-psec vpn on windows server 2016 step by stepL2 tp i-psec vpn on windows server 2016 step by step
L2 tp i-psec vpn on windows server 2016 step by stepAhmed Abdelwahed
 
Pivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First LookPivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First LookVMware Tanzu
 
Practical solutions for connections administrators
Practical solutions for connections administratorsPractical solutions for connections administrators
Practical solutions for connections administratorsSharon James
 

Ähnlich wie Cohesive networks Support Docs: VNS3 3.5 Upgrade Guide (20)

Cohesive Networks Support Docs: VNS3 Administration
Cohesive Networks Support Docs: VNS3 AdministrationCohesive Networks Support Docs: VNS3 Administration
Cohesive Networks Support Docs: VNS3 Administration
 
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC
Cohesive Networks Support Docs: VNS3 Configuration for Amazon VPC
 
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 Classic
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 ClassicCohesive Networks Support Docs: VNS3 Configuration for AWS EC2 Classic
Cohesive Networks Support Docs: VNS3 Configuration for AWS EC2 Classic
 
Cohesive Networks Support Docs: VNS3:turret Base Container Guide
Cohesive Networks Support Docs: VNS3:turret Base Container GuideCohesive Networks Support Docs: VNS3:turret Base Container Guide
Cohesive Networks Support Docs: VNS3:turret Base Container Guide
 
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide
Cohesive Networks Support Docs: VNS3 version 3.5+ API Guide
 
KB Article 1-FINAL
KB Article 1-FINALKB Article 1-FINAL
KB Article 1-FINAL
 
Cohesive Networks Support Docs: VNS3 Setup for Fortigate
Cohesive Networks Support Docs: VNS3 Setup for FortigateCohesive Networks Support Docs: VNS3 Setup for Fortigate
Cohesive Networks Support Docs: VNS3 Setup for Fortigate
 
module B.docx
module B.docxmodule B.docx
module B.docx
 
ArubaOS 6.3.x Quick Start Guide
ArubaOS 6.3.x Quick Start GuideArubaOS 6.3.x Quick Start Guide
ArubaOS 6.3.x Quick Start Guide
 
Aruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guideAruba os 6.3.x quick start guide
Aruba os 6.3.x quick start guide
 
The endian vpn menu
The endian vpn menuThe endian vpn menu
The endian vpn menu
 
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2
MuleSoft Meetup Roma - Runtime Fabric Series (From Zero to Hero) - Sessione 2
 
Amazon AWS Workspace Howto
Amazon AWS Workspace HowtoAmazon AWS Workspace Howto
Amazon AWS Workspace Howto
 
How To Configure VNC Server on CentOS 7
How To Configure VNC Server on CentOS 7How To Configure VNC Server on CentOS 7
How To Configure VNC Server on CentOS 7
 
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...
OSMC 2022 | Ignite: Observability with Grafana & Prometheus for Kafka on Kube...
 
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
Cohesive Networks Support Docs: VNS3 Side by Side IPsec Tunnel Guide
 
Liberty Scalability and Elasticity Locally and in the IBM Cloud
Liberty Scalability and Elasticity Locally and in the IBM CloudLiberty Scalability and Elasticity Locally and in the IBM Cloud
Liberty Scalability and Elasticity Locally and in the IBM Cloud
 
L2 tp i-psec vpn on windows server 2016 step by step
L2 tp i-psec vpn on windows server 2016 step by stepL2 tp i-psec vpn on windows server 2016 step by step
L2 tp i-psec vpn on windows server 2016 step by step
 
Pivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First LookPivotal Cloud Foundry 2.5: A First Look
Pivotal Cloud Foundry 2.5: A First Look
 
Practical solutions for connections administrators
Practical solutions for connections administratorsPractical solutions for connections administrators
Practical solutions for connections administrators
 

Mehr von Cohesive Networks

CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...
CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...
CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...Cohesive Networks
 
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...Cohesive Networks
 
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...Cohesive Networks
 
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)Cohesive Networks
 
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...Cohesive Networks
 
Comparison: VNS3 and Openswan
Comparison: VNS3 and OpenswanComparison: VNS3 and Openswan
Comparison: VNS3 and OpenswanCohesive Networks
 
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-Ons
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-OnsCohesive Networks Support Docs: VNS3 3.5 Container System Add-Ons
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-OnsCohesive Networks
 
Cohesive Networks Support Docs: VNS3:turret NIDS Guide
Cohesive Networks Support Docs: VNS3:turret NIDS GuideCohesive Networks Support Docs: VNS3:turret NIDS Guide
Cohesive Networks Support Docs: VNS3:turret NIDS GuideCohesive Networks
 

Mehr von Cohesive Networks (9)

CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...
CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...
CircleCity Con 2017 - Dwight Koop's talk Cybersecurity for real life: Using t...
 
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...
Protecting Vital Data With NIST Framework - Patrick Kerpan's Secure260 presen...
 
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...
Let’s rethink cloud application security in 2016 - Patrick Kerpan's Secure360...
 
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
Lessons Learned in Deploying the ELK Stack (Elasticsearch, Logstash, and Kibana)
 
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...
The Chicago School of Cybersecurity: A Pragmatic Look at the NIST Cybersecuri...
 
Comparison: VNS3 vs Vyatta
Comparison: VNS3 vs VyattaComparison: VNS3 vs Vyatta
Comparison: VNS3 vs Vyatta
 
Comparison: VNS3 and Openswan
Comparison: VNS3 and OpenswanComparison: VNS3 and Openswan
Comparison: VNS3 and Openswan
 
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-Ons
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-OnsCohesive Networks Support Docs: VNS3 3.5 Container System Add-Ons
Cohesive Networks Support Docs: VNS3 3.5 Container System Add-Ons
 
Cohesive Networks Support Docs: VNS3:turret NIDS Guide
Cohesive Networks Support Docs: VNS3:turret NIDS GuideCohesive Networks Support Docs: VNS3:turret NIDS Guide
Cohesive Networks Support Docs: VNS3:turret NIDS Guide
 

Kürzlich hochgeladen

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Zilliz
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 

Kürzlich hochgeladen (20)

Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

Cohesive networks Support Docs: VNS3 3.5 Upgrade Guide

  • 1. © 2016 VNS3 3.5 Upgrade Instructions Version 2.x/3.x to 3.5 2016
  • 2. © 2016 Table of Contents 2 Introduction 3 Upgrade Steps 7 1. Create a Snapshot of the 2.x/3.x Manager 8 2. Launch a 3.5 Controller Instance 9 3. Log into the 3.5 Controller 10 4. Upload the Snapshot to 3.5 Controller 11 5. Set the 2.x/3.x Manager to only receive IPsec 12 Review the 3.5 Controller’s Imported Configuration 13 6. Swap the Public IP or Reconfigure the Overlay 14 7. Reboot the 2.x/3.x Manager 15
  • 4. © 2016 Upgrade Requirements 4 You have an existing VPN3 version 2.x or VNS3 version 3.x Manager launched and configured. You have access to a new VNS3:net version 3.x Image provided by Cohesive or via public catalog. You have scheduled an operational window with any parties connected to or using the existing Overlay Network (see downtime considerations on the following page).
  • 5. © 2016 Upgrade Downtime Considerations 5 Upgrading between versions of VPN3/VNS3 requires launching and configuring a new Controller server instance. While steps 1-5 in the following document can be done with no impact to an existing VPN3 topology, cutting over to the new 3.5 Controller will interrupt service to the Overlay Network. Downtime can be greatly reduced if the existing Controller and the Overlay Network topology has been configured using a user controlled and assignable static Public IP like AWS Elastic IPs. Step 6 of this document shows the assignment of the Public IP to the new 3.5 Controller allowing the IPsec tunnels and the Overlay Network client servers to automatically reconnect. If you cannot control the Public IP address of the new 3.5 Controller, you will need to reconfigure any IPsec devices connecting to the 3.5 Controller and Overlay Network client servers to point to the 3.5 Controller’s Public IP address.
  • 6. © 2016 Getting Help with VNS3 6 Cohesive Networks offer support and services for VNS3 version upgrades. Audits, snapshot reviews, and chaperoned upgrade windows can be scheduled with your account representative or by emailing us at support@cohesive.net 
 Please review the VNS3 Support Plans and Contacts before sending support inquiries. If you need specific help with project planning, POCs, or audits, contact our professional services team via sales@cohesive.net for details.
  • 8. © 2016 1. Create a VPN3 Snapshot of the 2.x/3.x Manager 8 This Upgrade example will use a VNS3 3.0 Snapshot to import the running configuration of a 3.0 Manager to a 3.5 Controller. Create the VPN3 Snapshot that will be used to import the running configuration of the existing Manager to the 3.5 Controller. From the existing Manager UI, click the View and Create left column menu item under the Snapshots section. On the resulting Runtime Snapshots page, click Take New Snapshot Now. The Controller will create a new Snapshot and present a download link. Click the download link and save locally.
  • 9. © 2016 2. Launch a 3.5 Controller instance 9 Use the 3.5 Controller AMI IDs available in the cloud’s public catalog or those provided by Cohesive Networks. Launch the 3.5 Controller in the same Region/Datacenter/Availability Zone as the existing Manager using the cloud’s console or the command line. Below are some examples of the launch command in AWS EC2. Launch your 3.x Controller in US region, in vnscubed-mgr security group: ec2run -U https://us-east-1.ec2.amazonaws.com AMI_ID_US -n 1 -g vnscubed-mgr OR Launch VNS3 Controller in EU region: ec2run -U https://eu-west-1.ec2.amazonaws.com AMI_ID_EU -n 1 -g vnscubed-mgr 
 IMPORTANT: 3.5 Controller AMIs do not need to be launched with a different kernel or ramdisk parameter as with previous VPN3 AMI versions.
  • 10. © 2016 3. Log into the 3.5 Controller 10 Log into the new 3.5 Controller instance using the following log in credentials: username: vnscubed password: either AWS instance ID (i-xxxxxxxx) or vnscubed depending on the deployment environment You will be prompted to change both the UI and API password when logging into a 3.5 VNS3 Controller for the first time. The passwords you enter in this step will be used by the 3.5 after the snapshot from the old Manager is uploaded.
  • 11. © 2016 4. Upload the Snapshot to the 3.5 Controller 11 Click the Upload Snapshot left column menu item under the Initialization section. Browse and specify the VPN3 Snapshot saved locally in Step 1. Click Submit and reboot. Click OK on the popup window informing you the 3.5 Controller will reboot once the Snapshot is uploaded.
  • 12. © 2016 5. Set the 2.x/3.x Manager only to receive IPsec 12 Add the following Extra Parameters on the 2.x Manager to prevent the 2.x Manager from trying to connect after the Upgrade has been completed. auto=add
 rekey=no This allows you to keep the 2.x Manager running in order to rollback if necessary without additional downtime.
  • 13. © 2016 Review the 3.5 Controller’s Imported Configuration 13 No Changes have been made to your existing Controller, cloud-deployment, or negotiated IPsec tunnels in the previous steps 1-5. Validate the Snapshot Upload was successful (review Peering setup, IPsec configurations, Firewall configurations, Clientpacks, and Topology Name). Extra Configuration Parameters
 The 3.x release introduced a new set of arguments for the Extra Configuration Parameters field on the IPsec Endpoint page (see the 3.5 Configuration Guide | Administration Guide for more information). 3.x Controller are backward compatible with 2.x Extra Configuration Parameters entries using the compat: prefix. CloudWAN Tunnels
 The 3.x release changed the way CloudWAN features are surfaced to the customer. 3.x release introduced the concept of tunnels where you define the source and destination subnets allowing complete control over the IPsec connections. Previously configured CloudWAN subnets will be surfaced as new tunnels as part of the Snapshot Upgrade. Note: the default tunnels for each Endpoint, with source subnet of the entire Overlay Subnet, will also be automatically created. Firewall Rules If you are using negation rules, the underlying VNS3 Firewall Rule syntax has changed. Previously the exclamation mark was used after the -d or -s. for an address space to be excluded. In VNS3 3.5 the exclamation mark is now used before the -d or -s. Old Syntax - INPUT_CUST -s ! 192.168.1.0/24 -j ACCEPT New Syntax - INPUT_CUST ! -s 192.168.1.0/24 -j ACCEPT The Next step will initiate the Operational Window and briefly bring both the IPsec and Overlay connections down. Before preceding make sure all parties involved are aware of the temporary connectivity outage.
  • 14. © 2016 6. Swap the Public IP or Reconfigure the Overlay 14 As previously mentioned Steps 1-5 have no impact on your existing VPN3 deployment. If your old Manager and the Overlay Network topology is configured using a user controlled and assignable static Public IP like AWS Elastic IPs, switching the Public IP from the old Manager to the 3.5 Controller will force the IPsec connection and Overlay Network client connections to reconnect with the new 3.5 Controller automatically. If you do not have control over the Public IP address of the old Manager you will need to reconfigure both the IPsec connection and Overlay Network client server connections (vpncubed.conf/ vpncubed.ovpn) to point to the 3.5 Controller’s Public IP address. For this example the use of Elastic IPs is demonstrated. From the AWS console click the Elastic IPs left column menu item under the Network & Security section. Select the Elastic IP currently associated with the 2.x Manager and click Disassociate then Yes, Disassociate in the popup window. With the same Elastic IP selected click Associate and select the 3.x Controller instance then click Yes, Associate in the popup window.
  • 15. © 2016 7. Reboot the 2.x/3.x Manager 15 Once the Elastic IP has been associated with the 3.5 Controller active tunnels (both IPsec and Overlay Network client servers) will still be connected to the old Manager. To force the automatic connect to the new 3.5 Controller reboot the old Manager from the VPN3/VNS3 Manager UI. Click the Reboot left column menu item under the Admin section and confirm you want to reboot the old Manager by clicking OK on the popup window. The reboot will bounce the active tunnels and force them to reconnect. The total time to reconnect is ~1-2 minutes.
  • 16. © 2016 8. Review the 3.5 Controller Configuration 16 Once the connections have migrated to the 3.5 Controller validate traffic flow and final configuration of the 3.5 Controller. It is recommended you leave the old Manager running for a 24 hour period in the case you wish to roll back. In the event you need to roll back, follow the steps below. 1.Disassociate the Elastic IP from the 3.5 Controller 2.Associate the Elastic IP with the 2.x/3.x Manager 3.Reboot the 3.5 Controller
  • 17. © 2016 VNS3 Configuration Document Links 17 VNS3 Product Resources - Documentation | Add-ons VNS3 Configuration Instructions
 Instructions and screenshots for configuring a VNS3 Controller in a single or multiple Controller topology. Specific steps include, initializing a new Controller, generating clientpack keys, setting up peering, building IPsec tunnels, and connecting client servers to the Overlay Network. 
 VNS3 Administration Document
 Covers the administration and operation of a configured VNS3 Controller. Additional detail is provided around the VNS3 Firewall, all administration menu items, upgrade licenses, other routes and SNMP traps.
 VNS3 Troubleshooting
 Troubleshooting document that provides explanation issues that are more commonly experienced with VNS3.