You can configure network isolation for your VMware Cloud on AWS deployment needs by specifying and using on-demand network settings in a network profile.

You can specify an isolated network by using a security group or by using on-demand network settings. In this example, you configure network isolation by specifying on-demand network settings in the network profile. Later, you access the network in a cloud template and use the cloud template in a VMware Cloud on AWS deployment.

Unless otherwise indicated, the step values that you enter in this procedure are for this example workflow only.



  1. Open the network profile that you used in the basic VMware Cloud on AWS workflow, for example vmc-network1. See Configure network and storage profiles for VMware Cloud on AWS deployments in vRealize Automation Cloud.
  2. You do not need to make any selections on the Networks tab.
  3. Click the Network Policies tab.
  4. Select the Create an on-demand network option and select the default cgw network domain. Specify an appropriate CIDR and subnet size.
  5. Click Save.

    When you use this network profile, machines are deployed to a network in the default network domain. The network is isolated from other networks by using private or outbound network access.

What to do next

Configure a network component in your cloud template. See Define a network component in a cloud template to support network isolation for VMware Cloud on AWS in vRealize Automation Cloud