The network design details the design decisions for network segment placement, IP addressing, name resolution, and time synchronization of VMware Aria Operations for Networks.

Network Segment

The network segment design consists of characteristics and decisions for placement of VMware Aria Operations for Networks in the management domain.

For secure access and multi-instance designs, you deploy the VMware Aria Operations for Networks platform nodes on the cross-instance NSX segment. You place the VMware Aria Operations for Networks collector nodes on the corresponding local-instance NSX segments.

This validated solution uses an implementation of the VMware Cloud Foundation application virtual networks feature in the management domain provided by NSX. The application virtual networks in the management domain can be either overlay-backed NSX segments or VLAN-backed NSX segments.
Table 1. NSX Segment Types

Type

Description

Overlay-backed NSX segment

The routing of the VLAN-backed management network segment and other networks is dynamic and based on the Border Gateway Protocol (BGP).

Routed access to the VLAN-backed management network segment is provided through an NSX Tier-1 and Tier-0 gateway.

This design facilitates scale out option to a multi instance design with support for disaster recovery.

VLAN-backed NSX segment

You must provide two unique VLANs, network subnets, and vCenter Server portgroup names.

Figure 1. Network Design for Intelligent Network Visibility
Table 2. Design Decisions on Network Segments for VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-001

Place the VMware Aria Operations for Networks platform nodes on the cross-instance NSX network segment.

Provides a consistent deployment model for management applications and a potential to extend to a second VMware Cloud Foundation instance for disaster recovery.

You must use an implementation of NSX to support this network configuration.

INV-VAON-NET-002

Place the VMware Aria Operations for Networks collector nodes on the local-instance NSX network segment.

Supports collection of metrics and flows locally per VMware Cloud Foundation instance.

You must use an implementation in NSX to support this networking configuration.

Network Segments for Multiple VMware Cloud Foundation Instances

In an environment with multiple VMware Cloud Foundation instances, the VMware Aria Operations for Networks collector nodes in each instance are connected to the corresponding local-instance NSX network segment.

Table 3. Design Decisions on the Network Segments for VMware Aria Operations for Networks for Multiple VMware Cloud Foundation Instances

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-003

In an environment with multiple VMware Cloud Foundation instances, place at least one VMware Aria Operations for Networks collector node in each instance on the local-instance NSX segment.

Supports collection of metrics and flows locally per VMware Cloud Foundation instance.

You must use an implementation in NSX to support this networking configuration.

IP Addressing

Allocate statically assigned IP addresses and host names to the VMware Aria Operations for Networks platform and collector nodes from their corresponding network.

Table 4. Design Decisions on IP Addresses for the VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-004

Allocate and assign static IP addresses from the cross-instance NSX segment for each VMware Aria Operations for Networks platform node.

Static IP addresses provides network reliability, simplifies maintenance, and aids in conflict avoidance, while necessitating robust security due to their predictability.

Requires precise IP address management.

INV-VAON-NET-005

Allocate and assign static IP addresses from the cross-instance NSX segment for each VMware Aria Operations for Networks collector node.

Static IP addresses provides network reliability, simplifies maintenance, and aids in conflict avoidance, while necessitating robust security due to their predictability.

Requires precise IP address management.

IP Addressing for Multiple VMware Cloud Foundation Instances

In an environment with multiple VMware Cloud Foundation instances, the VMware Aria Operations for Networks collector nodes in each instance are assigned IP addresses, associated with their corresponding network.

Table 5. Design Decisions on IP Addresses for the VMware Aria Operations for Networks for Multiple VMware Cloud Foundation Instances

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-006

In an environment with multiple VMware Cloud Foundation instances, allocate and assign static IP addresses from each local-instance NSX segment to the corresponding VMware Aria Operations for Networks collector nodes in the instance.

Static IP addresses provides network reliability, simplifies maintenance, and aids in conflict avoidance, while necessitating robust security due to their predictability.

Requires precise IP address management.

Name Resolution

Name resolution provides the translation between an IP address and a fully qualified domain name (FQDN), which makes it easier to connect components across the SDDC. The IP address of each node must have a valid internal DNS forward (A) and reverse (PTR) records.

Table 6. Design Decisions on Name Resolution for the VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-007

Configure forward and reverse DNS records for each VMware Aria Operations for Networks platform and collector node.

Each VMware Aria Operations for Networks platform and collector node is accessible by using a unique fully qualified domain name.

You must provide the DNS records for the VMware Aria Operations for Networks nodes.

Time Synchronization

Time synchronization provided by the Network Time Protocol (NTP) ensures that all components within the SDDC are synchronized to the same time source. This section of the design consists of characteristics and decisions that support the time configuration for the VMware Aria Operations for Networks platform and collector nodes.

Table 7. Design Decisions on Time Synchronization for the VMware Aria Operations for Networks

Decision ID

Design Decision

Design Justification

Design Implication

INV-VAON-NET-008

Configure the NTP servers on each VMware Aria Operations for Networks platform and collector node.

  • Ensures accurate time synchronization.

  • VMware Aria Operations for Networksdepends on time synchronization.

  • NTP infrastructure services should be highly-available in the environment.

  • Firewalls between the nodes and the NTP servers must allow NTP traffic.

  • You must provide two or more NTP servers unless an NTP geographic load balancing is active.