The design decisions determine the deployment configuration to support the Cloud-Based Network Visibility for VMware Cloud Foundation validated solution.

Deployment Specification

Table 1. Design Decisions for Deployment of the VMware Aria Operations for Networks Data Collector Appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-CFG-001

Deploy the VMware Aria Operations for Networks Data Collector appliance in the default management vSphere cluster.

Required to establish secure communication between the VMware Cloud Foundation instance and VMware Aria Operations for Networks.

The VMware Aria Operations for Networks Data Collector must be able to connect to the internet through a firewall.

CBN-CDP-CFG-002

Protect the VMware Aria Operations for Networks Data Collector appliance by using vSphere High Availability.

Supports the availability objective without requiring manual intervention during an ESXi host failure.

None.

CBN-CDP-CFG-003

Place the VMware Aria Operations for Networks Data Collector appliance in a designated virtual machine folder.

Provides organization of the appliances in the management domain vSphere inventory.

You must create the virtual machine folder during deployment.

Table 2. Design Decisions for Deployment of the VMware Aria Operations for Networks Data Collector Appliance in Multiple Availability Zones

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-CFG-004

When using two availability zones, add the VMware Aria Operations for Networks Data Collector appliance to the VM group of the first availability zone.

Ensures that the VMware Aria Operations for Networks Data Collector appliance runs in the primary availability zone hosts group.

After the implementation of the second availability zone for the management domain, you must update the VM group for the primary availability zone virtual machines to include the VMware Aria Operations for Networks Data Collector appliance.

Network Design

Table 3. Design Decisions on Network Segments for the VMware Aria Operations for Networks Data Collector appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-NET-001

Place the VMware Aria Operations for Networks Data Collector appliance on the management VLAN.

  • Places the VMware Aria Operations for Networks Data Collector on the same network as the VMware Cloud Foundation components that the appliance must communicate with.

  • Provides a consistent deployment model for VMware Cloud services.

None.

Table 4. Design Decisions on IP Addresses for the VMware Aria Operations for Networks Data Collector Appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-NET-002

Allocate statically assigned IP addresses from the management VLAN to the VMware Aria Operations for Networks Data Collector appliance.

Using statically assigned IP addresses ensures stability of the deployment and simplifies maintenance and tracking.

Requires precise IP address management.

Table 5. Design Decisions on Name Resolution for the VMware Aria Operations for Networks Data Collector Appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-NET-003

Configure forward and reverse DNS records for the VMware Aria Operations for Networks Data Collector appliance IP address.

Ensures the appliance is accessible by using a fully qualified domain name instead of using IP addresses only.

  • You must provide a DNS record for the appliance IP address.

  • Firewalls between the appliance and the DNS servers must allow DNS traffic.

CBN-CDP-NET-004

Configure DNS servers on the VMware Aria Operations for Networks Data Collector appliance.

Ensures the appliance has accurate name resolution.

  • DNS infrastructure services should be highly-available in the environment.

  • Firewalls between the appliance and the DNS servers must allow DNS traffic.

  • You must provide two or more DNS servers unless a DNS geographic load balancing is active.

Table 6. Design Decisions on Time Synchronization for the VMware Aria Operations for Networks Data Collector Appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-NET-005

Configure NTP servers for the VMware Aria Operations for Networks Data Collector appliance.

  • Ensures that the appliance has accurate time synchronization.

  • Assists in the prevention of time mismatch between the appliance and dependencies.

  • NTP infrastructure services should be highly-available in the environment.

  • Firewalls between the appliance and the NTP servers must allow NTP traffic.

  • You must provide two or more NTP servers unless an NTP geographic load balancing is active.

Life Cycle Management

Table 7. Design Decisions on Life Cycle Management for the VMware Aria Operations for Networks Data Collector Appliance

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-LCM-001

Use the VMware Cloud Services Console to perform the upgrades to the VMware Aria Operations for Networks Data Collector appliance.

You perform manual life cycle management of the VMware Aria Operations for Networks Data Collector appliance by using the VMware Cloud Services Console.

You must configure email notifications for new updates available. VMware Aria Operations for Networks does not provide automatic upgrades or UI reminders.

VMware Aria Operations for Networks Design

Table 8. Design Decisions on Data Sources for VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

CBN-NVA-CFG-001

Configure a vCenter Server data source in VMware Aria Operations for Networks, for each management domain and VI workload domain vCenter Server.

Provides network visibility to the VMware Cloud Foundation instance, for vSphere networking.

You must configure a data source for the management domain and each VI workload domain vCenter Servers in each region.

CBN-NVA-CFG-002

For each vCenter Server data source, enable NetFlow on each vSphere Distributed Switch within the domain.

Provides the collection of network flows via the IPFIX protocol.

For the management domain and VI workload domains in each region, VMware Aria Operations for Networks will automatically update the NetFlow settings for each cluster's vSphere Distributed Switch.

CBN-NVA-CFG-003

Configure a NSX Management cluster data source in VMware Aria Operations for Networks, for each management domain and VI workload domain NSX Management cluster.

Provides network visibility to the VMware Cloud Foundation instance, for NSX networking.

You must configure a NSX data source for the management domain and VI workload domains in each region.

CBN-NVA-CFG-004

For each NSX data source, enable IPFIX for the distributed firewall.

Provides the collection of network flows via the IPFIX protocol.

The distributed firewall service must be enabled on the NSX Management cluster for the VI workload domain.

The service account used to integrate VMware Aria Operations for Networks with NSX requires the Enteprise Admin role to be assigned in NSX Manager for the management and each VI workload domain.

CBN-NVA-CFG-005

For each NSX data source, enable latency metric collection.

Provides the collection of latency metrics from NSX Transport Nodes.

Any firewall rule sets from all ESXi hosts to the VMware Aria Operations for Networks Data Collector must allow traffic on TCP 1991.

CBN-NVA-CFG-006

For environments using NSX Federation use the Local Manager as the Data Source

Global Managers can not be added as a data source in VMware Aria Operations for Networks. All the VMware NSX-T Federation related data is fetched from the Local Managers.

You must configure the Local Manager as the NSX data source if you are using NSX-T Federation.

Table 9. Design Decisions on Data Retention for VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

CBN-NVA-CFG-007

Use the retention period that aligns with your organizations policy requirements. 1 month is the default.

VMware Aria Operations for Networks SAAS allows the flexibily to choose anywhere between the default value of one month up to the maximum of 13 months.

You must manage this value in the VMware Aria Operations for Networks Data Management interface to align with your organizations policy requirements.

Table 10. Design Decisions on Notifications and Alerts for VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

CBN-NVA-CFG-008

Configure VMware Aria Operations for Networks to send notifications and alerts for relevant system events via push or email.

Enables relevant system events to be sent to operational teams so remediation actions can be taken.

You must select the system alerts and notifications for the system events that are relevant to the information you want to see.

Information Security and Access Control Design

Table 11. Design Decisions on Identity Management for Cloud-Based Network Visibility

Decision ID

Design Decision

Design Justification

Design Implication

CBN-IAM-SEC-001

Limit the use of local accounts for interactive or API access and solution integration.

Local accounts are not specific to user identity and do not offer complete auditing from an endpoint back to the user identity.

You must define and manage service accounts, security groups, group membership, and security controls in Active Directory.

CBN-IAM-SEC-002

Limit the scope and privileges for accounts used for interactive or API access and solution integration.

The principle of least privilege is a critical aspect of access management and must be part of a comprehensive defense-in-depth security strategy.

You must define and manage custom roles and security controls to limit the scope and privileges used for interactive access or solution integration.

CBN-IAM-SEC-003

Assign VMware Aria Operations for Networks service roles to designated users.

By assigning Active Directory users with specific VMware Aria Operations for Networks service roles, you introduce improved accountability and facilitate access tracking.

You must maintain the service roles required for users of your organization.

Table 12. Design Decisions on Service Accounts for Cloud-Based Network Visibility

Decision ID

Design Decision

Design Justification

Design Implication

CBN-NVA-SEC-001

Define a custom vCenter Server role for VMware Aria Operations for Networks that has minimum privileges required to support a vCenter Server integration.

Connects VMware Aria Operations for Networks and each VI workload domain vCenter Server instance using a minimum set of privileges.

  • You must maintain the privileges required by the custom vSphere role.

CBN-NVA-SEC-002

Create and assign the custom vCenter Server role to an Active Directory user account as a service account for each VI workload domain vCenter Server instance for application-to-application communication between VMware Aria Operations for Networks and vCenter Server.

Provides the following access control features:

  • VMware Aria Operations for Networks accesses each VI workload domain vCenter Server instance with a minimum set of permissions.

  • If there is a compromised account, the accessibility to the destination instance remains restricted.

  • You can introduce an improved accountability in tracking request-response interactions between VMware Aria Operations for Networks and the vCenter Server endpoint.

You must maintain the life cycle, availability, and security controls for the account in Active Directory.

CBN-NVA-SEC-003

Create and assign the Enterprise Admin role to a local NSX guestuser account for each VI workload domain NSX Manager instance for application-to-application communication between VMware Aria Operations for Networks and NSX Manager.

Provides integration and data collection of network objects managed by NSX Manager for a given workload domain.

You must manage the local user activation and password expiration settings on each NSX Manager.

Table 13. Design Decisions on Password Policies for Cloud-Based Network Visibility

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-SEC-001

Configure the local user password expiration policy for each VMware Aria Operations for Networks Data Collector instance.

  • You configure the local user password expiration policy for each VMware Aria Operations for Networks Data Collector instance to align with the requirements of your organization which might be based on industry compliance standards.

  • The local user password expiration policy is applicable to the support and consoleuseraccounts for the VMware Aria Operations for Networks Data Collector appliance.

You must manage the local user passwords expiration settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console.

CBN-CDP-SEC-002

Configure the local user password complexity policy for each VMware Aria Operations for Networks Data Collector instance.

  • You configure the local user password complexity policy for each VMware Aria Operations for Networks Data Collector instance to align with the requirements of your organization which might be based on industry compliance standards.

  • The local user password complexity policy is applicable only to the local VMware Aria Operations for Networks Data Collector appliance users.

You must manage the local user password complexity settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console.

CBN-CDP-SEC-003

Configure the local user account lockout policy for each VMware Aria Operations for Networks Data Collector instance.

  • You configure the local user account lockout policy for each VMware Aria Operations for Networks Data Collector instance to align with the requirements of your organization which might be based on industry compliance standards.

  • The local user account lockout policy is applicable only to the local VMware Aria Operations for Networks Data Collector appliance users.

You must manage the local user account lockout settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console.

Table 14. Design Decisions on Password Management for Cloud-Based Network Visibility

Decision ID

Design Decision

Design Justification

Design Implication

CBN-CDP-SEC-004

Change the VMware Aria Operations for Networks Data Collector support and consoleuserpasswords on a recurring or event-initiated schedule.

The password for the VMware Aria Operations for Networks Data Collector appliance support and consoleuser accounts expires based on the default password expiration policy.

  • You must manage the password change for the support and consoleuser account.

  • You must manage the password change on each VMware Aria Operations for Networks Data Collector appliance by using the virtual appliance console.

  • You must monitor the password expiration of the accounts passwords.

CBN-CDP-SEC-005

Change the VMware Aria Operations for Networksguestuser2 password on a recurring or event-initiated schedule.

The password for the Guest Account that is used to integrate NSX and VMware Aria Operations for Networks expires based on the default password expiration policy.

You must manage the password change for the Guest Account account. You must monitor the password expiration of the Guest Account password.