{"id":22451974,"url":"https://github.com/odennav/vmware-vsphere-sddc-private-cloud","last_synced_at":"2025-08-02T00:32:32.292Z","repository":{"id":236382520,"uuid":"792251875","full_name":"odennav/vmware-vsphere-sddc-private-cloud","owner":"odennav","description":"Implement software-defined data center architecture  with VMware for private cloud hosting solutions","archived":false,"fork":false,"pushed_at":"2024-06-20T13:21:23.000Z","size":289,"stargazers_count":2,"open_issues_count":0,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-06-21T05:35:08.820Z","etag":null,"topics":["drs","nsx-t","packer","sddc","sdrs","terraform","ubuntu-server","vcsa","virtual-machine","vmfs","vmware","vmware-vcenter","vmware-vsphere","vmware-vsphere-esxi","vspher-ha","vsphere-provider"],"latest_commit_sha":null,"homepage":"","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/odennav.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-04-26T09:31:59.000Z","updated_at":"2024-06-20T13:21:26.000Z","dependencies_parsed_at":"2024-06-21T04:48:59.477Z","dependency_job_id":null,"html_url":"https://github.com/odennav/vmware-vsphere-sddc-private-cloud","commit_stats":null,"previous_names":["odennav/vmware-private-cloud","odennav/vmware-sddc-private-cloud","odennav/vmware-sddc-private-cloud-lab"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/odennav%2Fvmware-vsphere-sddc-private-cloud","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/odennav%2Fvmware-vsphere-sddc-private-cloud/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/odennav%2Fvmware-vsphere-sddc-private-cloud/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/odennav%2Fvmware-vsphere-sddc-private-cloud/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/odennav","download_url":"https://codeload.github.com/odennav/vmware-vsphere-sddc-private-cloud/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":228419606,"owners_count":17916772,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["drs","nsx-t","packer","sddc","sdrs","terraform","ubuntu-server","vcsa","virtual-machine","vmfs","vmware","vmware-vcenter","vmware-vsphere","vmware-vsphere-esxi","vspher-ha","vsphere-provider"],"created_at":"2024-12-06T06:09:25.274Z","updated_at":"2024-12-06T06:09:26.128Z","avatar_url":"https://github.com/odennav.png","language":"HCL","funding_links":[],"categories":[],"sub_categories":[],"readme":"# VMware vSphere SDDC Private Cloud Lab\n\nSDDC (Software Defined Data Center) is an architecture that allows for any application's infrastructure to be fully automated and always available.\n\nIt's a special kind of data storage and computing facility in which basic components such as CPU, storage, networking, security are all virtualized and delivered as services via smart software.\n\n**Main Components of VMware SDDC**\n\n- Server Virtualization with VMware's vSphere\n\n- Resource Sharing with VMware vSphere HA and Storage DRS \n\n- Network Virtualization with VMware NSX\n\n![](https://github.com/odennav/vmware-sddc-private-cloud/blob/main/docs/datacenter.PNG)\n\n\nThe objective of this project is to utilize VMware infrastructure for private cloud hosting solutions in your home lab. \nYou'll also find relevant guides on alternative large-scale VMware deployments.\n\nThe two core components of vSphere are `ESXi` and `vCenter Server`.\n\nESXi is the virtualization platform to make virtual machines and virtual appliances.\n\nThe vCenter server appliance is a preconfigured virtual machine optimized for running vCenter server and the vCenter server components.\nvCenter server is a service that lets you pool and manage the resources of multiple hosts.\n\n\n-----\n\n# Getting Started\n\nTo ensure a successful VMware deployment, note the workflow required:\n\n1. Prepare for ESXi Installation.\n\n2. Install ESXi on Hosts.\n\n3. Configure ESXi on Hosts.\n\n4. Prepare for vCenter Installation.\n\n5. Deploy vCenter Server Appliance.\n\n6. Manage vCenter Server Services\n\n7. vSphere Distributed Switch Setup\n\n8. NFS Storage Server Setup\n\n9. Compute Cluster \u0026 Resource Sharing Solutions(vHA, DRS, SDRS)\n\n10. Provision Windows and Linux VMs to vSphere Compute Cluster\n\n11. NSX-T Setup and Configuration\n\n\n## Prepare for ESXi Installation\n\nTwo important steps to implement for preparation are:\n\n1. **Download the ESXi Installer**\n\nCreate a [VMware Customer Connect](https://customerconnect.vmware.com/home) account and download `ESXi VMware-VMvisor-Installer`.\n\n2. **Choose option for installing ESXi**\n\nESXi installations are designed to accommodate a range of deployment sizes.  \nThe different options available for accessing the installation media and booting the installer:\n\n- Interactive ESXi installation\n\n- [Scripted ESXi installation](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-00224A32-C5C5-4713-969A-C50FF4DED8F8.html)\n\n- [vSphere Auto Deploy ESXi installation](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-DC5D6EA2-2F17-4CB0-A0DB-C767F2BE2FBA.html)\n\nCheck this guide [here](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-6E6BCACF-33CA-4466-90B7-73CCA37BB5E1.html)\nto thoroughly understand the different ways of deployment.\n\nWe'll implement `Interactive ESXi installation` with `VMware Workstation` for small deployment of 3 hosts in this project.\n\n\n3. **ESXi Requirements**\n\nTo install or upgrade ESXi, your system must meet specific hardware and software requirements.\n\n\n### ESXi Hardware Requirements\n\nTo install or upgrade ESXi 7/8, your hardware and system resources must meet the following\nrequirements:\n\n- Requires a host with at least two CPU cores.\n\n- Supports a broad range of multi-core of 64-bit x86 processors.\n\n- Requires the NX/XD bit to be enabled for the CPU in the BIOS.\n\n- Minimum of 8 GB of physical RAM. Provide at least 8 GB of RAM to run\nvirtual machines in typical production environments.\n\n- For 64-bit virtual machines, support for hardware virtualization (Intel VT-x or AMD RVI) must be enabled on x64 CPUs.\n\n- Recommended size for VMware ESXi 7/8 is 142GB minimum. VMFS datastore is created automatically to store virtual machine data.\n  Local disk of 128 GB or larger for optimal support of ESX-OSData. \n  The disk contains the boot partition, ESX-OSData volume and a VMFS datastore.\n\n- vSphere 7/8 supports booting ESXi hosts from the Unified Extensible Firmware Interface (UEFI). With UEFI, we can boot systems from hard drives, CD-ROM drives, or USB media.\n \n\nFor a complete list of supported processors and server platforms, see the VMware compatibility guide at http://www.vmware.com/resources/compatibility.\n\n-----\n\n## Install ESXi on Hosts\n\n### Creating ESXi virtual machine in VMware Workstation\n\n1. Download `VMware Workstation Player 17` [here](https://www.vmware.com/products/workstation-player/workstation-player-evaluation.html)\n\n2. Open your VMware Workstation, click on `Create a New Virtual Machine`\n\n3. Select `Installer disc image file (iso):` and click `Browse...` to find the VMware ESXi iso in your directory. Click `Next`.\n\n4. Name the virtual machine as `ESXi-1` and select `Location` you want the ESXi installed.   Click `Next`.\n\n5. Select `store virtual disk as a single file` and specify disk capacity of 180GB. Click `Next`.\n\n6. Click on `Customize Hardware`, select `Memory` size of 8GB and 4 Processor cores as minimum.\n   \n   Select `Virtualize Intel VT-x/EPT or AMD-V/RVI`\n   \n   Use `Bridged` or `NAT` network connection.\n\n7. Select `Power on this virtual machine after creation`.\n   \n   Click `Finish`.\n\n\n### Installing ESXi in VMware Workstation\n\nOnce your virtual machine is up and running, follow the next steps to finish the ESXi installation on your VMware Workstation.\n\n1. When the `Welcome to the VMware ESXi installation` pops up, press `Enter` to continue.\n\n2. Accept the `End User License Agreement` by hitting the `F11` key.\n\n3. Select the `Local` disk where ESXi will be installed and hit Enter.\n\n4. Choose your `keyboard` layout and hit Enter.\n\n5. Enter your `Root password`, confirm it and securely store it. Press `Enter`.\n\n6. Confirm the installation by pressing `F11`.\n\n7. Once complete, you must remove the installation media. You can remove it by clicking `I Finished Installing` at the bottom right side of the VMware Workstation window.\n\nAfter removing your installation media, go back to the virtual machine installation screen and hit `Enter` to reboot. The VM will shutdown and reboot.\n\n-----\n\n## Configure ESXi on Hosts\n\nAfter the reboot is complete and the ESXi virtual machine is running, note the IP address of the ESXi host server.\nDynamic host configuration protocol (DHCP) assigns the IP address the VMware ESXi server uses when it is initialized. \n\nYou can use the IP address assigned from DHCP, or as an alternative, you can set up a static IP address of your choice by following these steps.\n\n1. In the running ESXi virtual machine, press `F2`.\n\n2. Enter your `Login Name` as root, type your `Password` and hit Enter.\n\n3. Use the arrow keys to move and select `Configure Management Network` then press Enter.\n\n4. Select `IPv4 Configuration` and hit Enter.\n\n5. Using the arrow keys, highlight `Set static IPv4 address and network configuration` and press the Space key to select it.\n\n6. Enter your static `IPv4 Address` and `Subnet Mask`, and hit Enter. Note `Default Gateway` will have the same IPv4 address as `Primary DNS Server`. Please note you'll have to confirm the static IPv4 address is available, you can ping it and confirm it's `Unreachable` at this moment.\n\n7. Navigate to `DNS Configuration` and press Enter.\n\n8. Next, select `Use the following DNS server address and hostname` and press the Space key.\n\n9. Insert your `DNS server` IPv4 address, change `Hostname` to `esxi01` and hit Enter.\n\n10. Use the ESC key to go one step back and afterward hit the Y`` key to save changes and restart network management.\n\n11. Go back to `Test Management Network` to ping your default gateway and DNS servers. \n\n12. Confirm the `Ping Address` and press Enter. Note hostname resolved to 'localhost.localdomain`.\n\n13. To log out, hit the ESC key and press the `F12` key.\n\n14. Finally, run the ESXi virtual machine from the VMware Workstation. After the server is up and running, navigate in your browser to the ESXi server's IPv4 address and you can start managing your VMware ESXi vSphere server.\n\nWe're installing and configuring three ESXi hosts, hence you'll have to repeat the `Interactive Installation Step` twice to get total of three ESXi hosts powered on and running.\n\nAlso note when you're configuring subsequent ESXi, remember to change the `Hostname` in `DNS Configuration` section. For example second and third ESXi will be named `esxi02` and `esxi03` respectively.\n\nPlease note the hardware specifications for `esxi02` will be different and bigger than other hosts because we'll deploy the vcsa on it.\n\n-----\n\n## Deploy vCenter Server Appliance\n\nYou can deploy the vCenter Server appliance on an ESXi host 7/8, or on a vCenter Server instance 7/8. \n\nWhen you use Fully Qualified Domain Names, verify that the client machine from which you are deploying the appliance and the network on which you are deploying the appliance use the same DNS server.\n\nThere are two methods of deploying VCSA\n\n- Deploy a vCenter Server Appliance by Using the CLI\n- Deploy a vCenter Server Appliance by Using the GUI\n\nWe'll implement the CLI method.\n \n\n### Requirements for Deploying the vCenter Server Appliance\n\nOur system must meet specific software and hardware requirements.\n\n**Prerequisistes**\n\n1. Download the vCenter Installer from [Customer Connect account](https://my.vmware.com/web/vmware/)\n\n2. Hardware requirements of ESXi Host:\n   \n   This depends on the hardware specifications of host esxi02.\n   - We'll use `Tiny Environment`(for up to 10 hosts or 100 virtual machines)\n   - 18GB Memory (14GB minimum)\n   - Default storage size of 579GB minimum\n\n   Software requirements:\n\n   - Assign a fixed IP address and an FQDN that is resolvable by a DNS server so that clients can reliably access the service.\n   - If you use DHCP instead of a static IP address for the vCenter Server appliance, verify that the appliance name is updated in the domain name service (DNS).\n   - If you manage network components from outside a firewall, you might be required to reconfigure the firewall to allow access on the appropriate ports. For the list of all supported ports and protocols in vSphere, see the VMware Ports and Protocols [Tool](https://ports.vmware.com)\n\n\n**vSphere Client Software Requirements**\n\nUse of the vSphere Client requires supported web browsers:\n- Google Chrome 89 or later\n- Mozilla Firefox 80 or later\n- Microsoft Edge 90 or later\n\nSupported Guest Operating Systems\n- Windows 32-bit and 64-bit\n- Mac OS\n\n\n**Running the vCenter Server Appliance Installer**\n\n1. Navigate to your root directory and extract contents of the `VMware-VCSA` iso file downloaded from VMware Customer Connect account.\n   In my case, the root directory is C:\\ directory on my Windows local machine.\n\n2. To find the command line tool(Installer), navigate to the `vcsa-cli-installer` subdirectory in the extracted folder of downloaded `VMware-VCSA` iso file.\n\n- If you are running the deployment on Windows OS, executable is located at `vcsa-cli-installer\\win32\\vcsa-deploy.exe` \n- If you are running the deployment on Linux OS, executable is located at `vcsa-cli-installer/lin64/vcsa-deploy` \n- If you are running the deployment on Mac OS, executable is located at `vcsa-cli-installer/mac/vcsa-deploy`\n\n\n3. Use the `vcsa-cli-installer\\templates\\install\\embedded_vCSA_on_ESXi.json` template to deploy single instance of VCSA on our second ESXi host.\n\nEdit the template file for your specification. View sample below:\n\n```yaml\n{\n    \"__version\": \"2.13.0\",\n    \"__comments\": \"Template to deploy a vCenter Server Appliance with an embedded Platform Services Controller on an ESXi host.\",\n    \"new_vcsa\": {\n        \"esxi\": {\n            \"hostname\": \"esxi02.localdomain\",\n            \"username\": \"root\",\n            \"password\": \"**********\",\n            \"deployment_network\": \"VM Network\",\n            \"datastore\": \"datastore2\"\n        },\n        \"appliance\": {\n            \"__comments\": [\n                \"You must provide the 'deployment_option' key with a value, which will affect the vCenter Server Appliance's configuration parameters, such as the vCenter Server Appliance's number of vCPUs, the memory size, the storage size, and the maximum numbers of ESXi hosts and VMs which can be managed. For a list of acceptable values, run the supported deployment sizes help, i.e. vcsa-deploy --supported-deployment-sizes\"\n            ],\n            \"thin_disk_mode\": true,\n            \"deployment_option\": \"tiny\",\n            \"name\": \"vCenter-Server-Appliance\"\n        },\n        \"network\": {\n            \"ip_family\": \"ipv4\",\n            \"mode\": \"static\",\n            \"system_name\": \"\",\n            \"ip\": \"\u003cStatic IP address for the appliance.\u003e\",\n            \"prefix\": \"24\",\n            \"gateway\": \"\u003cGateway IP address.\u003e\",\n            \"dns_servers\": [\n                \"\u003cDNS Server IP address.\u003e\"\n            ]\n        },\n        \"os\": {\n            \"password\": \"**********\",\n            \"ntp_servers\": \"time.nist.gov\",\n            \"ssh_enable\": true\n        },\n        \"sso\": {\n            \"password\": \"**********\",\n            \"domain_name\": \"odennav.local\"\n        }\n    },\n    \"ceip\": {\n        \"description\": {\n            \"__comments\": [\n                \"++++VMware Customer Experience Improvement Program (CEIP)++++\",\n                \"VMware's Customer Experience Improvement Program (CEIP) \",\n                \"provides VMware with information that enables VMware to \",\n                \"improve its products and services, to fix problems, \",\n                \"and to advise you on how best to deploy and use our \",\n                \"products. As part of CEIP, VMware collects technical \",\n                \"information about your organization's use of VMware \",\n                \"products and services on a regular basis in association \",\n                \"with your organization's VMware license key(s). This \",\n                \"information does not personally identify any individual. \",\n                \"\",\n                \"Additional information regarding the data collected \",\n                \"through CEIP and the purposes for which it is used by \",\n                \"VMware is set forth in the Trust \u0026 Assurance Center at \",\n                \"http://www.vmware.com/trustvmware/ceip.html . If you \",\n                \"prefer not to participate in VMware's CEIP for this \",\n                \"product, you should disable CEIP by setting \",\n                \"'ceip_enabled': false. You may join or leave VMware's \",\n                \"CEIP for this product at any time. Please confirm your \",\n                \"acknowledgement by passing in the parameter \",\n                \"--acknowledge-ceip in the command line.\",\n                \"++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++\"\n            ]\n        },\n        \"settings\": {\n            \"ceip_enabled\": false\n        }\n    }\n}\n\n```\n\n\n4. Run a pre-deployment check without deploying the appliance to verify that you prepared the deployment template correctly.\n\n   ```console\n   cd C:\\VMware-VCSA-all-8.0.2\\vcsa-cli-installer\\win32\n   vcsa-deploy install --accept-eula --precheck-only C:\\VMware-VCSA-all-8.0.2\\vcsa-cli-installer\\templates\\install\\embedded_vCSA_on_ESXi.json\n   ```\n   Press `1` to accept SHA-1 thumbprint of the certificate.\n\n   View pre-check task completed.\n\n\n5. Perform template verification\n\n   ```console\n   vcsa-deploy install --accept-eula --verify-template-only C:\\VMware-VCSA-all-8.0.2\\vcsa-cli-installer\\templates\\install\\embedded_vCSA_on_ESXi.json\n   ```\n   View template-validation task completed.\n\n6. Create directory to store output of files that the installer generates\n   ```console\n   mkdir C:\\VCSA-Logs\n   ```\n\n7. Run the deployment command\n\n   ```console\n   vcsa-deploy install --accept-eula  --log-dir=C:\\VCSA-Logs C:\\VMware-VCSA-all-8.0.2\\vcsa-cli-installer\\templates\\install\\embedded_vCSA_on_ESXi.json\n   ```\n\n\n### Configure System Logging.\n\nWe'll use the vSphere Client to configure the syslog service globally and edit various advanced settings.\n\nThe syslog service receives, categorizes, and stores log messages for analyses that help you take preventive action in your environment.\n\n**Procedure**\n\n1. Browse to the ESXi host in the vSphere Client inventory.\n2. Click `Configure`.\n3. Under `System`, click `Advanced System Settings`.\n4. Click `Edit`.\n5. Filter for `syslog`.\n6. To set up logging globally and configure various advanced settings, see [ESXi Syslog Options](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-8981F5FA-BB2A-47FB-A59A-7FC5C523CFDE.html#GUID-8981F5FA-BB2A-47FB-A59A-7FC5C523CFDE).\n7. (Optional) To overwrite the default log size and log rotation for any of the logs:\n   - Click the name of the log that you want to customize.\n   - Enter the number of rotations and the log size you want.\n8. Click `OK`.\n\nSyslog parameter settings defined by using the vSphere Client or VMware Host Client are effective immediately.\n\n-----\n\n## Manage vCenter Server Services\n\n**Enable Maintenance Mode Operations**\n\nWorkload Control Plane(wcp) service is needed for maintenance mode operations.\n\nImplement the following steps:\n\n1. Generate SSH key pair and save public key as `~/.ssh/id_rsa.pub`\n   \n   *This key will also be used for terraform null provisioner*\n\n   ```bash\n   ssh-keygen -t rsa -b 4096\n   ```\n\n2. Log in as root through an SSH or console session on the vCenter Server Appliance.\n\n3. List the vCenter Server Appliance services\n   ```bash\n   service-control --list\n   ```\n\n4. Check service staus of `wcp`\n\n   ```bash\n   service-control --status wcp\n   ```\n\n5. Create a backup of /etc/vmware/wcp/wcpsvc.yaml \n\n   ```bash\n   cp /etc/vmware/wcp/wcpsvc.yaml /etc/vmware/wcp/wcpsvc.yaml.bak\n   ```\n\n6. Open the `wcpsvc.yaml` file and confirm the value of `rhttpproxy_port` is `443` \n\n\n7. Start service staus of `wcp`\n   If its stopped, service needs to be started.\n\n   ```bash\n   service-control --start wcp\n   ```\n\n\n**Enable Cloning of Virtual Machines**\n\nThe  Policy Based Management(PBM) service is required for cloning a virtual machine or deploying a virtual machine from a template.\n\n1. Check service staus of `vmware-sps`\n\n   ```bash\n   service-control --status vmware-sps\n   ```\n\n2. Start the `vmware-sps` service\n\n   ```bash\n   service-control --start vmware-sps\n   ```\n\n3. Restart the `vmware-sps` service\n\n   ```bash\n   service-control --restart vmware-sps\n   ```\n\n-----\n\n## vSphere Distributed Switch Setup\n\nThis switch is required to handle the networking configuration for all ESXi hosts.\n\nWe'll implement the following:\n- Create a vSphere Distributed Switch\n- Create Distributed Port Groups\n- Add Hosts to the vSwitch.\n- Create VMkernel Adapters\n\n\n### Create a vSphere Distributed Switch\n\n**Procedure**\n\n- Navigate to a data center in the vSphere Client\n\n- Right-click the data center and select **`Distributed Switch`** \u003e **`New Distributed Switch`**.\n\nEnter `Odennav-DSwitch` as name for the new distributed switch.\n\nEnter version `8.0` for the distributed switch.\n\nIn `Configure Settings`, enter value of `2` as number of uplinks ports.\n\nReview the settings and Click `Finish`.\n\nRight-click the distributed switch just created and select **`Settings`** \u003e **`Edit settings`**.\n\nOn the Advanced tab, enter a value of more than `1700` as the MTU value and click `OK`.\nThe MTU size must be 1700 or greater on any network that carries overlay traffic.\n\n\n### Create Distributed Port Groups\n\nWe'll create port groups for each of the following ESXi services below:\nNote their VLAN IDs\n\n- vMotion (VLAN-ID=5)\n- Provisioning (VLAN-ID=6)\n- Fault Tolerance (VLAN-ID=7)\n- vSAN (VLAN-ID=8)\n- Management (VLAN-ID=10)\n- NSX Tunnel Endpoints (VLAN-ID=20)\n- NSX Edge Uplink (VLAN-ID=50)\n\n**Procedure to Create vMotion Port Group**\n\n- Navigate to a data center in the vSphere Client\n\n- Right-click the distributed switch and select **`Distributed Port Group`** \u003e **`New Distributed Port Group`**.\n\n- Create a port group for the vMotion. Name it `DPortGroup-vMotion`.\n\n- Set `VLAN Type` as VLAN Trunking.\n\n- Accept the default VLAN trunk range `(0-4094)`. Set `VLAN ID` to **`5`**.\n\n- Click `Next`, then click `Finish`.\n\n- Right-click the distributed switch, **`Odennav-DSwitch`**, select **`Distributed Port Group`** \u003e **`Manage Distributed Port Groups`**.\n\n- Select `Teaming and failover` and click `Next`.\n\n- Configure active and standby uplinks. Set active uplink as `Uplink1` and standby uplink is `Uplink2`.\n\n- Click `OK` to complete the configuration of the port group.\n\nRepeat steps above to create port groups for other ESXi services listed above.\n\nAlso configure the default port group to handle `VM traffic`.\n\n\n\n### Add Hosts to the vSwitch\n\nWe'll connect the physical NICs, VMkernel adapters and virtual machine network adapters of the hosts to the distributed switch.\n\n**Procedure**\n\n- In the vSphere Client, navigate to **`Networking`** tab and select the distributed switch.\n\n- From the `Actions` menu, select `Add and Manage Hosts`.\n\n- On the `Select task` page, select `Add hosts`, and click `Next`.\n\n- On the `Select hosts` page, click `New hosts`, select the hosts in your data center, click `OK`, and then click `Next`.\n\nOn the `Manage physical adapters` page, we'll configure physical NICs on the distributed switch.\n\n- From the `On other switches/unclaimed` list, select a physical NIC.\n\n- Click `Assign uplink`.\n\n- Select an uplink. Assign `Uplink 1` to `vmnic0` and `Uplink 2` to `vmnic1`\n\n- To assign the uplink to all the hosts in the cluster, select **`Apply this uplink assignment to the rest of the hosts`**.\n\n- Click `OK`, then `Next`\n\nOn the `Manage VMkernel adapters` page, configure VMkernel adapters.\n\n- Select a VMkernel adapter and click `Assign port group`.\n\n- Select the `DPortGroup-vMotion` distributed port group.\n\nTo apply the port group to all hosts in the cluster, select **`Apply this port group assignment to the rest of the hosts`**.\n\nClick `OK`and save this configuration.\n\n\n\n### Create VMkernel Adapters\n\nSetup networking TCP/IP stack for the vMotion ESXi service\n\n**Procedure**\n\n- In the vSphere Client, select esxi01 host.\n\n- Under `Manage`, select `Networking` and then select `VMkernel adapters`.\n\n- Click `Add host networking`.\n\n- On the `Select connection type` page, select `VMkernel Network Adapter` and click `Next`.\n\n- On the `Select target device` page, select the created port-group, **`DPortGroup-vMotion`** associatd with **`Odennav-DSwitch`**\n\n- On the `Port` properties, enable **`vMotion`** Traffic and select Next.\n\n- Configure network settings for the vMotion VMkernel interface, use a unique IP address for host's vMotion interface. and click `Next`.\n  Note: it is not recommended to override the default gateway.\n\n- Review the settings and click `Finish`.\n\n\n-----\n\n## NFS Storage Server Setup\n\n### Create NFS virtual machine in VMware Workstation\n\n1. Open your VMware Workstation, click on `Create a New Virtual Machine`\n\n2. Select Installer disc image file (iso): and click Browse... to find the `CentOS 8` Server iso in your directory.\n   Click Next.\n\n3. Name the virtual machine as `NFS-Server-1` and select Location you want the NFS server installed.\n   Click Next.\n\n4. Select `store virtual disk as a single file` and specify disk capacity of 200GB. Click Next.\n\n5. Click on `Customize Hardware`, then select `Memory` size of 8GB and 4 Processor cores as minimum.\n\n   Select `Virtualize Intel VT-x/EPT or AMD-V/RVI`\n\n6. Use `Bridged` or  `NAT` network connection. For `Bridged` connection, ensure DHCP is properly configured on your router.\n\n7. Select `Power on this virtual machine after creation`.\n\n   Click `Finish`.\n\n### Install CentOS in Virtual Machine\n\n   Once your virtual machine is up and running, follow the next steps to finish the CentOS installation on your VMware Workstation.\n\n1. Set correct `DATE \u0026 TIME`\n\n2. Configure preferred `LANGUAGE SUPPORT` and `KEYBOARD` layout.\n\n3. Set `INSTALLATION DESTINATION`\n\n4. Configure `NETWORK \u0026 HOSTNAME` and `ROOT PASSWORD`\n\n   Click `Begin Installation` at bottom right corner.\n\n\n### Install NFS\n\n   Update package list and upgrade all installed packages\n   ```bash\n   yum update \u0026\u0026 yum upgrade -y\n   ```\n\n   Install NFS utilities and libraries\n   ```bash\n   yum install nfs-utils libnfsidmap -y\n   ```\n\n   Enable and start these services for NFS to function properly\n   ```bash\n   systemctl enable rpcbind\n   systemctl enable nfs-server\n   systemctl start rpcbind\n   systemctl start rpc-statd\n   systemctl start rpc-statd\n   systemctl start nfs-idmapd\n   ```\n\n   Check available disk partitions\n   ```bash\n   fdisk -l\n   ```\n\n### Add Disks to CentOS Server\n\nWe'll create new disk and add to server inventory.\nThis disk will be used to setup NFS datastore.\n\n- Go to **`Player`** \u003e **`Manage`** \u003e **`Virtual Machine Settings`** at top left of VMware workstartion.\n- Click `Add...` at bottom left\n- In the popped up `Add Hardware Wizard`, select `Hard Disk` hardware type and click `Next`\n- Select `SCSI` as virtual disk type and click `Next`\n- Select `Create a new virtual disk` and click `Next`\n- Set `Maximum disk size` at 200GB and choose `store virtual disk as a single file`\n- Click `Finish`\n\nNotice new `Hard Disk(SCSI)` with size 200GB added to hardware inventory.\n\nRepeat steps above to add another `Hard Disk(SCSI)` with size 5GB.\n\nThis disk will be used to setup Heartbeat datastore.\n\nReboot CentOS server\n```bash\nreboot\n```\n\n### Create XFS Partitions on Linux\n\nImplement the following steps to create XFS partition on disk for NFS:\n\n1. Check available disks detected and confirm new disks\n   ```bash\n   fdisk -l\n   ```\n   Note both `/dev/sdb` and `/dev/sdc` now added to list of disks available.\n\n2. Partition second disk available\n   ```bash\n   fdisk /dev/sdb\n   ```\n\n3. System will ask for `Command` input\n   Enter `n` to add a new partition\n\n4. Type and enter `p` to select Primary partition type\n\n5. Press `Enter` to set default `partition number` as 1\n\n6. For `First sector` prompt, press `Enter` to use default value of 2048\n\n7. For `Second sector` prompt, press `Enter` again to use default value.\n\n   Note statement of `Partition 1 of type Linux and of size 200GB is set`\n\n8. Type `w` and press `Enter` to write this new partition to the disk and ensure partition table is re-read.\n\n9. Make xfs filesystem on new partition\n   ```bash\n   mkfs.xfs /dev/sdb1\n   ```\n\n\nImplement the following steps to create XFS partition on disk for Heartbeat:\n\n1. Check available disks detected and confirm new disks\n   ```bash\n   fdisk -l\n   ```\n   Note boot partition `/dev/sdb1`\n\n2. Partition second disk available\n   ```bash\n   fdisk /dev/sdc\n   ```\n\n3. System will ask for `Command` input\n   Enter `n` to add a new partition\n\n4. Type and enter `p` to select Primary partition type\n\n5. Press `Enter` to set default `partition number` as 1\n\n6. For `First sector` prompt, press `Enter` to use default value of 2048\n\n7. For `Second sector` prompt, press `Enter` again to use default value.\n\n   Note statement of `Partition 1 of type Linux and of size 200GB is set`\n\n8. Type `w` and press `Enter` to write this new partition to the disk and ensure partition table is re-read.\n\n9. Make xfs filesystem on new partition\n   ```bash\n   mkfs.xfs /dev/sdc1\n   ```\n\n### Create NFS Mount Points\n\n  Make new directories as NFS mount points\n  ```bash\n  mkdir /nfs-share-1\n  mkdir /hb-share-1\n  ```\n\n  Mount disk partitions\n  ```bash\n  mount /dev/sdb1 /nfs-share-1\n  mount /dev/sdc1 /hb-share-1\n  ```\n\n  Check disk space usage and confirm filesystems are mounted\n  ```bash\n  df -h\n  ```\n\n  **Enable Auto Mount**\n\n   Confirm the file sytem table is defined for our new filesystems to be mounted at system boot and normal operations.\n\n   Check `/etc/fstab` and confirm entries for both `/dev/sdb1` and `/dev/sdc1` filesystems.\n   \n   If not available, add them as shown below:\n\n   Copy config file\n   ```bash\n   cp /etc/fstab /etc/fstab.bak\n   cd /etc\n   ```\n\n   Edit fstab configuration file\n   ```bash\n   vi /etc/fstab\n   ```\n\n   ```bash\n   /dev/sdb1\t/nfs-share-1\txfs\tdefaults\t0\t0\n   /dev/sdc1\t/hb-share-1     xfs\tdefaults\t0\t0\n   ```\n\n   **Configure Exports Configuration File**\n   \n   Check `/etc/exports` file used by NFS server to define the directories and options that it will export to NFS clients.\n\n   Copy config file\n   ```bash\n   cp /etc/exports /etc/exports.bak\n   cd /etc\n   ```\n\n   Edit exports configuration file\n   ```bash\n   vi /etc/exports\n   ```\n\n   Add entry to exports configuration file\n   ```bash\n   /nfs-share-1 *(rw,sync,no_root_squash,insecure)\n   /hb-share-1 *(rw,sync,no_root_squash,insecure)\n   ```\n\n   Export the NFS shares\n\n   ```bash\n   exportfs -rv\n   ```\n\n   Disabling firewall(optional)\n\n   If firewall is configured to block nfs related ports.\n   Please re-open this ports. No need to disable entire firewall.\n\n\n   **Mount NFS Shares to ESXi Hosts**\n\n   We'll use vCenter server to mount this NFS shares to ESXi hosts in workload cluster named `odennav-dc-cluster.\n   This task will be implemented with terraform.\n\n\n   ```bash\n   yum update -y\n   yum install net-tools\n   ```\n\n   View IP address of NFS server\n   ```bash\n   ifconfig\n   ```\n\n   We'll add the IPv4 address of NFS servers to the terraform manifest `vmware-sddc-private-cloud/terraform-manifest/modules/datastores_nfs/datastores_nfs_main.tf`\n\n\n\n   Please note you'll have to create another NFS server to provide redundancy and fault tolerance.\n   If one NFS server goes down or experiences issues, clients can still access data from the other NFS server.\n\n   Name of directories to mount as nfs shares:\n   - /nfs-share-2\n   - /hb-share-2\n\n   For the second NFS server, use same disk sizes for 1st NFS server.\n\n-----\n\n##  Compute Cluster \u0026 Resource Sharing Solutions(vHA, DRS, SDRS)\n\n\nHigh Availability is a utility that provides uniform, cost-effective failover protection against hardware and operating system outages within your virtualized IT environment.\n\nvSphere HA allows you to:\n\n- Monitor VMware vSphere hosts and virtual machines to detect hardware and guest operating system failures.\n\n- Restart virtual machines on other vSphere hosts in the cluster without manual intervention when a server outage is detected.\n\n- Reduce application downtime by automatically restarting virtual machines upon detection of an operating system failure.\n\n\nVMware vSphere Distributed Resource Scheduler (DRS) is the resource scheduling and load balancing solution for vSphere.\nDRS works on a cluster of ESXi hosts and provides resource management capabilities like load balancing and virtual machine (VM) placement.\n\nStorage DRS allows you to manage the aggregated resources of a datastore cluster.\nWhen Storage DRS is enabled, it provides recommendations for virtual machine disk placement and migration to balance space and I/O resources across the datastores in the datastore cluster.\n\n\nWe'll implement the following to enable this solutions in vSphere using Terraform:\n\n- Install Terraform\n- Create Datacenter\n- Provision Datacenter cluster and add ESXi hosts\n- Create Datastore cluster\n- Enable vHA, DRS and SDRS\n- Add NFS shares to Datastore Cluster\n- Create Inventory tags\n\n\n**Install Terraform**\n\nChocolatey is a free and open-source package management system for Windows which we'll use to install Terraform.\nCheck [Chocolatey](https://chocolatey.org/install) guide for installation method.\n \nIf you're using a different operating system, check [here](https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli) for Terraform install guide.\n\nVerify Chocolatey installation\n```bash\nchoco -help\n```\n\nInstall the Terraform package on git bash.\n```bash\nchoco install terraform\n```\n\nVerify terraform installation\n```bash\nterraform version\n```\n\nLocate terraform manifests and initialize the directory\nInstall vSphere providers defined \n\n```bash\ncd terraform-manifest/\nterraform init \n```\n\nFormat your configuration\n```bash\nterraform fmt \n```\n\nValidate your configuration\n```bash\nterraform validate \n```\n\nCreate an execution plan that describes the planned changes to the vSphere infrastructure\n```bash\nterraform plan \n```\n\nApply the configuration \n```bash\nterraform apply --auto-approve\n```\n\n-----\n\n\n## Provision Windows and Linux VMs to vSphere Cluster\n\n**Install Packer**\n\nWe'll install Packer with Chocolatey\n\n```bash\nchoco install packer\n```\n\nVerify Packer installation\n```bash\npacker version\n```\n\nBefore we implement Packer, note the configuration template that creates a Windows VM image.\n\n```yaml\nvariable \"vcenter_username\" {\n    type = string\n    default = \"vcenter\"\n    sensitive = true\n}\n\nvariable \"vcenter_password\" {\n    type = string\n    default = \"**********\"\n    sensitive = true\n}\n\nvariable \"vcenter_server\" {\n    type = string\n    default = \"vcenter.odennav.local\"\n    sensitive = true\n}\n\nvariable \"vcenter_cluster\" {\n    type = string\n    default = \"odennav-dc-cluster\"\n    sensitive = true\n}\n\nvariable \"vcenter_datacenter\" {\n    type = string\n    default = \"odennav-dc\"\n    sensitive = true\n}\n\nvariable \"esx_datastore\" {\n    type = string\n    default = \"odennav-datastore-cluster\"\n    sensitive = true\n}\n\n\n\nlocals {\n    buildtime = formatdate(\"YYYY-MM-DD hh:mm ZZZ\", timestamp())\n}\n\nsource \"vsphere-iso\" \"windows2019\" {\n    vcenter_server = var.vcenter_server\n    username = var.vcenter_username\n    password = var.vcenter_password\n    cluster = var.vcenter_cluster\n    datacenter = var.vcenter_datacenter\n    datastore = var.esx_datastore\n    folder =\"Templates\"\n    insecure_connection = \"true\"\n\n    notes = \"Built by Packer on ${local.buildtime}\"\n    vm_name = \"packer_windows2019\"\n    winrm_username = \"Administrator\"\n    winrm_password = \"S3cret!\"\n    CPUs = \"1\"\n    RAM = \"4096\"\n    RAM_reserve_all = true\n    communicator = \"winrm\"\n    disk_controller_type = [\"lsilogic-sas\"]\n    firmware = \"bios\"\n    floppy_files = [\n        \"artifacts/autounattend.xml\",\n        \"artifacts/setup.ps1\",\n        \"artifacts/winrm.bat\",\n        \"artifacts/vmtools.cmd\"\n    ]\n    guest_os_type = \"windows9Server64Guest\"\n    iso_paths = [\n        \"[${var.esx_datastore}] ISO/SERV2019.ENU.JAN2021.iso\",\n        \"[] /vmimages/tools-isoimages/windows.iso\"\n    ]\n\n    network_adapters {\n        network = \"VM Network\"\n        network_card = \"vmxnet3\"\n    }\n\n    storage {\n        disk_size = \"40960\"\n        disk_thin_provisioned = true\n    }\n\n    convert_to_template = true\n\n    http_port_max = 8600\n    http_port_min = 8600\n}\n\nbuild {\n    sources = [\"source.vsphere-iso.windows2019\"]\n}\n```\n\nInitialize your Packer configuration\n\n```bash\ncd ~/vmware-vsphere-sddc-private-cloud/packer/\npacker init \n```\n\nEnsure template has consistent format\n\n```bash\npacker fmt \n```\n\nEnsure your configuration is syntactically valid and internally consistent\n\n```bash\npacker validate \n```\n\nBuild image\n```bash\npacker build \n```\n\nView `packer_windows2019` and `packer_ubuntu20` VM templates created in vSphere inventory.\n\n\n**Provision VMs to vSphere Custer**\n\nAdd the following modules required to provision linux and windows server vm to vsphere environment.\n\nCopy modules from `vm_modules` file and append to `main.tf` as shown below:\n\n```yaml\nmodule \"vm_ubuntu\" {\n  source = \"./modules/vm_ubuntu\"\n}\n\noutput \"vm_ubuntu\" {\n  description = \"ubuntu server vm template\"  \n  value = module.vm_ubuntu.ubuntu_details\n}\n\nmodule \"vm_windows\" {\n  source = \"./modules/vm_windows\"\n}\n\noutput \"vm_windows\" {\n  description = \"windows server vm template\"  \n  value = module.vm_windows.windows_details\n}\n```\n\nFormat your configuration\n```bash\ncd ~/vmware-vsphere-sddc-private-cloud/terraform-manifest\nterraform fmt\n```\n\nValidate your configuration\n```bash\nterraform validate \n```\n\nTarget vm modules for planned changes to the vSphere infrastructure\n```bash\nterraform plan -target=module.vm_ubuntu -target=module.vm_windows\n```\n\nApply the configuration \n```bash\nterraform apply -target=module.vm_ubuntu -target=module.vm_windows\n```\n\n-----\n\n## NSX-T Setup and Configuration\n\nNSX network virtualization programmatically creates and manages virtual networks.\n\nUsing network virtualization, the functional equivalent of a network hypervisor we can reproduce the \ncomplete set of Layer 2 through Layer 7 networking services (for example, switching, routing, \naccess control, firewalling, QoS) in software.\n\nNSX works by implementing three separate but integrated planes: management, control and \ndata planes\n\nThese planes are implemented as a set of processes, modules, and agents residing on two \ntypes of nodes: \n- NSX Manager \n- Transport Nodes.\n\n**Requirements**\n\nNote the following resources we'll need to configure NSX-T for this project:\n\n- Two datacenter clusters:\n\n  Workload cluster(3 ESXi hosts)\n  \n  Edge cluster(1 ESXi host)\n\n- vDS(Virtual Distributed Switch) over workload cluster, With six port-groups available for:\n  - Management\n  - vMotion\n  - Provisioning\n  - Fault tolerance\n  - Tunnel Endpoint\n  - NSX Edge(Uplink)\n\n\n- Enable Jumbo frames by setting MTU to 1700 or larger on VSS(Virtual Standard Switch) and VDS.\n\n- Use physical multilayer switch and configure 3 VLANS:\n  \n  Mangaement VLAN \n  Tunnel Endpoint(TEP) \n  NSX Edge VLAN \n\n  These VLANS should be trunked(802.1q) to the ESXi hosts in workload cluster so that they're used with virtual switches.\n\n- NSX-T Data Center needs license for proper configuration and `vSphere7 Enterprise Plus license` needed for ESXi hosts.\n\n\n### NSX Networking Information\n\nThis networking information is required when installing NSX.\n\nThe subnet mask is /24 for all the IP addresses below:\n\nVLAN 10 -----------------------\u003e Management traffic \n\nVLAN 20 -----------------------\u003e For NSX TEP traffic\t                                                            \n\nVLAN 50 -----------------------\u003e For traffic between the tier-0 gateway and physical router(NSX edge traffic      \n\nDPortGroup-MGMT -----------\u003e vCenter PG-mgmt backed by VLAN 10 \t                                         \n\nManagement subnet ----------\u003e 192.168.10.0/24, Default gateway: 192.168.10.1, Subnet mask: 255.255.255.0       \n\nTunnel Endpoint(TEP) ---------\u003e Subnet 192.168.20.0/24, Default gateway: 192.168.20.1, Subnet-mask:255.255.255.0 \n \t\nvCenter IP address ------------\u003e 192.168.10.10 (VLAN 10)                                           \t\n\nESXi-1 IP address -------------\u003e 192.168.10.11 (VLAN 10), 192.168.20.11 (VLAN 20)   \n\nESXi-2 IP address -------------\u003e 192.168.10.12 (VLAN 10), 192.168.20.12 (VLAN 20)\n                                                                                    \nESXi-3 IP address -------------\u003e 192.168.10.13 (VLAN 10), 192.168.20.13 (VLAN 20)  \n\nESXi-4 IP address -------------\u003e 192.168.10.14 (VLAN 10)\n\nNSX-mgr-1 IP address --------\u003e 192.168.10.15 (VLAN 10) \n\nNSX-mgr-2 IP address --------\u003e 192.168.10.16 (VLAN 10) \n\nEdge-1 IP address -------------\u003e 192.168.10.17 (VLAN 10), 192.168.20.17 (VLAN 20)\t\n\nEdge-2 IP address -------------\u003e 192.168.10.18 (VLAN 10), 192.168.20.18 (VLAN 20)        \n\nPhysical router's downlink IP address --------------------------\u003e 192.168.50.1 (VLAN 50)                                                             \t                                                                               |                        \t\n\nTier-0 gateway's external-interface IP address on Edge-1 -------\u003e 192.168.50.11 (VLAN 50)                                                           \n                                                                                                                                                                       \t\nTier-0 gateway's external interface IP address on Edge-2 -------\u003e 192.168.50.12 (VLAN 50)\n\nTier-0 gateway's virtual IP -----------------------------------------\u003e 192.168.50.13 (VLAN 50)                                                         \n\nLB1.1 subnet -------------------------------------------------------\u003e 192.168.1.0/24\n\n\nLB-VM-1 IP address -----------------------------------------------\u003e 192.168.1.2                                                                   \n\nWEB1.1 subnet ----------------------------------------------------\u003e 192.168.2.0/24                                                              \n\nWEB-VM-1 IP address --------------------------------------------\u003e 192.168.2.2                                                                   \n\nWEB-VM-2 IP address --------------------------------------------\u003e 192.168.2.3                                                                     \t\n\nWEB-VM-3 IP address --------------------------------------------\u003e 192.168.2.4                                                                    \n\n\n### Deploy NSX-T Manager\n\nNSX-T Manager supports a cluster with three node, which merges policy manager, management, and central control services on a cluster of nodes. \n\nClustering is recommended for production environment and this provides high availability of the user interface and API.\n\nDownload VMware ovf tool for your preferred operating system from [here](https://developer.vmware.com/web/tool/ovf/) and use it to deploy to an ESXi host.\n\nDue to resources available we'll just install one manager on esxi03 which is managed by vCenter.\n\n\n**Procedure**\n\nRun the ovftool command with appropriate command parameters.\nInstallation is done on windows local machine\n\nCeate directory on local machine for ovftool logs\n```console\nmkdir C:\\ovftool-logs\n```\n\nExtract ovftool zipped package to `C:\\`  and run below command in Windows command prompt.\nNote my extracted folder from zip package is `C:\\VMware-ovftool-4.4.3-18663434-win.x86_64`\n\n```console\nC:\\VMware-ovftool-4.4.3-18663434-win.x86_64\\ovftool\u003eovftool \n--name=nsx-manager-1\n--X:injectOvfEnv \n--X:logFile=C:\\ovftool-logs\\ovftool.log \n--sourceType=OVA \n--vmFolder='' \n--allowExtraConfig \n--datastore=nfs-datastore-1\n--net:\"\" \n--acceptAllEulas \n--skipManifestCheck \n--noSSLVerify \n--diskMode=thin\n--quiet \n--hideEula \n--powerOn \n--prop:nsx_ip_0=192.168.10.15  \n--prop:nsx_netmask_0=255.255.255.0 \n--prop:nsx_gateway_0=192.168.10.1\n--prop:nsx_dns1_0=192.168.36.2 \n--prop:nsx_domain_0=odennav.local \n--prop:nsx_ntp_0=162.159.200.1 \n--prop:nsx_isSSHEnabled=True \n--prop:\"nsx_passwd_0=password\" \n--prop:\"nsx_cli_passwd_0=password-cli\" \n--prop:\"nsx_cli_audit_passwd_0=password-cli-audit\" \n--prop:nsx_hostname=nsx\n--prop:mgrhostname01=\"mgr@gmail.com\" \n--prop:nsx_allowSSHRootLogin=True \n--prop:nsx_role=\"NSX Manager\" \n--X:logFile=/root/ovftool/ovf-folder.log \n--X:logLevel=trivia \n--ipProtocol=IPv4 \n--ipAllocationPolicy=\"fixedPolicy\" C:\\NSX-T Data Center 4.1\\nsx-embedded-unified-appliance-4.1.ova \\\n'vi://Administrator@vsphere.local:\u003cvcenter-password\u003e@192.168.10.10/odennav-datacenter/host/Install/192.168.10.13/\n```\n\nThe result should look something like this:\n\n```text\nOpening OVA source: nsx-embedded-unified-appliance-4.1.ova\nThe manifest validates\nSource is signed and the certificate validates\nOpening VI target: vi://Administrator@vsphere.local@192.168.10.13:443/\nDeploying to VI: vi://Administrator@vsphere.local@192.168.10.13:443/\nTransfer Completed\nPowering on VM: NSX Manager\nTask Completed\nCompleted successfully\n```\n\nAfter deployment, verify that the NSX Manager UI comes up by accessing the \nfollowing URL, `192.168.10.15` on your browser.\n\n\n### NSX IP-Pools Setup \n\nWe'll setup IP pools to assign Tunnel Endpoints to each of our ESXi hosts that are participating in the NSX Overlay networks.\n\nSince we're using three hosts, and expect to deploy 1 edge node, we’ll need a TEP Pool(static IPv4 addresses) with at least 4 IP Addresses.\n\n**Procedure**\n\nLogin to NSX Manager\n\n\nAt the NSX-T Manager, go to **`Networking`** -\u003e **`IP Management`** -\u003e **`IP Address Pools`** \n\n- Click `ADD IP ADDRESS POOL` enter the following details:\n\n  Name --\u003e TEP-Pool\n  \n  Description --\u003e Tunnel Endpoint Pool\n\n\n- Click `Set` hyperlink under `Subnets`.\n\nOn the `Set Subnets` section, assign the following:\n\nIP Ranges -----\u003e 192.168.20.2-192.168.20.30\n\nCIDR ----------\u003e 192.168.20.0/24\n\nGateway IP ----\u003e 192.168.20.1\n\nDNS Servers ---\u003e 192.168.36.2\n\nDNS Suffix ----\u003e odennav.local\n\nClick `ADD`\n\n### NSX Transport Zone Setup\n\nNext task is to setup transport zone where data packets are sent between nodes.\n\nThe ESXi hosts that participate in NSX networks are grouped in the transport zone.\n\nWe'll setup two transport zones:\n\n- Overlay Transport Zones\n\n- VLAN Transport Zones\n\n**Procedure for Overlay Transport Zones**\n\nAt the NSX-T Manager, go to **`System`** –\u003e **`Fabric`** –\u003e **`Transport Zones`**\n\nClick the `+` button and assign the the following:\n\nName ----------\u003e Overlay-Zone\n\nDescription ---\u003e NSX Overlay Zone\n\nSwitch Name ---\u003e \n\nTraffic Type --\u003e Overlay\n\nPress `ADD`\n\n**Procedure for VLAN Transport Zones**\n\nAt the NSX-T Manager, go to **`System`** –\u003e **`Fabric`** –\u003e **`Transport Zones`**\n\nClick the `+` button and assign the the following:\n\nName ----------\u003e VLAN-Zone\n\nDescription ---\u003e VLAN Transport Zone\n\nSwitch Name ---\u003e NSX-VLAN\n\nTraffic Type --\u003e Overlay\n\nClick `ADD` to save this configuration\n\n\n**Procedure for Uplink Profiles**\n\nThis helps to set uplinks for any of the transport nodes we’ll be creating.\n\nWe'll use two NICs(Network Interface Cards)\n\nAt the NSX-T Manager, go to **`System`** –\u003e **`Fabric`** –\u003e **`Profiles`**\n\nClick on `Uplink Profiles` then press the `+` button and assign the the following:\n\nName -------------\u003e Overlay-Uplink-Profile\n\nTransport VLAN ---\u003e 20\n\n\nSave this configuration\n\n\n\n**Procedure for Transport Node Profile**\n\nThis is used to  provide configuration for each of the ESXi nodes and specify which NICs on the nodes to be configured for the VDS switch.\n\nIt also specifies the IP Addresses assigned for the TEP(Tunnel Endpoints) on this switch.\n\nWe'll use two NICs(Network Interface Cards)\n\nAt the NSX-T Manager, go to **`System`** –\u003e **`Fabric`** –\u003e **`Profiles`**\n\nClick `Transport Node Profiles` then press the `+` button and assign the the following:\n\nName --------------\u003e Transport-Node-Profile\n\nDescription -------\u003e Odennav Transport Node Profile\n\nType --------------\u003e VDS\n\nMode --------------\u003e Standard\n\nName --------------\u003e vcenter.odennav.local     \u0026\u0026    Switch -----\u003e Odennav-DSwitch\n\nTransport Zone ----\u003e Overlay-Zone\n\nUplink Profile ----\u003e Overlay-Uplink-Profile\n\nIP Assignment -----\u003e Use IP Pool\n\nIP Pool -----------\u003e TEP-Pool\n\nUplinks -----------\u003e vmnic1(Uplink 1)\n\nSave this configuration.\n\n\n**Procedure to Configure Transport Nodes**\n\nWe apply the transport node profile to configure the transport nodes in the `odennav-dc-cluster`\n\nAt the NSX-T Manager, go to **`System`** –\u003e **`Fabric`** –\u003e **`Nodes`**\n\nClick `Host Transport Nodes` then press the `Managed by` button to select the vCenter server.\n\nSelect radio button to indicate the chosen workload cluster\n\nThen click on `CONFIGURE NSX` and assign the following:\n\nTransport Node Profile ---\u003e Transport-Node-Profile\n\n\nClick `APPLY` to configure the ESXi hosts.\n\n\nNow we've successfully configured our chosen transport nodes and uplinks on vDS with the profiles created.\n\n\n### Deploy NSX Edge Nodes\n\nNSX-T Edge nodes are used for security and gateway services that can’t be run on the distributed routers in use by NSX-T. \nNorth/South routing and load balancing services are implemented by edge nodes.\n\nEdge node is deployed to Edge Cluster named `odennav-edge-cluster`.\nThis approach is best for production setup because these nodes will become a network hotspot.\n\nThe Edge VM has a virtual switch inside it, and we’ll connect the edge vm uplinks to the Distributed virtual switch uplinks.\n\nEdge VM will have three or more interfaces:\n\n- Management\n- Overlay\n- VLAN traffic to the physical network.\n\n**Procedure**\n\n- In NSX Manager, go to **`System`** \u003e **`Fabric`** \u003e **`Nodes`** \u003e **`Edge Transport Nodes`**.\n\n- Click `Add Edge Node`.\n\nAssign the following:\n\nName -------------------\u003e Edge-1\n\nHost name --------------\u003e edge1.odennav.local\n\nForm Factor ------------\u003e Select the appropriate edge node size.\n\nCLI User Name ----------\u003e admin\n\nCLI Password -----------\u003e ***********\t\n\nAllow SSH Login\t--------\u003e Select option based on your datacenter policy.\n\nSystem Root Password----\u003e **************\t\n\nAllow Root SSH Login ---\u003e Select option based on your datacenter policy.\n\nAudit User Name\t--------\u003e audit \n\nAudit Password\t--------\u003e ********\n\nCompute Manager\t--------\u003e vcenter\n\nCluster\t----------------\u003e odennav-edge-cluster\n\nHost -------------------\u003e 192.168.10.14\n\nDatastore --------------\u003e nfs-datastore-2\n\nIP Assignment ----------\u003e Static\n\nManagement IP ----------\u003e 192.168.10.17\n\nDefault Gateway --------\u003e 192.168.10.1\n\nManagement Interface ---\u003e DPortGroup-MGMT\n\nDNS Servers ------------\u003e 192.168.36.2\n\nNTP Servers ------------\u003e pool.ntp.org\n\nEdge Switch name -------\u003e nsx-overlay, nsx-vlan\n\nTransport Zone ---------\u003e nsx-overlay-transportzone, nsx-vlan-transport-zone\n\nUplink Profile ---------\u003e Overlay-Uplink-Profile\n\nTeaming Policy(Uplinks)-\u003e DPortGroup-TEP(uplink-1), DPortGroup-EDGE(uplink-1)\n\nIP Assignment ----------\u003e Use Static IP List\n\nStatic IP List ---------\u003e 192.168.20.17\n\nGateway ----------------\u003e 192.168.20.1\n\nSubnet Mask ------------\u003e 255.255.255.0\n\nWait until the Configuration State column displays `Success`.\n\nYou can click the Refresh button to refresh the window.\n\nRepeat steps 4-6 to deploy `Edge-2` on host `192.168.10.12` with management IP `192.168.10.18` and static IP `192.168.20.18`.\n\n\n### Create an Edge Cluster\n\n**Procedure**\n\nVMware recommend deployment of edge nodes in pairs and pooled together to form an edge cluster.\n\n- In NSX Manager, go to **`System`** \u003e **`Fabric`** \u003e **`Nodes`** \u003e **`Edge Clusters`**.\n\n- Click `Add Edge Cluster`.\n\nAssign the following:\n\nName ----------------\u003e Edge-cluster-1\n  \nDescription ---------\u003e Odennav Edge Cluster\n\n\n- Move `Edge-1` and `Edge-2` from the `Available` window to the `Selected` window.\n\n- Save this configuration.\n\nNext, we create overlay networks for our VMs.\n\n-----\n\n### Create Tier-1 Gateways\n\nWe'll setup two tier-1 gateways/routers for nsx overlay segments\n\nIn NSX Manager, go to **`Networking`** \u003e **`Tier-1 Gateways`**.\n\nClick **`Add Tier-1 Gateway`**.\n\nAssign the following:\n\nTier-1 Gateway Name --------\u003e T1-gateway-1\n\nEdge Cluster ---------------\u003e Edge-cluster-1\n\nLinked Tier-0 Gateway ------\u003e T0-gateway-1\n\n\nUnder **`Route Advertisement`**, enable the following:\n \n`All Connected Segments \u0026 Service Ports`\n`All Static Routes`\n`All IPSec Local Endpoints`\n\nSave the changes.\n\nRepeat steps 2-5 and create T1-gateway-2. Specify the same edge cluster.\n\n\n### Create NSX Overlay Segments for VMs\n\nWe'll create three nsx overlay segments for VMs\n\nIn NSX Manager, go to **`Networking`** \u003e **`Segments`**.\n\nClick `Add Segment`.\n\nAssign the following:\n\nSegment Name --------\u003e LB1.1\n\nConnectivity --------\u003e T1-gateway-1\n\nTransport Zone ------\u003e Overlay-Zone\n\nSubnet --------------\u003e 192.168.1.0/24\n\n\nRepeat steps 2-3 and create WEB1.1 (subnet: 192.168.2.0/24, connectivity: T1-gateway-2) \n\nVerify that LB1.1 and WEB1.1 are created under the VDS(Odennav-DSwitch) in Vcenter.\n\n\n### Create NSX VLAN Segment\n\nWe'll create a segment for our Tier-0 gateway to use and connect to our physical network.\n\nIn NSX Manager, go to **`Networking`** \u003e **`Segments`**.\n\nClick `Add Segment`.\n\nAssign the following:\n\nSegment Name --------\u003e Uplink-Segment\n\nConnectivity --------\u003e T0-gateway-1\n\nTransport Zone ------\u003e VLAN-Zone\n\nSubnet --------------\u003e 192.168.50.2/24\n\nVLAN ----------------\u003e 50\n\n-----\n\n### Create a Tier-0 Gateway\n\nThis gateway connects directly to our physical VLAN and provides north/south routing into the NSX overlay networks.\n\nWith the Tier-0 Gateway we can connect our new NSX backed overlay segments to the physical network through the NSX-T Edge cluster.\n\n**Procedure**\n\n- In NSX Manager, go to **`Networking`** \u003e **`Tier-0 Gateways`**.\n\n- Click `Add Tier-0 Gateway`.\n\n- Enter a name for the gateway, for example, `T0-gateway-1`.\n\n- Select the HA (high availability) mode `Active Standby`.\n\n- Select the Edge cluster `Edge-Cluster-1`.\n\n- Click `Save` and continue configuring this gateway.\n\n- Click `Interfaces` and click `Set`.\n\n- Click `Add Interface`.\n\n- Enter a name, for example, IP1-EdgeNode1.\n\n- Enter the IP address 192.168.50.11/24.\n\n- In the `Connected To (Segment)` field, select Uplink-segment-1.\n\n- In the Edge Node field, select `Edge-1`.\n\n- Save the changes.\n\n- Repeat steps 8-13 to configure a second interface called IP2-EdgeNode2. The IP address \n  should be 192.168.50.12/24. The `Edge Node` should be `Edge-2`.\n\n- In the `HA VIP Configuration` field, click `Set` to create a virtual IP for the tier-0 \n  gateway.\n\n- Enter the IP address 192.168.50.13/24.\n\n- Select the interfaces IP1-EdgeNode1 and IP2-EdgeNode2.\n\n- Save the changes.\n\n\n### Configure Routing on the Physical Router and Tier-0 Gateway\n\n**Procedure**\n\n- On the physical router, configure a static route to the subnets 192.168.1.0/24 and 192.168.2.0/24 via 192.168.50.13,\n  which is the virtual IP address of the tier-0 gateway's external interface.\n\n- In NSX Manager, go to Networking \u003e Tier-0 Gateways.\n\n- Edit T0-gateway-1.\n\n- Under Routing \u003e Static Routes, click Set and click Add Static Route.\n\n- In the Name field, enter default.\n\n- In the Network field, enter 0.0.0.0/0.\n\n- Click Set Next Hops.\n\n- In the IP Address field, enter 192.168.50.1.\n\n- Click Add.\n\n- Save the changes.\n\n\nFinally, we've deployed Tier-0 router and connected NSX-T backed overlay segments to your physical network. \n\nImplement the following to test east-west and north-south connectivity:\n\n- Ping WEB-VM-1 from LB-VM-1 and vice versa\n- Ping the downlink interface of the physical router from WEB-VM-1.\n\n\nPlease note for VMs deployed to NSX-T overlay segments, ensure the network adapter is set to correct overlay segment.\n\n\n-----\n\n\n\n\n### Next Steps\n\nvSphere with Kubernetes\n\n-----\n\n### Media Options for Booting the ESXi Installer(Optional)\n\n[Download and Burn the ESXi installer ISO image to a CD or DVD](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-048CCB07-7E27-4CE8-9E6A-1BF655C33DAC.html)\n\n[To Format a USB flash drive to boot the ESXi installer](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-33C3E7D5-20D0-4F84-B2E3-5CD33D32EAA8.html#GUID-33C3E7D5-20D0-4F84-B2E3-5CD33D32EAA8)\n\n[To Create a USB flash drive and store the ESXi installation script or upgrade script](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-6DC29685-9757-456E-B396-DD6349B75A15.html)\n\n[How to Install VMware ESXi Type-1 Hypervisor](https://mattheweaton.net/posts/how-to-install-vmware-esxi-type-1-hypervisor/)\n\n[Create an Installer ISO Image with a Custom Installation or Upgrade Script](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-C03EADEA-A192-4AB4-9B71-9256A9CB1F9C.html)\n\n[Network Booting the ESXi Installer](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-B9DB94CA-4857-458B-B6F1-6A688726AED0.html)\n\n[Installing and Booting ESXi with Software FCoE](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-C05BAD53-2309-4BC2-9DBF-F2D3313F2B73.html)\n\n[Using Remote Management Applications](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-0E82A6CA-202A-4C5D-8811-53A7CF8D5CDC.html)\n\n[Customizing Installations with vSphere ESXi Image Builder](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-48AC6D6A-B936-4585-8720-A1F344E366F9.html)\n\n[ESXi Requirements](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-E170469F-9C33-4950-8672-9825501557AE.html#GUID-E170469F-9C33-4950-8672-9825501557AE)\n\n[vSphere Auto Deploy ESXi Installation](https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.esxi.install.doc/GUID-DC5D6EA2-2F17-4CB0-A0DB-C767F2BE2FBA.html)\n\n-----\n\n\nEnjoy!\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fodennav%2Fvmware-vsphere-sddc-private-cloud","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fodennav%2Fvmware-vsphere-sddc-private-cloud","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fodennav%2Fvmware-vsphere-sddc-private-cloud/lists"}