NAT with MiCloud Management Gateway (MMG)
Mitel provides a VMware NAT application called MiCloud Management Gateway (MMG) to facilitate access by management computers such as MMP and Platform Manager (management side network) to VMware VM instances that are located on one or more isolated VLAN networks (customer side network). For more information, see the MMG documentation.
If a Platform Blueprint indicates that the MMG is to be used, then Platform Manager can perform the following:
-
Configure the MMG customer network with a unique VLAN-ID (provided by you at the time of platform instance creation).
-
Assign management side IP addresses from a pool.
-
Optionally create mappings from customer side IP addresses to computers on the management side of the NAT. These are called 'services' on the MMG. You can use these to provide access to management side servers for services like SNMP Trap and scheduled MSL backups.
Configure MMG server
The MMG application is provided as a VMware .ova file. Install .ova file in VMware with two network interfaces. The first network interface is connected to your Management Network. The second interface is connected to a VMware VLAN trunk group. This trunk group is a group of VLAN interfaces, each with a unique VLAN-ID, which represent the VLANs that are accessible to your management network.
Caution
The MMG server's MSL settings are configured to grant access to all the computers in the management network. By default, MSL grants management access only to computers in its local subnet. You need to configure both MSL web forms: MSL > server-manager > Security > Remote-access and server-manager > Configuration > Networks. In each form, add sufficient networks to include every management side computer that need to access one of these NAT addresses.
Register MMG Server
To register MMG server(s) with Platform Manager, perform the following steps:
-
Browse to PM > Configuration >MMG.
-
Click Add a MMG.
-
Enter MMG address.
-
Enter MMG subnet mask.
MMG subnet is used to validate management side IP addresses. -
Enter MSL admin account credentials.
Create a pool of management side IP addresses:
At platform create time, an address is selected to build a NAT to a VM resource on the customer/VLAN side of the MMG.
Add or delete address
-
Browse to PM > Configuration > MMG.
-
Click Add Management Addresses.
-
Click Delete.
Management IP addresses must be in the same subnet as the MMG server.