NMAAS FAQ
The following nmaas-related questions are answered on this page:
- How can I contact the nmaas Team members?
- How can I test nmaas?
- How can I start monitoring my infrastructure with nmaas?
- How can I request creation of new nmaas domain for my NREN / Institution / Project?
- How can I deploy nmaas on my own intrastructure?
- Where can I find nmaas User Guide?
- Where can I find nmaas Administrator Guide?
- What applications are currently supported by nmaas?
- What type of VPNs are established by nmaas?
- What VPN solutions are supported by nmaas?
- What are nmaas VPN requirements?
How can I contact the nmaas Team members?
The nmaas Team can be contacted either by:
How can I test nmaas?
In order to test nmaas visit the nmaas sandbox instance at https://nmaas.geant.org.
Once You log in to the Portal, the nmaas administrator will receive an automatic notification and will add You as a member of the pre-configured Test domain. In this domain, You will be able to freely browse, deploy and access applications.
More information about the nmaas sandbox is available at nmaas Playground page.
How can I start monitoring my infrastructure with nmaas?
The GÉANT nmaas production service is available at https://nmaas.eu where users have the possibility to log in with their eduGAIN accounts.
However, in order to be able to deploy network management applications user needs to be assigned to a domain.
In order to request new dedicated domain creation refer to question "How can I request creation of new nmaas domain for my NREN/Institution/Project?"
How can I request creation of new nmaas domain for my NREN/Institution/Project?
In order to request a new nmaas domain on the GÉANT production service fill in and submit the form available at https://nmaas.eu/about?type=NEW_DOMAIN_REQUEST.
You will be requested to provide some basic information about the domain to be created and a brief justification of the request.
Your request will be reviewed by the nmaas Team and You will receive a reply as soon as possible.
In case of any issues, You can also email your request directly to [email protected].
How can I deploy nmaas on my own infrastructure?
The complete information about the deployment of nmaas instance is available at nmaas Installation Guide).
What are the technical requirement for the underlying nmaas infrastructure?
The complete information about the requirements for the nmaas Kubernetes cluster are available at nmaas Cluster Requirements.
Where can I find nmaas User Guide?
The nmaas User Guide is available at nmaas User Guide.
Where can I find nmaas Administrator Guide?
The nmaas Administrator guide is under preparation and an initial version is available at nmaas Administrator Guide
What applications are currently supported by nmaas?
For the up to date information about the supported applications refer to page nmaas Tools.
It is also possible to browse all the applications in on nmaas Portal directly at https://nmaas.eu.
What type of VPNs are established by nmaas?
Two types of VPN connections are configured before a user is able to deploy and effectively used nmaas applications:
- site-to-site VPN connection as a secure tunnel from the customer's management VLAN to nmaas infrastructure, used for monitoring of the network equipment
- client-access VPN used by the network operators, from their own workstations, to access and configure the deployed network management applications within nmaas.
What VPN solutions are supported by nmaas?
Currently, two site-to-site VPN technologies are actively supported: OpenVPN and WireGuard.
For client-access VPN we are using OpenVPN.
What are nmaas VPN requirements?
To use nmaas, prospective customers require two VPN connections:
- site-to-site VPN connection, establishing a secure tunnel from the customer's management VLAN to nmaas, used for monitoring of the network equipment
- client-access VPN used by the network operators, from their own workstations, to access and configure the deployed network management applications within nmaas.
Currently, two site-to-site VPN technologies are actively supported: OpenVPN and WireGuard.
More details are available in the subsections below.
Site-to-site VPN setup...
Site-to-site VPN
In order to be able to use nmaas, a secure site-to-site tunnel connection is required that will be used for all the monitoring traffic between the network management applications deployed on the nmaas infrastructure and the customer's network devices. As mentioned above, two VPN technologies are currently actively supported for establishing a site-to-site VPN tunnel: OpenVPN and WireGuard. Any one of these can be chosen, depending on the customer's preference or existing networking stack.Required Information
No matter the chosen VPN technology, the nmaas team requires the following information before VPN connectivity can be established:Establishing the VPN connection
Once the necessary information has been exchanged, the nmaas team will provision the necessary VPN and the customer will be sent additional information on how to connect to it. This information will include:Testing the VPN connection
After establishing the VPN connection, the client can perform a simple test to verify that everything is working as expected. The test involves accessing a special IP address on port 80. This special address is customer dependent and will be provided by the nmaas team during the registration process. Any command line utility that can open TCP sessions on an arbitrary port can be used for this test, depending on the platform that you are testing from.Note that ICMP and echo requests are not supported on this IP, and ping is not expected to work.
Client-access VPN setup...
Client-access VPN
A client-access VPN connection is used for accessing and interacting with the deployed applications within nmaas. In order to provide greater security and isolation between the customers, by default, all applications deployed by nmaas are accessible only through the respective client-access profiles, and not publicly. However, the option for publicly exposing a given application is also possible. Currently, the preferred way for establishing the client-access connections is by using an OpenVPN tunnel, since it offers stable packages for all major operating systems.The only information required before the client-access profiles can be generated is a list of individuals, along with their full names and email addresses that should have access to the new nmaas domain being created.
Testing the VPN connection
The client-access connection can be tested in a similar fashion to the site-to-site connection. The operator, after connecting to the nmaas VPN server can simply open a browser and type in the IP address provided by the nmaas team during the registration process.Required information for the VPN profiles...
Required information for the VPN profiles
In conclusion, accessing nmaas requires two types of VPN connections: a site-to-site, and a client-access.Before the site-to-site profiles can be created, nmaas requires the following information:
Before the client-access profile can be created, the following information is needed: