A new SDDC includes a logical network (the management network) and an NSX Edge gateway that controls access to the network. To provide secure communications between this network and your on-premises management network, create virtual private networks (VPNs) in each location, and configure the management gateway to connect them.
You don't have to set up a VPN connection, but transferring virtual machine templates and disk images into your SDDC in the cloud is easier if you do.
Use the VMC Console to create a VPN in the SDDC management network to your on-premises management network, configure the management gateway with firewall rules, and specify DNS server addresses for the management network. Your networking team can configure the on-premises VPN using information you download form the SDDC.