You deploy a load balancer for use by the cross-region Workspace ONE Access, vRealize Operations Manager, and vRealize Automation components, which are connected to the Mgmt-xRegion01-VXLAN
application virtual network.
Procedure
- In a Web browser, log in to vCenter Server by using the vSphere Client.
Setting Value URL https://sfo01m01vc01.sfo01.rainpole.local/ui User name [email protected] Password vsphere_admin_password - In the Networking and security inventory, click NSX Edges.
- From the NSX Manager drop-down menu, select 172.16.11.65.
- Click Add and select Edge services gateway.
- On the Basic details page of the New edge services gateway wizard, enter these values and click Next.
Setting
Value
Name
sfo01m01lb01
Hostname
sfo01m01lb01.sfo01.rainpole.local
Tenant
-
Description
Load Balancer for vRealize Suite
Deploy NSX Edge
Selected
Enable high availability
Selected
- On the Settings page, enter these values and click Next.
Setting
Value
User name
admin
Password
edge_admin_password
Enable SSH access
Selected
Enable FIPS mode
Deselected
Enable auto rule generation
Selected
Edge control level logging
Info
- On the Deployment configuration page, perform the following configuration steps, and click Next.
- From the Datacenter drop-down menu, select sfo01-m01dc.
- Under Appliance size, select Large.
- Click Add edge appliance VM, enter these values, and click OK.
Setting
Value
Resource pool
sfo01-m01-mgmt01
Datastore
sfo01-m01-vsan01
Folder
sfo01-m01fd-nsx
Resource reservation
System Managed
- Repeat Step 7.c to create a second appliance.
- On the Configure interfaces page, configure the OneArmLB interface.
- Click Add.
- On Basic tab, enter these values.
Setting
Value
Name
OneArmLB
Type
Internal
Connected to
Mgmt-xRegion01-VXLAN
Connectivity status
Connected
- On Basic tab, under Configure subnets, click Add and enter these values.
Setting
Value
Primary IP address
192.168.11.2
Subnet prefix length
24
- Click the Advanced tab and enter these values.
Setting
Value
MAC address
-
MTU
9000
Proxy ARP
Disabled
Send ICMP redirect
Selected
Reverse path filter
Enable Strict
Fence parameters
-
- Click OK and click Next.
- On the Default gateway page, turn off the Configure default gateway toggle to disable the default gateway and click Next.
- On the Firewall default policy page, configure these settings and click Next.
Setting
Value
Firewall default policy
Enabled
Default traffic policy
Accept
Logging
Disabled
- On the High availability page, configure these settings and click Next.
Setting
Value
vNIC
any
Declare dead time
15
Management IPS
-
HA logging
Disabled
- On the Review page, review the configuration settings that you entered and click Finish.
- Enable HA logging.
- On the NSX Edges page, click the ID of the sfo01m01lb01 edge services gateway to open its network settings.
- Click the Configure tab and click High availability.
- Click Edit.
- Turn on the Logging toggle and click Save.
- Configure the default gateway.
- On the NSX Edges page, click the ID of the sfo01m01lb01 edge services gateway to open its network settings.
- Click the Routing tab and click Global configuration.
- Next to Default Gateway, click Edit.
- In the Gateway IP text box, enter 192.168.11.1 and click Save.
- Click Publish changes.
- Enable the Load Balancer and Acceleration mode.
- On the NSX Edges page, click the ID of the sfo01m01lb01 edge services gateway to open its network settings.
- Click the Load balancer tab, click Global configuration.
- Click Edit and turn on the Load balancer and Acceleration toggles.
- Click Save.