Adding cloud services - User Guide - Micetro - 26.1.0

Micetro Admin Guide

ft:locale
en-US
Product name
Micetro
Version
26.1.0
Note: Before integrating cloud services, Micetro requires several prerequisites. Refer to Micetro components for Windows or Micetro components for Linux to make sure that these prerequisites are met.

You must have permission to administer DNS or DHCP to add a new service to Micetro.

To add a cloud service:

  1. On the Admin page, select the Service management tab.
  2. Select Add service on the task bar.
  3. Select the cloud provider you want to use, enter the required information, and select Add.
    The Service type step of the Add service wizard.

Refer to the tabs below for details on each specific cloud provider.

Enter the information required to connect to Akamai Edge DNS:


The Add service wizard for Akamai Edge DNS. Required information to add an Akamai Edge DNS service include a name for the service, as well as access credentials to connect to the service.

Obtaining access credentials: For information about how to create API Access Credentials for Micetro, refer to the Akamai documentation on creating EdgeGrid authentication credentials.

Warning: Akamai OPEN APIs are time-sensitive! It is crucial to synchronize the system your client operates on with a Stratum 2 or higher time source.
DANGER
If the time on the server running the DNS Agent differs significantly from Coordinated Universal Time (UTC), authentication will fail, preventing you from accessing or updating zones through Micetro.
Note: Before adding an AWS cloud service, update the VPC security group in AWS to open the ports for the DNS, DHCP, and Update Agents. Refer to Networking requirements.
  1. Enter the information required to connect to Amazon Web Services (AWS):
    The Add service wizard for Amazon Web Services (AWS).
    • Use the Agent dropdown to select an agent to manage the cloud service. If you are not sure which agent to use, select Use Central host.
    • Enter a Name for the service.
    • Select whether the service will Manage DNS, Manage IPAM, or both.
    • Check the Authenticate with instance roles to use an EC2 instance's IAM role to access AWS services. This requires both the DNS and DHCP Agents to be running inside an AWS instance.
    • If you do not authenticate with instance roles, you must enter an Access key ID and Secret access key to use for authentication. For information about how to create API access credentials for Micetro to use, refer to AWS security credentials.
      Note:

      For information about the minimum permissions required for adding AWS accounts, refer to Permissions for integrating AWS cloud services with Micetro.

  2. Check the Use organization discovery checkbox to enable Micetro to automatically discover and manage AWS resources in accounts belonging to the AWS Organization that Micetro has access to.
  3. Check the Exclude regions checkbox to skip discovery and management of resources in specific regions. If selected, you will be prompted in a subsequent step to select regions from which to exclude resources during discovery.
  4. Select Next.
  5. If you selected to use organization discovery, complete the following fields in the Organization discovery settings step:
    The Organization discovery settings step of the Add service wizard for an AWS service.
    • Account management role name: The name of the role that Micetro will assume to manage accounts belonging to your AWS organization.
    • Organization management role ARN: The role ARN that Micetro will assume to discover accounts belonging to your AWS organization.
    • (Optional) Ignore list: A list of organizational units or account IDs to ignore during organizational discovery, separated by newlines or commas.
      Note: If you add an account that is currently managed by Micetro to the ignore list, it will be removed from Micetro.
  6. Select Next.
  7. If you selected to exclude regions, select the AWS regions where discovery should not be run in the AWS region exclusions step. Account-specific exclusions become available after the service has been added to Micetro and can be added by editing the service properties.
    The AWS region exclusions step of the Add service wizard for an AWS service.

Enter the information required to connect to Azure:


The Add service wizard for Azure.
  • Use the Agent dropdown to select an agent to manage the cloud service. If you are not sure which agent to use, select Use Central host.
  • Enter a Name for the service.
  • Select whether the service will Manage DNS, Manage IPAM, or both.
  • To use managed identities instead of secrets, certificates, or other forms of authentication, select the Authenticate with managed identities checkbox. To use managed identities, the agent must be running on a virtual machine in Azure with managed identities enabled. For more information about managed identities, refer to What is managed identities for Azure resources?.
    Note: Micetro supports authentication with both system-assigned and user-assigned managed identities. When using a user-assigned managed identity, you must also specify the Client ID of the user-assigned managed identity. This ensures that, if a virtual machine has multiple user-assigned managed identities, Micetro can determine which one to use for authentication. For instructions on how to set up managed identities in Azure, refer to Configure managed identities on Azure virtual machines (VMs).
  • Enter the following access credentials to access Azure DNS: Tenant ID, Subscription ID, Client ID and Client secret. For instructions on how to retrieve this information, refer to the Microsoft documentation.

    If you choose to use managed identities, you do not need to enter these access credentials.

  • To use Azure government, check the Use Azure government checkbox.

For information about how to configure Azure, refer to Configuring Azure.

To manage Meraki with Micetro, you must have an operational instance of the Micetro DHCP Agent. For additional details about the DHCP Agent, refer to Installing Micetro DHCP Agents on Windows or Installing Micetro DHCP Agents on Linux.

In the Add service wizard, enter the following information:


The Add service wizard for Cisco Meraki DHCP.
  • Use the Agent dropdown to select a Micetro DHCP agent to proxy requests through.
  • Enter a Name for the service.
  • Enter an API key to access the service.
  • In the Ignore list field, enter the Meraki Organization or Network IDs that Micetro should exclude from synchronization. List one ID per line.

For information about how to create API Access Credentials for use by Micetro, refer to Cisco Meraki Dashboard API.

Synchronization parameters, such as network client synchronization interval, can be configured in the Advanced system settings.

Enter the information required to connect to NS1:


The Add service dialog for NS1 DNS. Required information to add an NS1 service include a name for the service and an API key to access it.

Obtaining access credentials: For information about how to create API Access Credentials for use by Micetro, refer to the IBM NS1 Connect documentation.

The service and any subnets defined will be displayed under DNS services or DHCP services, respectively.