The design decisions determine the deployment configuration to support the Cloud-Based Network Visibility for VMware Cloud Foundation validated solution.
Deployment Specification
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-CFG-001 |
Deploy the VMware Aria Operations for Networks Data Collector appliance in the default management vSphere cluster. |
Required to establish secure communication between the VMware Cloud Foundation instance and VMware Aria Operations for Networks. |
The VMware Aria Operations for Networks Data Collector must be able to connect to the internet through a firewall. |
CBN-CDP-CFG-002 |
Protect the VMware Aria Operations for Networks Data Collector appliance by using vSphere High Availability. |
Supports the availability objective without requiring manual intervention during an ESXi host failure. |
None. |
CBN-CDP-CFG-003 |
Place the VMware Aria Operations for Networks Data Collector appliance in a designated virtual machine folder. |
Provides organization of the appliances in the management domain vSphere inventory. |
You must create the virtual machine folder during deployment. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-CFG-004 |
When using two availability zones, add the VMware Aria Operations for Networks Data Collector appliance to the VM group of the first availability zone. |
Ensures that the VMware Aria Operations for Networks Data Collector appliance runs in the primary availability zone hosts group. |
After the implementation of the second availability zone for the management domain, you must update the VM group for the primary availability zone virtual machines to include the VMware Aria Operations for Networks Data Collector appliance. |
Network Design
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-NET-001 |
Place the VMware Aria Operations for Networks Data Collector appliance on the management VLAN. |
|
None. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-NET-002 |
Allocate statically assigned IP addresses from the management VLAN to the VMware Aria Operations for Networks Data Collector appliance. |
Using statically assigned IP addresses ensures stability of the deployment and simplifies maintenance and tracking. |
Requires precise IP address management. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-NET-003 |
Configure forward and reverse DNS records for the VMware Aria Operations for Networks Data Collector appliance IP address. |
Ensures the appliance is accessible by using a fully qualified domain name instead of using IP addresses only. |
|
CBN-CDP-NET-004 |
Configure DNS servers on the VMware Aria Operations for Networks Data Collector appliance. |
Ensures the appliance has accurate name resolution. |
|
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-NET-005 |
Configure NTP servers for the VMware Aria Operations for Networks Data Collector appliance. |
|
|
Life Cycle Management
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-LCM-001 |
Use the VMware Cloud Services Console to perform the upgrades to the VMware Aria Operations for Networks Data Collector appliance. |
You perform manual life cycle management of the VMware Aria Operations for Networks Data Collector appliance by using the VMware Cloud Services Console. |
You must configure email notifications for new updates available. VMware Aria Operations for Networks does not provide automatic upgrades or UI reminders. |
VMware Aria Operations for Networks Design
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-NVA-CFG-001 |
Configure a vCenter Server data source in VMware Aria Operations for Networks, for each management domain and VI workload domain vCenter Server. |
Provides network visibility to the VMware Cloud Foundation instance, for vSphere networking. |
You must configure a data source for the management domain and each VI workload domain vCenter Servers in each region. |
CBN-NVA-CFG-002 |
For each vCenter Server data source, enable NetFlow on each vSphere Distributed Switch within the domain. |
Provides the collection of network flows via the IPFIX protocol. |
For the management domain and VI workload domains in each region, VMware Aria Operations for Networks will automatically update the NetFlow settings for each cluster's vSphere Distributed Switch. |
CBN-NVA-CFG-003 |
Configure a NSX Management cluster data source in VMware Aria Operations for Networks, for each management domain and VI workload domain NSX Management cluster. |
Provides network visibility to the VMware Cloud Foundation instance, for NSX networking. |
You must configure a NSX data source for the management domain and VI workload domains in each region. |
CBN-NVA-CFG-004 |
For each NSX data source, enable IPFIX for the distributed firewall. |
Provides the collection of network flows via the IPFIX protocol. |
The distributed firewall service must be enabled on the NSX Management cluster for the VI workload domain. The service account used to integrate VMware Aria Operations for Networks with NSX requires the Enteprise Admin role to be assigned in NSX Manager for the management and each VI workload domain. |
CBN-NVA-CFG-005 |
For each NSX data source, enable latency metric collection. |
Provides the collection of latency metrics from NSX Transport Nodes. |
Any firewall rule sets from all ESXi hosts to the VMware Aria Operations for Networks Data Collector must allow traffic on TCP 1991. |
CBN-NVA-CFG-006 |
For environments using NSX Federation use the Local Manager as the Data Source |
Global Managers can not be added as a data source in VMware Aria Operations for Networks. All the VMware NSX-T Federation related data is fetched from the Local Managers. |
You must configure the Local Manager as the NSX data source if you are using NSX-T Federation. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-NVA-CFG-007 |
Use the retention period that aligns with your organizations policy requirements. 1 month is the default. |
VMware Aria Operations for Networks SAAS allows the flexibily to choose anywhere between the default value of one month up to the maximum of 13 months. |
You must manage this value in the VMware Aria Operations for Networks Data Management interface to align with your organizations policy requirements. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-NVA-CFG-008 |
Configure VMware Aria Operations for Networks to send notifications and alerts for relevant system events via push or email. |
Enables relevant system events to be sent to operational teams so remediation actions can be taken. |
You must select the system alerts and notifications for the system events that are relevant to the information you want to see. |
Information Security and Access Control Design
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-IAM-SEC-001 |
Limit the use of local accounts for interactive or API access and solution integration. |
Local accounts are not specific to user identity and do not offer complete auditing from an endpoint back to the user identity. |
You must define and manage service accounts, security groups, group membership, and security controls in Active Directory. |
CBN-IAM-SEC-002 |
Limit the scope and privileges for accounts used for interactive or API access and solution integration. |
The principle of least privilege is a critical aspect of access management and must be part of a comprehensive defense-in-depth security strategy. |
You must define and manage custom roles and security controls to limit the scope and privileges used for interactive access or solution integration. |
CBN-IAM-SEC-003 |
Assign VMware Aria Operations for Networks service roles to designated users. |
By assigning Active Directory users with specific VMware Aria Operations for Networks service roles, you introduce improved accountability and facilitate access tracking. |
You must maintain the service roles required for users of your organization. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-NVA-SEC-001 |
Define a custom vCenter Server role for VMware Aria Operations for Networks that has minimum privileges required to support a vCenter Server integration. |
Connects VMware Aria Operations for Networks and each VI workload domain vCenter Server instance using a minimum set of privileges. |
|
CBN-NVA-SEC-002 |
Create and assign the custom vCenter Server role to an Active Directory user account as a service account for each VI workload domain vCenter Server instance for application-to-application communication between VMware Aria Operations for Networks and vCenter Server. |
Provides the following access control features:
|
You must maintain the life cycle, availability, and security controls for the account in Active Directory. |
CBN-NVA-SEC-003 |
Create and assign the Enterprise Admin role to a local NSX guestuser account for each VI workload domain NSX Manager instance for application-to-application communication between VMware Aria Operations for Networks and NSX Manager. |
Provides integration and data collection of network objects managed by NSX Manager for a given workload domain. |
You must manage the local user activation and password expiration settings on each NSX Manager. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-SEC-001 |
Configure the local user password expiration policy for each VMware Aria Operations for Networks Data Collector instance. |
|
You must manage the local user passwords expiration settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console. |
CBN-CDP-SEC-002 |
Configure the local user password complexity policy for each VMware Aria Operations for Networks Data Collector instance. |
|
You must manage the local user password complexity settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console. |
CBN-CDP-SEC-003 |
Configure the local user account lockout policy for each VMware Aria Operations for Networks Data Collector instance. |
|
You must manage the local user account lockout settings on each VMware Aria Operations for Networks Data Collector instance by using the appliance console. |
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
CBN-CDP-SEC-004 |
Change the VMware Aria Operations for Networks Data Collector support and consoleuserpasswords on a recurring or event-initiated schedule. |
The password for the VMware Aria Operations for Networks Data Collector appliance support and consoleuser accounts expires based on the default password expiration policy. |
|
CBN-CDP-SEC-005 |
Change the VMware Aria Operations for Networksguestuser2 password on a recurring or event-initiated schedule. |
The password for the Guest Account that is used to integrate NSX and VMware Aria Operations for Networks expires based on the default password expiration policy. |
You must manage the password change for the Guest Account account. You must monitor the password expiration of the Guest Account password. |