Configure Segments with the New Orchestrator UI
Segmentation is the process of dividing the network into logical sub-networks called Segments by using isolation techniques on a forwarding device such as a switch, router, or firewall. Network segmentation is required when traffic from different organizations and data types must be isolated.
In the segment-aware topology, different Virtual Private Network (VPN) profiles can be enabled for each segment. For example, Guest traffic can be backhauled to remote data center firewall services, Voice media can flow direct from Branch-to-Branch based on dynamic tunnels, and the PCI segment can backhaul traffic to the data center to exit out of the PCI network.
- In the Enterprise portal, select the Open New Orchestrator UI option available at the top of the Window.
- Select Launch New Orchestrator UI in the pop-up window.
- The UI opens in a new tab displaying the monitoring and configuring options.
In the new Orchestrator UI, select the Configure tab.
- Does not upload user flow stats to Orchestrator except for VeloCloud Control, VeloCloud Management, and a single IP flow that counts all transmitted and received packets and bytes sent on the segment. For example, Customer flow stats like Source IP, Destination IP and so on, are not shown in the Monitor tab for the flows related to Private segment.
- Does not allow users to view flows in Remote Diagnostics.
- Does not allow traffic to be sent as Internet Multipath as all business policies that are set to Internet Multipath are automatically overridden to Direct by the Edge.
If the segment is configured as CDE, then the hosted Orchestrator and Controller will be aware of the PCI segment and will be in the PCI scope. Gateways (marked as non-CDE Gateways) will not be aware or transmit PCI traffic and will be out of PCI scope.
To remove a Segment, select the Segment and select Delete. You cannot delete a Segment used by a Profile.
