HCX Architecture Design
HCX Architecture Design
HCX Architecture Design
Solution Architecture
Date: 1/29/2018
Version 1.1
Table of Figures
Figure 1 VMware Cloud Foundation – Hybrid Cloud Services ........................ Error! Bookmark not defined.
Figure 2 Hybrid Cloud Services with single source .................................................................................. 12
Figure 3 Hybrid Cloud Services with multiple sources ............................................................................ 12
Figure 4 Source Hybrid Cloud Services ................................................................................................... 17
Figure 5 Source Cloud Gateway .............................................................................................................. 18
Figure 6 Source WAN Optimizer ............................................................................................................. 19
Figure 7 Source L2 Concentrator ............................................................................................................ 20
Figure 8 VIP Configuration for NSX Edge ................................................................................................ 25
Figure 9 Pool Configuration for NSX Edge............................................................................................... 25
Figure 10 Target - Hybrid Cloud Services Appliance ................................................................................ 26
Figure 11 Cloud Gateway Deployment ................................................................................................... 27
Figure 12 WAN Optimizer Deployment .................................................................................................. 28
Figure 13 L2 Concentrator Deployment .................................................................................................. 29
List of Tables
Table 1 NSX Edge Deployment ............................................................................................................... 24
Table 2 NSX Edge Anti-Affinity Rules ...................................................................................................... 24
2.3 Networking
The following networking features are built into the Cloud Gateway and the Layer 2 Concentrators.
2.3.3 Security
The Cloud Gateway offers Suite B-compliant AES-GCM with IKEv2, AES-NI offload, and flow-based
admission control. HCX also owns the source and destination encryption and decryption process, ensuring
consistent security and administration for hybrid workflows such as virtual machine migration and
network extension. Security policies defined and assigned to a virtual machine on-premises can be
migrated with the virtual machine into the IBM Cloud.
Note that policy migration is only available under the following conditions
The on-premises data center must be running NSX 6.2.2 or greater.
In vSphere, the security policy is a single NSX Section which can contain many rules.
One can name a Set of IP addresses or MAC addresses to participate in the policy. The name of
the MAC Set or IP Set cannot exceed 218 characters.
HCX owns the source and destination encryption and decryption processes, ensuring consistent
security and providing admission for hybrid workflows such as virtual machine migration and
network extension.
HCX creates an optimized, software-defined WAN to increase stretched network performance,
enabling performance approaching LAN speed.
HCX also enables bidirectional workload and VMware NSX security policy migration to IBM Cloud
Networking services.
HCX integrates with vSphere vCenter and is managed from the vSphere Web Client.
For more information on the IBM Cloud for VMware Solutions architecture, please visit:
https://www.ibm.com/devops/method/content/architecture/virtCloudFoundationPlatform
7.2 On Premises
Before installing HCX, verify that your environment can support the tasks you want to accomplish.
The on-premises environment must support the following tasks before HCX can be installed.
Virtual Center with vSphere 5.5 Update 3 or 6.0 Update 2.
vMotion and policy migration features require NSX version 6.2.2 or higher.
A vSphere service account with the Administrator vCenter Server system role assigned to it. See
https://pubs.vmware.com/vsphere-
60/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-93B962A7-93FA-4E96-B68F-
AE66D3D6C663.html.
In the vCenter, enough disk space for the HCX appliances to be installed.
Sufficient IP addresses for the on-premises VMs provisioned during the installation. See IP
Address Requirements for the minimum requirements for each configuration.
Ports and firewalls opened as required as documented in Port Access Requirements.
If the single sign-on (SSO) server is remote, the URL of the vCenter, external SSO Server, or
Platform Services Controller (PSC) that runs the external lookup service must be identified. When
the HCX Manager is registered with the vCenter, this URL must be supplied.
If a vCenter does not have its own internal instance of the lookup service, it might be for one of
the following reasons:
o vCenter 6.0u2 is running an external Platform Services Controller.
o The vCenter is in linked mode (where the secondary vCenter uses the SSO service from
the primary vCenter or an external SSO service).
8.2 Procedure
1. Log in to My VMware and download the Hybrid Cloud Services OVA file from the product
download page.
2. Open a browser and log in to the vSphere® Web Client. (This task cannot be performed from the
vSphere Client.) View the Home tab.
3. In the Inventories Trees list, click Host and Clusters.
4. Expand the hierarchy to show the data centers.
5. Right-click the target data center and select Deploy OVF Template from the context menu (it
might take a few seconds for the Deploy OVF Template menu item to appear). The Deploy OVF
template wizard opens.
o DNS.
o Click DNS, and enter the IP addresses for DNS servers (separated by spaces) and the
domain search list. The values in the following screenshot are samples:
o DS configuration
8. Review the vService bindings page. Click Next to continue, or to change previous screens, click
Back.
9. On the “Ready to complete” page:
o Check the “Power on after deployment” check box.
o Review the Hybrid Cloud Services settings, and click Finish. It might take several minutes
for the Hybrid Cloud Services appliance to power on.
o To check the status, go to the vSphere Web Client home page, and in the Home tab, go
to Inventories and click Hosts and Clusters. Expand the data center hierarchy, and click
the Hybrid Cloud Services service virtual machine to display a summary in the center
pane.
o The Summary tab, the console reads “Powered On” and the Play button is green.
10. The HCX Manager is powered on and ready to be registered with the vCenter.
9.1 Prerequisites
The Hybrid Cloud Services virtual appliance must be powered on before it can be registered.
9.2 Procedure
1. Log in to Hybrid Cloud Services service virtual appliance.
2. Click the Manage Settings tile.
a. In the left pane, under Configure Systems, select vCenter.
b. Click the Add vCenter button on the upper right.
c. Enter the IP address of the vCenter Server in the form https:\\<vCenter-host-name> or
https:\\<vCenter-IP-address>.
d. For example, https:\\My-vCenter or https:\\ 10.108.26.211.
e. Enter the vCenter Server user name and password. The account used must have the
vCenter Administrator role.
f. Click OK. Do not restart when the “You need to restart the app" message is displayed.
Proceed to next step.
5. To finalize the registration, log out of the vSphere® Web Client. Log back in to verify that the
screen update has occurred.
Notice the existing Hybrid Cloud icon and the Hybrid Cloud Services menu item on the left, as indicated in
red the following screenshot. The Hybrid Cloud Services registration updates these labels as shown in the
following screenshot. In the inventory, Hybrid Cloud Services becomes Hybrid Cloud Services, and the icon
label also becomes Hybrid Cloud Services.
o Using the vSphere Web Client, the bidirectional migration wizard is accessible from the
Hybrid Cloud Services Getting Started tab. This wizard handles all migration details,
including multiple virtual machines.
Check The Virtual Machine Before Migration