After deploying and configuring VMware Cloud Director Availability and the external access, the next step is configuring from where VMware Cloud on AWS allows establishing pairings. Create an additional compute group with the public IP addresses allowed for pairing and an additional firewall rule allowing the access from this new group to the Public Service Endpoint.
To allow pairing with VMware Cloud Director Availability in VMware Cloud on AWS, in the compute group below add the public IP addresses of the Public Service Endpoint instances and the on-premises appliances.
Prerequisites
- Verify that before pairing, network port 3030/TCP from the remote Tunnel Appliance and the remote On-Premises to Cloud Director Replication Appliance to the Replicator Appliance in VMware Cloud on AWS is allowed. For information about the required network ports, see https://ports.vmware.com/home/VMware-Cloud-Director-Availability.
- Verify that VMware Cloud Director Availability in VMware Cloud on AWS is configured. For more information, see Configure VMware Cloud Director Availability in VMware Cloud on AWS.
Procedure
- Log in to VMware Cloud on AWS at https://vmc.vmware.com.
- In the VMC console, in the left pane click SDDCs.
- Under the SDDC click View Details and click the Networking & Security tab.
- To allow accessing the Public Service Endpoint compute gateway service in VMware Cloud on AWS, create a compute group containing the remote sites IP addresses.
- On the Networking & Security tab, in the left pane under the Inventory section click Groups.
- To create the compute group, under the Compute Groups tab, click Add Group and enter a group name, for example enter VCDA Pairing Compute Group.
- To add trusted sites members to the compute group, under the Compute Members column, click the Set Members link.
- In the Select Members window, on the IP Addresses tab enter the IP addresses of the following site members and click Apply.
- To allow each private cloud site backed by VMware Cloud Director pairing, add the Public Service Endpointpublic-IP-address of the Tunnel Appliance in the private cloud site.
- To allow each tenant pairing, add the public-IP-addresses of all their On-Premises to Cloud Director Replication Appliance instances.
Important: Adding or removing IP addresses from this compute group controls which remote cloud sites and on-premises tenants can establish pairing with VMware Cloud Director Availability in VMware Cloud on AWS.Before VMware Cloud Director Availability pairs with another site, to allow the pair add the remote site IP address in the VCDA Pairing Compute Group.
- To save the pairing compute group, click Save.
- To allow access from the pairing compute group, create a compute gateway firewall rule.
- On the Networking & Security tab, in the left pane under the Security section, click Gateway Firewall.
- On the Compute Gateway tab, click Add Rule and configure the following settings.
Option Description Name Enter a name for the compute gateway firewall rule, for example enter VCDA Pairing Compute Rule. Sources Click Any in the Sources column, then in the Set Source window select User Defined Groups, select the pairing IP addresses compute group, for example select VCDA Pairing Compute Group, and click Apply. Destinations Click Any in the Sources column, then in the Set Source window select User Defined Groups, select the Tunnel Appliance IP address compute group, for example select VCDA Tunnel Compute Group, and click Apply. Services In the Services column, click Any, then in the Set Source window, select the Public Service Endpoint service, for example select VCDA-Service-Endpoint TCP (Source: Any | Destination: 8048) and click Apply. Applied To All Uplinks Action Allow By default, the new compute gateway firewall rule is enabled, allowing the Tunnel Appliance Public Service Endpoint access from the pairing IP addresses compute group. - To publish the new compute gateway firewall rule, click Publish.
The new rule receives an integer ID value, used in the log entries that it generates.
Results
VMware Cloud Director Availability in VMware Cloud on AWS allows pairing with On-Premises to Cloud Director Replication Appliance instances and with VMware Cloud Director Availability instances in private cloud sites backed by VMware Cloud Director.
What to do next
- Tenants can now configure and pair their On-Premises to Cloud Director Replication Appliance and migrate their workloads to VMware Cloud on AWS. For more information, see Configure and Pair the On-Premises to Cloud Director Replication Appliance.
- You can now pair private cloud sites and migrate cloud workloads to VMware Cloud on AWS. For more information, see Pair VMware Cloud Director Cloud Sites.
- You can allow administrative operations by using the management interfaces of the services of VMware Cloud Director Availability. For more information, see Post-configure the SDDC networking in VMware Cloud on AWS.