Virtual Network Segment
This network design has the following features:
- Workspace ONE Access cluster nodes for cross-region SDDC solutions are deployed together on the same cross-region virtual network segment in Region A. This provides a consistent deployment model for management applications, and supports growth to a dual-region design.
-
All Workspace ONE Access components have routed access to the VLAN-backed management network through the NSX-T Data Center Tier-0 Gateway.
-
Routing to the VLAN-backed management network and other external networks is dynamic and is based on the Border Gateway Protocol (BGP).

As part of this design, use the application virtual network configuration to connect Workspace ONE Access with the other management solutions in the SDDC. The cross-region Workspace ONE Access cluster is connected to the cross-region virtual network segment, xreg-m01-seg01
, and use the load balancer on the NSX-T Tier-1 Gateway for high availability and balancing user access across the Workspace ONE Access cluster.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-COM-SEC-IAM-021 |
Place the Workspace ONE Access cluster nodes for cross-region SDDC solutions on the existing cross-region virtual network segment, |
Provides a consistent deployment model for management applications and potential to extend to a dual-region design. |
You must use an implementation in NSX-T Data Center to support this network configuration. |
IP Addressing
Allocate a statically assigned IP address and host name from the cross-region network segment to the cross-region Workspace ONE Access cluster virtual appliances.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-COM-SEC-IAM-022 |
Allocate statically assigned IP addresses and host names to the Workspace ONE Access nodes in the management domain. |
Using statically assigned IP addresses ensures stability across the SDDC and makes it simpler to maintain and easier to track. |
Requires precise IP address management. |
Name Resolution
The IP addresses of the cross-region Workspace ONE Access cluster nodes are associated with a fully qualified name whose suffix is set to the root domain, rainpole.io
.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-COM-SEC-IAM-023 |
Configure forward and reverse DNS records for each cross-region Workspace ONE Access appliance IP address and the load-balancer virtual IP address. |
Workspace ONE Access is accessible by using a fully qualified domain name instead of by using IP addresses only. |
You must provide DNS records for each Workspace ONE Access appliance and the load-balancer virtual IP address. |
Time Synchronization
Workspace ONE Access is dependent on time synchronization for all nodes.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-COM-SEC-IAM-024 |
Configure NTP for each Workspace ONE Access appliance. |
Workspace ONE Access depends on time synchronization for all nodes. |
All firewalls located between the Workspace ONE Access nodes and the NTP servers must allow NTP traffic. |
Load Balancing
A Workspace ONE Access cluster deployment requires a load balancer to manage connections to Workspace ONE Access services.
The design uses load balancing services provided by NSX-T Data Center in the management domain.
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
SDDC-COM-SEC-IAM-025 |
Add a small-size load balancer in NSX-T Data Center on a dedicated Tier-1 gateway in the management domain to load balance connections across the cross-region Workspace ONE Access cluster members. |
Required to deploy Workspace ONE Access as a cluster deployment type, enabling it to handle a greater load and obtain a higher level of availability for vRealize Automation and vRealize Operations, which also share this load balancer. |
You must use an implementation in NSX-T Data Center to support this network configuration. |
SDDC-COM-SEC-IAM-026 |
|
|
|
SDDC-COM-SEC-IAM-027 |
|
|
None |
SDDC-COM-SEC-IAM-028 |
|
|
None |
SDDC-COM-SEC-IAM-029 |
|
The cross-region Workspace ONE Access cluster requires cookie session persistence for the Workspace ONE Access UI. |
None |
SDDC-COM-SEC-IAM-030 |
|
|
None |
SDDC-COM-SEC-IAM-031 |
|
End-to-end SSL is required to support load balancing for the cross-region Workspace ONE Access cluster deployment type. |
|
SDDC-COM-SEC-IAM-032 |
Configure the NSX-T Data Center load-balancer virtual server,
|
HTTP header rewrites are required to support load balancing for the cross-region Workspace ONE Access cluster deployment type. |
None |
SDDC-COM-SEC-IAM-033 |
|
|
None |
SDDC-COM-SEC-IAM-034 |
|
Ensures that connections to non-secure HTTP are automatically redirected to HTTPS for the cross-region Workspace ONE Access cluster. |
None |