Setting Up the SCC-VE in Microsoft Azure
  
Setting Up the SCC-VE in Microsoft Azure
SteelCentral Controller for SteelHead (virtual edition) (SCC-VE) is available in Microsoft Hyper-V format. Hyper-V is the Microsoft virtualization technology. For details about Hyper-V, visit the Microsoft website:
https://docs.microsoft.com/en-us/virtualization/hyper-v-on-windows/about/
This appendix describes how to install and configure an SCC-VE on a Hyper-V virtual appliance. It includes these sections:
•  Before using SCC-VE in Azure
•  Prerequisites for installing SCC-VE in Azure
•  Installing SCC-VE in Azure
•  Upgrading the SCC-VE software version
Before using SCC-VE in Azure
This information will help you make the most of your SCC-VE for Azure:
•  In Azure, NAT rules to a virtual machine are very aggressive. These rules can cause frequent failures of the inner connection pool. To avoid this issue, configure your client-side SteelHead appliances that pair with a SCC-VE for Azure so that their inner keepalive interval is 30 seconds or less.
cfe (config) # protocol connection addr <azure-sh-ip> inner-intvl 30 oob-intvl 30
•  License your SCC-VE for Azure after you create it.
•  Out-of-path deployment using fixed-target rules and agent-intercept deployment using Discovery Agent are supported.
Prerequisites for installing SCC-VE in Azure
Before you install the virtual appliance, ensure that these prerequisites are met:
•  You have access credentials to a Microsoft Azure account that allow you to create resources in the region and virtual networks where you want to deploy SCC-VE.
•  You have obtained a one-time token from the Riverbed Cloud Portal to license your SCC-VE. Access the portal at https://cloudportal.riverbed.com.
•  The SCC-VE instance must have continuous SSL/TLS (TCP port 443) access to the Riverbed Cloud Portal in order to verify that the license is active. If the SCC-VE cannot contact the Riverbed Cloud Portal, it will stop optimization and will by-pass connections until it can verify the license again. For enhanced security, configure a TCP proxy in the virtual machine’s Networking > Host Settings.
Installing SCC-VE in Azure
This section provides instructions for installing a SCC-VE virtual appliance on an Azure Hyper-V virtual machine using the default mode (Create a virtual machine wizard.) The programmatic deployment mode is not covered in this document. See the Azure documentation for details about that mode.
Note: The default deployment mode in Microsoft Azure has changed from Classic (programmatic) to Resource Manager (wizard.) SCC-VE can be deployed in either mode; however, resources deployed through different deployment modes cannot interoperate. Select the deployment mode that matches the rest of your infrastructure in Azure.
To install SCC-VE in Azure
1. Log in to the Microsoft Azure portal and navigate to your dashboard.
2. Click Create a resource.
The New page appears. On this page you can find Marketplace items by search, type, or popularity.
3. Search for keywords: Riverbed SteelCentral Controller.
4. Select an image from the available options.
5. In the image details pane, near the bottom, click Create.
The Create a virtual machine page appears.
6. In the Basics section of the wizard, enter this information:
Project Details
–  Select a subscription model.
–  Select a resource group, or click Create new if you want to place the virtual appliance you are creating into a new resource group.
Instance Details
–  Enter a display name for the virtual appliance.
–  Select the region where you want to deploy the virtual appliance.
–  Specify Availability options.
–  Select the image you want to install on the virtual machine. The default is the item you selected in Step 4.
–  Select a size for the virtual machine. The size determines the maximum amount of compute resources (CPU, RAM memory) available to the virtual machine.
Administrator Account
Note: The account that you create in this step is not used. However, use the password you specify here along with the username admin for first-time login. After initial login, you can change your credentials at any time.
–  Specify how administrators will authenticate when logging in to the Hyper-V virtual machine.
7. Click Next : Disks > to advance to the wizard’s Disks tab.
8. Under Disk Options, select a disk type for the SCC-VE virtual appliance’s operating system (RiOS).
9. Optionally enable Ultra SSD compatibility.
10. Under Data Disks, create and attach a disk or attach an existing disk to serve as the SCC-VE virtual appliance’s data store.
If you do not already have a data store disk, select Create and Attach a new disk.
–  In the Create a new disk page, specify these settings: disk type, display name, size in gigabytes (GB), source type.
–  Click OK. A virtual disk with your settings is allocated. The Create a new disk page closes and you are returned to the wizard’s Disk tab. The newly allocated disk is listed under Data Disks.
–  Select Read/Write from the Host Caching drop-down menu corresponding to the newly allocated disk.
11. Under the Advanced section, accept the default values.
12. Click Next : Networking > to advance to the wizard’s Networking tab.
13. Select the network and subnet where you want to deploy the SCC-VE from the Virtual network and Subnet drop-down menus.
If you have not already configured a virtual network and a subnet, click Create new to display the Create new network page. Enter an address space for the new virtual network, create subnets, and then click OK. See the Microsoft Azure help for assistance.
14. Optionally select a public IP address from the Public IP drop-down menu. A public IP enables you to communicate with the virtual appliance from outside the virtual network.
If you want to use a public IP but none exist, click Create new to display the Create public IP address page. Enter a display name for the new IP address, specify SKU and assignment, and then click OK. See the Microsoft Azure help for assistance.
15. NIC network security group is Advanced. NIC network security group settings are preconfigured.
16. Select a network security group from the Configure network security group drop-down menu.
If no security groups exist, click Create new to display the Create network security group page, specify Inbound rules and Outbound rules, and then click OK. See the Microsoft Azure help for assistance.
17. Accelerated networking is Off. Accelerated networking is not supported.
18. Under Load Balancing, select No.
19. Click Next : Management > to advance to the wizard's Management tab.
20. Optionally configure the settings under Monitoring, Identity, and Auto-Shutdown to your liking.
21. Click Next : Guest config > to advance to the wizard's Guest config tab.
22. Click Next : Tags > to advance to the wizard's Tags tab.
23. Optionally add tags.
24. Click Next : Review + create > to advance to the wizard's Review + create tab.
25. Review your selections and then click Create.
26. License your virtual appliance, and then change the default administrator password.
Upgrading the SCC-VE software version
Microsoft Azure does not support upgrading and downgrading software versions through Azure. However, you can use this procedure to upgrade or downgrade the SCC-VE software version.
Note: The SCC-VE IP addresses might change during this process. You might need to update configurations that depend on those IP addresses.
To upgrade or downgrade the SCC-VE software version
1. Download the software package for the new version from the Riverbed Support site:
https://support.riverbed.com
2. Log in to the SCC Management Console web interface using an administrator account.
3. Choose Administration > Maintenance: Software Upgrade to display the Software Upgrade page.
4. Under Install Upgrade, select From Local File.
5. Browse your file system to the software image and select the image.
6. Click Install to upgrade your SCC software.
The software image can be quite large; uploading the image to the system can take a few minutes. Downloading a delta image directly from the Riverbed Support site is faster because the downloaded image includes only the incremental changes and is downloaded directly to the appliance.
As the upgrade progresses, status messages appear.
After the installation is complete, you’re reminded to reboot the system to switch to the new version of the software.
7. Choose Administration > Maintenance: Reboot/Shutdown and click Reboot.
The appliance can take a few minutes to reboot. This behavior is normal because the software is configuring the recovery flash device. Don’t press Ctrl+C, unplug, or otherwise shut down the system during this first boot. There’s no indication displayed during the system boot that the recovery flash device is being configured. After the reboot, the Dashboard, Software Upgrade, and Help pages in the Management Console display the RiOS version upgrade.