Reader small image

You're reading from  VMware Cloud on AWS Blueprint

Product typeBook
Published inFeb 2024
PublisherPackt
ISBN-139781803238197
Edition1st Edition
Right arrow
Authors (3):
Oleg Ulyanov
Oleg Ulyanov
author image
Oleg Ulyanov

Oleg Ulyanov is a Staff Cloud Architect with more than 15 years of experience. He is a Subject Matter Expert in VMware Hybrid Cloud, cloud migration, networking, and storage. He has experience as a VMware professional services architect, helping customers achieve their technical and business goals through IT transformation and migrating to VMware Hybrid Clouds. He holds various industry certificates, including VMware VCP, VCAP6/7-DCV, SNIA, and Microsoft.
Read more about Oleg Ulyanov

Michael Schwartzman
Michael Schwartzman
author image
Michael Schwartzman

Michael Schwartzman, a Senior Azure Application Innovation Specialist at Microsoft, has over a decade of experience in cloud infrastructure, cloud security, and hybrid cloud solutions. Prior to his current role, Michael served as a Lead Cloud Solution Architect specializing in VMware Cloud on AWS. He has played a pivotal role in assisting Global ISVs with the development and sale of SaaS solutions on Azure. Additionally, Michael's broad expertise encompasses support for both digital natives and traditional enterprises, optimization of their cloud systems. His dedication to remaining at the forefront of the rapidly evolving tech landscape establishes him as a go-to expert for businesses seeking to leverage cutting-edge cloud technology.
Read more about Michael Schwartzman

Harsha Sanku
Harsha Sanku
author image
Harsha Sanku

Harsha Sanku is a Solutions Architect at Amazon Web Services, specializing in AWS Hybrid Cloud and Edge Computing services. His expertise lies in Cloud Infrastructure including Networking & Security. He has been a VMware Cloud on AWS Specialist for the last four years. Harsha has a strong background in designing and implementing data center infrastructure and private clouds, with a particular focus on VMware technologies. In his current role at AWS, he collaborates with customers to migrate and modernize their hybrid cloud infrastructure, ensuring they remain competitive in the ever-evolving business and IT landscape.
Read more about Harsha Sanku

View More author details
Right arrow

Exploring Integrated Services Configuration

In this chapter, you will gain a comprehensive understanding of the intricacies involved in configuring integrated services. These services encompass the NSX Advanced security service, which offers a Layer 7 firewall and Intrusion Prevention System/Intrusion Detection System (IPS/IDS) security features. Additionally, you will explore VMware HCX, VMware Aria Operations for Logs, and the Tanzu Kubernetes Grid Service. By delving into these topics, you will acquire the essential knowledge required for your day-to-day tasks.

Specifically, this chapter covers the following topics:

  • Configuring the NSX Advanced Firewall service
  • The VMware HCX service
  • VMware Aria Operations for Logs
  • The Tanzu Kubernetes Grid managed service

Configuring the NSX Advanced Firewall service

The NSX Advanced Firewall service enables the following capabilities:

  • A distributed IDS/IPS
  • A distributed Firewall with the Layer 7 Application ID
  • A distributed Firewall (DFW) with an Active Directory-based user ID – Identity Firewall (IDFW)
  • A distributed Firewall with FQDN filtering

The NSX Advanced Firewall service further enhances the capabilities of the integrated distributed firewall, by providing end-to-end visibility and protection for the application traffic. This service protects both east-west and north-south traffic flows and offers additional protection against malware. From an architectural perspective, incorporating the NSX Advanced Firewall service into an SDDC is advisable when your design necessitates stringent compliance and security requirements, mandating end-to-end protection for application traffic. The NSX Advanced Firewall service is a paid service, billed per all the hosts in the...

The VMware HCX service

The VMware Hybrid Cloud Extension (HCX) service enables users to connect and migrate workloads from on-premises to VMware Cloud on AWS and back again, or from VMware Cloud on AWS to/from another VMware Cloud vSphere-based environment. HCX has a number of unique features that help to address the most sophisticated migration use cases, including the ability to schedule a migration, define a migration group, and stretch a Layer 2 network to the cloud.

Deploying and activating the HCX service

The steps to do this are as follows:

  1. To activate HCX, navigate to the SDDC console and then the Integrated Services tab, and select OPEN HCX, as shown in the following figure:
Figure 7.12 – The HCX add-on section

Figure 7.12 – The HCX add-on section

  1. Next, a new tab will open where we can initiate the HCX deployment on the VMware Cloud side. To do so, click on DEPLOY HCX, as shown in the following screenshot:
Figure 7.13 – Deploying the HCX add-on

Figure 7.13 ...

VMware Aria Operations for Logs

VMware Aria Operations for Logs aggregates logs from all infrastructure-related services in VMware Cloud on AWS, such as vCenter, ESXi, NSX, and the SDDC console. It is automatically preconfigured for all services. From the Cloud Service console, navigate to Services and select VMware Aria Operations for Logs.

Once inside the service, users can see a flow of all the different log messages and a summary of event types, as shown in the following screenshot:

Figure 7.61 – VMware Aria Operations for Logs

Figure 7.61 – VMware Aria Operations for Logs

Users have the ability to search for specific log messages, such as those associated with VPN events, by utilizing free-form text queries. For instance, entering the query terms text | Contains | vpn in the query field and clicking on the search icon will display all log messages in the environment containing the text VPN, as illustrated in Figure 7.62:

Figure 7.62 – VMware Aria Operations for Logs search

Figure 7.62 – VMware Aria Operations...

The Tanzu Kubernetes Grid managed service

The Tanzu Kubernetes Grid (TKG) managed service is included as part of the basic offering of VMware Cloud on AWS. Users can run, deploy, manage, and operate Kubernetes clusters on top of VMware Cloud on AWS, like they can with on-premises vSphere. The SDDC console provides a mechanism to enable TKGs on a selected cluster within an SDDC.

Note

To enable TKG, a cluster should have at least three hosts.

To activate TKG, you need to open the SDDC console, and inside the specific SDDC under ACTIONS, select Activate Tanzu Kubernetes Grid. This will initiate the deployment wizard for TKG, as shown in the following screenshot:

Figure 7.65 – Activation of vSphere with Tanzu

Figure 7.65 – Activation of vSphere with Tanzu

On the first screen of the wizard, you will need to fill in the networking details of the service CIDR used within the Tanzu Supervisor Cluster for Kubernetes Services, such as ClusterAPI and etcd. Namespace Network CIDR defines a new...

Summary

In this chapter, we reviewed how to configure VMware NSX Advanced Firewall, deploy HCX end to end, implement the different HCX migration methods, navigate and configure alert capabilities in VMware Aria Operations for Logs for VMware Cloud on AWS, and configure vSphere with Tanzu services.

In the following chapter, we’ll cover the topic of building applications and managing operations.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
VMware Cloud on AWS Blueprint
Published in: Feb 2024Publisher: PacktISBN-13: 9781803238197
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Authors (3)

author image
Oleg Ulyanov

Oleg Ulyanov is a Staff Cloud Architect with more than 15 years of experience. He is a Subject Matter Expert in VMware Hybrid Cloud, cloud migration, networking, and storage. He has experience as a VMware professional services architect, helping customers achieve their technical and business goals through IT transformation and migrating to VMware Hybrid Clouds. He holds various industry certificates, including VMware VCP, VCAP6/7-DCV, SNIA, and Microsoft.
Read more about Oleg Ulyanov

author image
Michael Schwartzman

Michael Schwartzman, a Senior Azure Application Innovation Specialist at Microsoft, has over a decade of experience in cloud infrastructure, cloud security, and hybrid cloud solutions. Prior to his current role, Michael served as a Lead Cloud Solution Architect specializing in VMware Cloud on AWS. He has played a pivotal role in assisting Global ISVs with the development and sale of SaaS solutions on Azure. Additionally, Michael's broad expertise encompasses support for both digital natives and traditional enterprises, optimization of their cloud systems. His dedication to remaining at the forefront of the rapidly evolving tech landscape establishes him as a go-to expert for businesses seeking to leverage cutting-edge cloud technology.
Read more about Michael Schwartzman

author image
Harsha Sanku

Harsha Sanku is a Solutions Architect at Amazon Web Services, specializing in AWS Hybrid Cloud and Edge Computing services. His expertise lies in Cloud Infrastructure including Networking & Security. He has been a VMware Cloud on AWS Specialist for the last four years. Harsha has a strong background in designing and implementing data center infrastructure and private clouds, with a particular focus on VMware technologies. In his current role at AWS, he collaborates with customers to migrate and modernize their hybrid cloud infrastructure, ensuring they remain competitive in the ever-evolving business and IT landscape.
Read more about Harsha Sanku