Networking and Security

About Networking and Security #

The Networking and Security validated solution provides comprehensive guidance on how to use VMware NSX (formerly VMware NSX-T Data Center) with the VMware Cloud Director platform for cloud automation services. This includes design, implementation, and operation recommendations. The VMware validated solution is a thoroughly designed and tested implementation that helps customers address common business use cases. It is created and tested by VMware and its partners to ensure it is efficient, reliable, and secure. Each solution comes with detailed guidance on design, implementation, and operation to ensure successful use.

Automation for This Design in VMware Cloud Foundation #

VMware Cloud Foundation SDDC Manager automates the prerequisite implementation tasks for this design. As noted in the design implications, you must perform the implementation steps manually for the rest of the design decisions. Nevertheless, this document also offers Terraform procedures (VMware NSX Terraform Provider) as code-based alternatives to completing specific procedures to provide a fast and efficient path to automating the VMware NSX for VMware Cloud Director implementation.

Intended Audience #

This documentation is intended for cloud provider architects and administrators who are familiar with and want to use VMware software and a Networking and Security validated solution for VMware Cloud Director.

Support Matrix #

The Networking and Security validated solution is compatible with certain versions of the VMware products that are used for implementing the solution.

Software Components in Networking and Security #
VMware Cloud Foundation Version Product Group Component Versions
5.0 Products part of VMware Cloud Foundation See VMware Cloud Foundation 5.0 Release Notes.
Solution-added products
  • VMware NSX 4.1.0.1
  • NSX Advanced Load Balancer ???
4.5.0 Products part of VMware Cloud Foundation See VMware Cloud Foundation 4.5.0 Release Notes.
Solution-added products
  • VMware NSX-T Data Center 3.2.1.2
  • NSX Advanced Load Balancer ???
4.4.1 Products part of VMware Cloud Foundation See VMware Cloud Foundation 4.4.1 Release Notes.
Solution-added products
  • VMware NSX-T Data Center 3.1.3.7.4
  • NSX Advanced Load Balancer ???
4.4.0 Products part of VMware Cloud Foundation See VMware Cloud Foundation 4.4 Release Notes.
Solution-added products
  • VMware NSX-T Data Center 3.1.3.5
  • NSX Advanced Load Balancer (21.1.1 or later; 20.1.6 or later)
4.3.1 Products part of VMware Cloud Foundation See VMware Cloud Foundation 4.3.1 Release Notes.
Solution-added products
  • VMware NSX-T Data Center 3.1.3.1
  • NSX Advanced Load Balancer (21.1.1 or later; 20.1.6 or later)
4.3.0 Products part of VMware Cloud Foundation See VMware Cloud Foundation 4.3 Release Notes.
Solution-added products
  • VMware NSX-T Data Center 3.1.3
  • NSX Advanced Load Balancer (21.1.1 or later; 20.1.6 or later)

Before You Apply This Guidance #

To design and implement the Networking and Security validated solution, your environment must have a certain configuration.

Supported VMware Cloud Foundation Deployment #
Workload Domain / Component Deployment Details
Management domain
  • Automated deployment using VMware Cloud Builder.
  • Availability of overlay-backed or VLAN-backed NSX segments in NSX-T Data Center for traffic in the same VMware Cloud Foundation instance and between VMware Cloud Foundation instances not required.

See the following VMware Cloud Foundation Documentation:
  • For information on deploying the management domain, see VMware Cloud Foundation Getting Started Guide and VMware Cloud Foundation Deployment Guide.
  • For information on designing the management domain, see VMware Cloud Foundation Design Guide for the Management Domain.
One or more virtual infrastructure workload domains
  • Automated deployment using SDDC Manager

See the following VMware Cloud Foundation Documentation:
  • For information on deploying the VI workload domains, see Getting Started with VMware Cloud Foundation and VMware Cloud Foundation Operations and Administration Guide.
  • For information on designing a VI workload domain, see VMware Cloud Foundation Design Guide for a Virtual Infrastructure Workload Domain.
NSX Edge cluster
  • Automated deployment using SDDC Manager

See the following VMware Cloud Foundation Documentation:
  • For information on deploying the NSX Edge cluster, see VMware Cloud Foundation Getting Started Guide and VMware Cloud Foundation Operations and Administration Guide.
  • For information on designing the NSX Edge cluster, see VMware Cloud Foundation Design Guide for a Virtual Infrastructure Workload Domain.
Advanced Load Balancing
  • Manual deployment using Advanced Load Balancing for VMware Cloud Foundation VMware Validated Solution

See the following VMware Validated Solutions Documentation:
  • For detailed design, implementation, configuration, and operation guidance on the use of NSX Advanced Load Balancer as a Load Balancing solution for workloads on VMware Cloud Foundation, see Advanced Load Balancing for VMware Cloud Foundation.

Overview of Networking and Security #

By implementing the validated Networking and Security solution, you can make full use of VMware Cloud Director’s networking automation services.

Implementation Overview of Networking and Security #
Stage Steps
1. Requirements Validate whether the VMware Cloud Foundation environment is in place and VMware Cloud Director is already deployed.
2. Configure VMware Cloud Director Infrastructure Resources
  1. Register a vCenter Server to VMware Cloud Director
  2. Register an NSX Manager Instance with VMware Cloud Director
  3. Optional - Configure NSX Manager Segment Profile Templates
3. Configure VMware Cloud Director Cloud Resources
  1. Configure VMware Cloud Director Network Pools
  2. Create Provider Virtual Data Center
  3. Create Organization
  4. Create Organization Virtual Data Center

Update History #

This Networking and Security solution is updated when necessary.

Revision Description
1. 14 SEP 2023 Initial document release.

Configuring VMware Cloud Director service for Load Balancing as a Service #

See the instructions below on how to deploy and configure VMware NSX Advanced Load Balancer in combination with VMware Cloud Director to provide Load Balancing as a Service capabitilies for end users.