Maintaining the safety and security of your SDDC management infrastructure is critical. By default, the management gateway blocks traffic to all management network destinations from all sources.
When configuring access to the SDDC management infrastructure, it's important that you create management gateway firewall rules that allow only the necessary access to the SDDC management network. To access the Management Gateway, you can Configure AWS Direct Connect Between Your SDDC and On-Premises Data Center, Configure a VPN Connection Between Your SDDC and On-Premises Data Center, or do both. Direct Connect, which provides private connectivity between your enterprise and the SDDC, can be used alone or in conjunction with an IPsec VPN to encrypt traffic.
If you can't use Direct Connect, VMware Managed Transit Gateway, or a VPN, you can access the SDDC vCenter directly over the Internet using public DNS and the vCenter public IP. If you do this, you must create management gateway firewall rules that prevent untrusted sources from accessing the management network. A VPN provides additional security through encryption and authentication protocols.
- Pre-defined firewall rules are created and managed by VMware Cloud on AWS. You cannot modify or reorder these rules. There is one pre-defined Management Gateway firewall rule:
Table 1. Pre-Defined Management Gateway Firewall Rules Name Sources Destinations Services Action Default Deny All Any Any Any Drop - Customer-defined firewall rules are processed in the order you specify and are always processed before pre-defined rules. These rules require either the source or destination to be a system-defined group, and the list of available ports and services is a limited one managed by VMware. When Sources is a system-defined group, Services must be Any. And because these rules must have an Allow action, rule order is generally unimportant.
Procedure
Example: Create a Management Gateway Firewall Rule
- Create a management inventory group that contains the on-premises ESXi hosts that you want to enable for vMotion to the SDDC.
- Create a management gateway rule with source ESXi and destination on-premises ESXi hosts.
- Create another management gateway rule with source on-premises ESXi hosts group and destination ESXi with a vMotion service.
What to do next
You can view Rule Hits Statistics and Flow Statistics for any rule other than the Default Deny All rule.
-
Click the gear icon to view or modify rule logging settings. Log entries are sent to the VMware VMware Aria Operations for Logs Service. See Using VMware Aria Operations for Logs in the VMware Cloud on AWS Operations Guide.
-
Click the graph icon to view Rule Hits and Flow statistics for the rule.
Table 2. Rule Hits Statistics Popularity Index Number of times the rule was triggered in the past 24 hours. Hit Count Number of times the rule was triggered since it was created. Table 3. Flow Statistics Packet Count Total packet flow through this rule. Byte Count Total byte flow through this rule.