diff --git a/docs/en-US/vnmc-cisco.xml b/docs/en-US/vnmc-cisco.xml index 62a472da66d..adcaaeac8d0 100644 --- a/docs/en-US/vnmc-cisco.xml +++ b/docs/en-US/vnmc-cisco.xml @@ -33,52 +33,41 @@ policy sets for both ingress and egress traffic. - Use Cisco ASA 1000v firewalls to create and apply NAT policy sets. + Use Cisco ASA 1000v firewalls to create and apply Source NAT, Port Forwarding, and + Static NAT policy sets. &PRODUCT; supports Cisco VNMC on Cisco Nexus 1000v dvSwich-enabled VMware hypervisors. -
- Use Cases - - - A Cloud administrator adds VNMC as a network element by using the admin API - addCiscoVnmcResource after specifying the credentials - - - A Cloud administrator adds ASA 1000v appliances by using the admin API - addCiscoAsa1000vResource. . - - - A Cloud administrator creates an Isolated guest network offering by using ASA 1000v as - the service provider for Firewall, Source NAT, Port Forwarding, and Static NAT. - - -
Guidelines + Cisco ASA 1000v firewall is supported only in Isolated Guest Networks. - When a guest network is created with Cisco VNMC firewall provider, an additional public - IP is acquired along with the Source NAT IP. The Source NAT IP is used for the rules, - whereas the additional IP is used to for the ASA outside interface. Ensure that this - additional public IP is not released. You can identify this IP as soon as the network is - in implemented state and before acquiring any further public IPs. The additional IP is the - one that is not marked as Source NAT. You can find the IP used for the ASA outside + Cisco ASA 1000v firewall is not supported on VPC. + + Cisco ASA 1000v firewall is not supported for load balancing. + + When a guest network is created with Cisco VNMC firewall provider, an additional + public IP is acquired along with the Source NAT IP. The Source NAT IP is used for the + rules, whereas the additional IP is used to for the ASA outside interface. Ensure that + this additional public IP is not released. You can identify this IP as soon as the network + is in implemented state and before acquiring any further public IPs. The additional IP is + the one that is not marked as Source NAT. You can find the IP used for the ASA outside interface by looking at the Cisco VNMC used in your guest network. - + Use the public IP address range from a single subnet. You cannot add IP addresses from + different subnets. - + Only one ASA instance per VLAN is allowed because multiple VLANS cannot be trunked to ASA ports. Therefore, you can use only one ASA instance in a guest network. - - - - + Supported only in Inline mode deployment with load balancer. + +