Adding cloud services - User Guide - Micetro - 25.2.0

Micetro Admin Guide

ft:locale
en-US
Product name
Micetro
Version
25.2.0
Note: Before integrating cloud services, Micetro requires several prerequisites. Refer to Micetro components for Windows or Micetro components for Linux to make sure that these prerequisites are met.

You must have permission to administer DNS or DHCP to add a new service to Micetro.

To add a cloud service:

  1. On the Admin page, select the Service management tab.
  2. Select Add service on the task bar.
  3. Select the cloud provider you want to use, enter the required information, and select Add.

Refer to the tabs below for details on each specific cloud provider.

Enter the information required to connect to Akamai Edge DNS:



Obtaining access credentials: For information about how to create API Access Credentials for Micetro, refer to Create EdgeGrid authentication credentials.

Warning: Akamai OPEN APIs are time-sensitive! It is crucial to synchronize the system your client operates on with a Stratum 2 or higher time source.
DANGER
If the time on the server running the DNS Agent differs significantly from Coordinated Universal Time (UTC), authentication will fail, preventing access/updating of zones through Micetro.
Note: Before adding an AWS cloud service, update the VPC security group in AWS to open the ports for the DNS, DHCP, and Update Agents. Refer to Networking requirements.

Enter the information required to connect to Amazon Web Services (AWS):



  • Use the Agent dropdown to select an agent to manage the cloud service. If you are not sure which agent to use, select Use Central host.
  • Enter a Name for the service.
  • Select whether the service will Manage DNS, Manage IPAM, or both.
  • Check the Authenticate with instance roles to use an EC2 instance's IAM role to access AWS services. This requires both the DNS and DHCP Agents to be running inside an AWS instance.
  • If you do not authenticate with instance roles, you must enter an Access key ID and Secret access key to use for authentication. For information about how to create API access credentials for Micetro to use, refer to AWS security credentials.
    Note:

    For information about the minimum permissions required for adding AWS accounts, refer to Permissions for integrating AWS cloud services with Micetro.

  • Check the Use organizational discovery checkbox to enable Micetro to automatically discover and manage AWS resources in accounts belonging to the AWS Organization that Micetro has access to.

    If you select to use organizational discovery, you need to complete the following fields:

    • Account management role name—The name of the role that Micetro will assume to manage accounts belonging to your AWS organization.
    • Organization management role ARN—The role ARN that Micetro will assume to discover accounts belonging to your AWS organization.
    • (Optional) Ignore list—A list of organizational units or account IDs to ignore during organizational discovery, separated by newlines or commas.

Enter the information required to connect to Azure:



  • Use the Agent dropdown to select an agent to manage the cloud service. If you are not sure which agent to use, select Use Central host.
  • Enter a Name for the service.
  • Select whether the service will Manage DNS, Manage IPAM, or both.
  • Enter the following access credentials to access Azure DNS: Tenant ID, Subscription ID, Client ID and Client secret. For instructions on how to retrieve this information, refer to the Microsoft documentation.
  • To use Azure government, check the Use Azure government checkbox.

For information about how to configure Azure, refer to Configuring Azure.

To manage Meraki with Micetro, you must have an operational instance of the Micetro DHCP Agent. For additional details about the DHCP Agent, refer to Installing Micetro DHCP Agents on Windows or Installing Micetro DHCP Agents on Linux.

In the Add service wizard, enter the following information:



  • Use the Agent dropdown to select a Micetro DHCP agent to proxy requests through.
  • Enter a Name for the service.
  • Enter an API key to access the service.
  • In the Ignore list field, enter the Meraki Organization or Network IDs that Micetro should exclude from synchronization. List one ID per line.

For information about how to create API Access Credentials for use by Micetro, refer to Cisco Meraki Dashboard API.

Synchronization parameters, e.g., network client synchronization interval, can be configured in the Advanced system settings.

Enter the information required to connect to NS1:



Obtaining access credentials: For information about how to create API Access Credentials for use by Micetro, refer to IBM NS1 Connect.

The service and any subnets defined will be displayed under DNS services or DHCP services, respectively.