Internal Networks
Overview
An Internal Network is a virtual network originated within your tenant. Any number of internal networks can be created, each being created secure by default. Network rules can be used to open up access between Internal Networks and through External Networks as needed.
Concepts
With each new tenant, a virtual network is automatically created to aggregate and encapsulate all of that tenant's traffic. From the tenant's perspective, this is their physical network. A tenant is then able to create a virtually unlimited number of internal networks within their own environment. A tenant is typically assigned one or more external IP addresses and traffic is routed through an external network on the host cluster.
Traffic Flow
See the Traffic Flow diagram to better understand how traffic moves within the platform.
Layer 2 & Layer 3 Support
Built-in Software Defined Networking (SDN) provides the ability to create/destroy Internal Networks on-the-fly without hardware changes. Both Layer 2 and Layer 3 Internal Networks are supported.
- Layer 2 Networks
- The network is managed up to layer 2 by the platform
- Cross-node routing is handled within the DMZ network
- IP-level administration is handled in third-party tools
(e.g., virtual firewall/router appliance)
- Layer 3 Networks
- Full network management
- IP administration (DNS, DHCP, routing, firewall, etc.) available within the platform
Network Rules
Rules govern incoming and outgoing traffic to the network, replacing the traditional role of firewalls, routers and switches. Rules can be defined on all networks, allowing more granular security.
- Firewall - accept, drop, or reject packets based on defined criteria
- Routing - to direct traffic between internal networks and out to external networks with defined static routes
- NAT/PAT - map external-internal/internal-internal IP addresses/ports
More information about working with network rules is available at Network Rules.
Internal Networks
Create Internal Network
Internal Networks are virtual networks originated within the platform. An Internal Network can be created as either Layer 2 or Layer 3, (Layer 3 is recommended).
- From the Top Menu, click Networks -> + New Internal
- Enter a Name for the network
- (Optional), enter a Description
- (Optional), enter a HA Group
ℹ️ HA Groups define two or more networks to provide high availability. When multiple networks are assigned to the same HA Group, the system will attempt to run the networks across different physical nodes to increase redundancy.
- (Optional), enter a Layer 2 ID
ℹ️ Most customers typically match Layer 2 ID and Layer 3 VLAN numbers.
- (Optional), Select a Port Mirroring option
- North/South - only mirror traffic that passes through the router
- East/West - mirror all traffic, including traffic between VMs in the network and traffic that passes through the router
ℹ️ See Port Mirroring for more information.
- Select IP Address Type
- Static (recommended) - Creates a Layer 3 network
- None - Creates a Layer 2 network
- Toggle Show Advanced Options
- Enter an IP Address for the network (e.g., 10.1.1.1)
- Enter a Network Address (e.g., 10.1.1.0/24)
- (Optional), enter a Hostname for the layer 3 routed interface
- (Optional), enter a Domain suffix (e.g., contoso.com)
- Select DNS type
- Bind - run a full-features DNS server (authoritative, etc.)
- Disabled - do not run a DNS server, but offer servers in the DNS server list to DHCP clients
- Other Network - forward DNS requests to another network and auto-create A records for DHCP clients
- Simple (recommended) - run a forwarding DNS server; if no forwarding servers are listed, the default gateway network DNS is used instead
- (Optional), add DNS Servers
- (Important), select a Default Gateway (typically External)
To give an Internal Network access outside of the platform (e.g., the internet), select the proper External Network as the default gateway. An appropriate routing rule will be created automatically.
If no default gateway is selected when creating the network, routing rules will need to be created manually to route traffic through an external network.
- The DHCP option is checked by default. If you do not wish to run DHCP on this network, or you have your own DHCP server, uncheck DHCP
- Configure any additional options, if desired
- Monitor Gateway - Continually ping the gateway and report uptime to the UI
- On Power Loss - Determines the action taken when power is restored
- Track Statistics for All Rules - Tracks total packets/bytes, per rule, for all rules assigned to this network. (Tracking does not apply to route rules)
- Track DMZ Statistics - Tracks total packets/bytes from this network through the DMZ network
- Trace/Debug Rules - Traces all traffic through the firewall for diagnostics
- Mirror Logs - Mirror syslog messages from this network to the main tenant UI
- Enable Rate Limiting - Throttles the bandwidth through the network's router
- Click Submit
After creating the network, you must power it on for it to become active.
- From the left menu, click Power On
Modify Internal Network
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click Edit
- Modify desired fields
- Click Submit
Delete Internal Network
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click Delete
Configure Inter-VLAN Routing
Both source and destination networks must already be created.
See Network Rules for additional information on network rules.
Create Outgoing Rule
- From the Top Menu, click Networks -> List
- Select the source VLAN
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., route_out_v10_to_v20)
- Action, select Route
- Select Protocol (typically ANY)
- Direction, select Outgoing
- Configure Source
- Type, select My Network Address
- Configure Destination
- Type, select Other Network Address
- Network, select the name of the desired network
- Configure Target
- Type, select Other Network DMZ IP
- Target Network, select the name of the desired network
- Click Submit
Create Incoming Rule
- From the Top Menu, click Networks -> List
- Select the source VLAN
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter Name a name for the rule (e.g., allow_in_v20_to_v10)
- Action, select Accept
- Select Protocol (typically ANY)
- Direction, select Incoming
- Configure Source
- Type, select Other Network Address
- Network, select the name of the destination network
- Configure Destination
- Type, select My Network Address
- Click Submit
Repeat For Second Network
Repeat the steps above for the second network.
Once completed you should have an Outgoing and Incoming rule on each network (source and destination).
Click Apply Rules to apply the changes.
IP Addressing
External IP Addresses
To request external IP addresses for your tenant, please contact KorGrid Support. Once external IP's have been assigned to your tenant, follow the steps in this section to make them available to your virtual machines.
Assign External IP
There are two ways KorGrid can assign public IPs:
- Single IP Assignment (/32)
- A network block that contains a single external IP address
- Use the Network Block Method
- Multiple IP Assignment (/29, /28, etc.)
- A network block that contains multiple external IP addresses
- Use the VIP Method
Determine IP Address
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu, click Network Blocks
- Determine the public IP address you wish to use from the network block
Create VIP
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu, click IP Addresses
- From the left menu, click New
- Type, select Virtual IP
- Enter the public IP address from the network block (e.g., 24.221.112.159)
- Owner Type, select Network
- Owner, select the desired internal network
- Click Submit
Once the external IP address(es) have been assigned to an internal network, you must create a translation rule to allow traffic to reach the destination VM.
Create NAT Translation
Assign to Network
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu:
- VIP Method
- Click IP Addresses
- Network Block Method
- Click Network Blocks
- Select the desired external IP Address or Network Block
- From the left menu, click Edit
- Owner Type, select Network
- Owner, select the desired internal network (e.g., vlan10, etc.)
- Click Submit
Create NAT Translation Rule
When assigning a network block or IP address to a network, routing rules will be automatically created. The only additional step needed is to create the 1:1 NAT translation.
- From the Top Menu, click Networks -> List
- Select the internal network your VM is assigned to (e.g., vlan10, etc.)
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule
ℹ️ Try to be as descriptive as possible. This name will appear in logs.
(e.g., NAT-64.96.23.16 > 10.3.16.95)
- (Optional), enter a Description
- Action, select Translate
- Protocol, select ANY
- Direction, select Incoming
- Configure Source
- Type, select Any / None
- Configure Destination
- VIP Method
- Type, select My IP Addresses
- IP Address, select the desired external IP address
- Network Block Method
- Type, select Other Network Block
- Network, select External
- Network Block, select the desired network block
- Configure Target
- Type, select IP / Custom
- Target IP, select the internal IP address of your target VM
- Click Submit
Apply Rules
⚠️ Click Apply Rules to apply the changes.
Advanced Configuration
It may be necessary to assign IP addresses from a single network block across multiple Internal Networks. When this is required, network rules must be created manually for each IP address in the block. This approach provides precise control over which IP addresses are assigned to each Internal Network.
Create External Network Rules
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu, click Rules
- Routing Rule
- From the left menu, click New
- Enter a Name for the rule
ℹ️ Try to be as descriptive as possible.
(e.g., Route-64.96.23.16)
- (Optional), enter a Description
- Action, select Route
- Protocol, select ANY
- Direction, select Incoming
- Configure Source
- Type, select Any / None
- Configure Destination
- Type, select Custom
- Custom Filter, select the desired public IP address
(e.g., 64.96.23.16)
- Configure Target
- Type, select Other Network DMZ IP
- Target Network, select your desired Internal Network
- Click Submit
- Firewall Rule
- From the left menu, click New
- Enter a Name for the rule
ℹ️ Try to be as descriptive as possible.
(e.g., Accept-64.96.23.16)
- (Optional), enter a Description
- Action, select Accept
- Protocol, select ANY
- Direction, select Incoming
- Configure Source
- Type, select Any / None
- Configure Destination
- Type, select Custom
- Custom Filter, select the desired public IP address
(e.g., 64.96.23.16)
- Click Submit
Create Internal Network Rules
- From the Top Menu, click Networks -> List
- Select the desired Internal Network
- From the left menu, click View
- From the left menu, click Rules
- Routing Rule
- From the left menu, click New
- Enter a Name for the rule
ℹ️ Try to be as descriptive as possible.
(e.g., Route-64.96.23.16)
- (Optional), enter a Description
- Action, select Route
- Protocol, select ANY
- Direction, select Outgoing
- Configure Source
- Type, select Custom
- Custom Filter, select the desired public IP address
(e.g., 64.96.23.16)
- Configure Destination
- Type, select Default
- Configure Target
- Type, select Other Network DMZ IP
- Target Network, select External
- Click Submit
- NAT Rule
- From the left menu, click New
- Enter a Name for the rule
ℹ️ Try to be as descriptive as possible.
(e.g., NAT-64.96.23.16)
- (Optional), enter a Description
- Action, select Translate
- Protocol, select ANY
- Direction, select Incoming
- Configure Source
- Type, select Any / None
- Configure Destination
- Type, select Custom
- Custom Filter, select the desired public IP address
(e.g., 64.96.23.16)
- Configure Target
- Type, select IP / Custom
- Target IP, select the internal IP address of your target VM
- Click Submit
Apply Rules
⚠️ Click Apply Rules to apply the changes.