To prepare a new SDDC to run compliance-audited workloads, you must create a firewall rule that allows you to connect directly to the SDDC's local NSX Manager, then disable the VMware Cloud Console Networking & Security tab and use the local NSX Manager to manage your SDDC networks.
Access controls on the VMware Cloud Console Networking & Security tab are not appropriate for a compliance-hardened SDDC. Any access to an SDDC using the Networking & Security tab renders the SDDC non-compliant. To maintain compliance, you must manage your SDDC networks using only the local NSX Manager, which has an authentication framework that meets compliance hardening requirements. Access to the Networking & Security tab must be disabled before you begin a compliance audit, and must remain disabled the duration of the audited period.
Before you disable access to the Networking & Security tab, you'll use it to create a VPN connection to your on-premises data center and a management gateway firewall rule that allows you to access the local NSX Manager over that VPN. After you verify that you can access NSX Manager, you can proceed to prepare the SDDC for compliance hardening by disabling access to the Networking & Security tab. If you need to re-enable access to the Networking & Security tab, contact VMware Support.
Prerequisites
- You must have a VPN connection to the SDDC. See Configure a VPN Connection Between Your SDDC and On-Premises Data Center in the VMware Cloud on AWS Networking and Security guide. After you have disabled Networking & Security tab access, a connection to the local NSX Manager over a VPN is the only way to manage your SDDC network. To ensure that you can reach the local NSX Manager in the event of a network failure, we recommend configuring a redundant connection such as AWS Direct Connect to with a route-based VPN as the backup, as described in Configure Direct Connect to a Private Virtual Interface for SDDC Management and Compute Network Traffic in the VMware Cloud on AWS Networking and Security guide.
- Compliance hardening must be enabled in the SDDC. VMware Cloud on AWS does not enable compliance hardening by default. Contact your account team for more information. Compliance hardening can be configured in SDDCs at version 1.14 and later created in an AWS region that provides the appropriate support, as shown in Choosing a Region.
Procedure
What to do next
After you have disabled Networking & Security tab access, you must use the local NSX Manager to manage your SDDC network. You can navigate the NSX Manager UI in much the same way as you navigate the Networking & Security tab. See NSX Manager in the NSX Administration Guide for information about how to use NSX Manager.
To conform with PCI compliance requirement 8.2.4 ("Change user passwords/passphrases at least once every 90 days"), you must use the NSX manager REST API, as documented in VMware Knowledge Base article 83551.
If you need to re-enable access to the Networking & Security tab, contact VMware Support.