Skip to content
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# NSX Add Firewall

[Previous Challenge](./10-AVS-Migrate-VM.md) - **[Home](../Readme.md)** - [Next Challenge](./12-AVS-ANF-Datastores.md)
[Previous Challenge](./10-AVS-Migrate-VM.md) - **[Home](../Readme.md)** - [Next Challenge](./12-AVS-Placement-Policy)

## Introduction

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# NSX DHCP

[Previous Challenge](./13-AVS-Storage-Policy.md) - **[Home](../Readme.md)** - [Next Challenge](./15-AVS-Managed-SNAT.md)
[Previous Challenge](./11-NSX-Firewall.md) - **[Home](../Readme.md)** - [Next Challenge](./13-AVS-Managed-SNAT.md)

## Introduction

Expand Down Expand Up @@ -50,4 +50,4 @@ VM-Host Anti-Affinity policies instruct DRS to try running the specified VMs on

### Solution - Spoilerwarning

[Solution Steps](../Solutionguide/14-AVS-Placement-Policy.md)
[Solution Steps](../Solutionguide/12-AVS-Placement-Policy.md)
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# AVS Managed SNAT

[Previous Challenge](./14-AVS-Placement-Policy.md) - **[Home](../Readme.md)** - [Next Challenge](./16-AVS-Automation-ESLZ.md)
[Previous Challenge](./12-AVS-Placement-Policy.md) - **[Home](../Readme.md)**

## Introduction

Expand Down
Binary file not shown.
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,9 @@ The automated script to setup the lab environment can be found under the followi

**Note: To best benefit from this Microhack, prior VMware knowledge and basic AVS knowledge are preferred.**

### Note

All the data needed is in the excel file: [AVSMicroHackData](Lab/info/datos_Microhack_300925.xlsx). Prefixes, credentials ..

## Solution Guide

Expand Down Expand Up @@ -94,6 +97,8 @@ The automated script to setup the lab environment can be found under the followi
- [Andreas Schwarz]()
- [Sven Forstreuter]()
- [Sarah Tabet]()
- [David Wahby]()
- [Pablo Vales]()


Thank you for participating in this MicroHack!
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ For the solution of each challenge you will need to use the following informatio
| Type | Name |
|------| ----|
| Jumpbox VM | AVS-SDDC-FOM-Jumpbox |
| Azure Key Vault | AVS-Microhack |
| vCenter on AVS | AVS-SDDC-FOM-SDDC |

## vCenter onprem
Expand All @@ -21,11 +20,4 @@ For the solution of each challenge you will need to use the following informatio
| vCenter on-prem | 10.1.1.2 |
| HCX Manager on-prem | 10.1.1.9 |
| Workload-1-1-1 | 10.1.11.129 |
| Workload-1-1-2 | 10.1.11.130 |

## VMs in the onprem SDDC

| Name | IP |
|------| ----|
| win2022-dc | 10.1.1.30|
| win2022-worker | 10.1.1.31 |
| Workload-1-1-2 | 10.1.11.130 |
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

**[Home](../Readme.md)** - [Next Challenge Solution](./02-NSX-Add-Segment.md)

### Note

All the data needed is in the excel file: [AVSMicroHackData](../Lab/info/datos_Microhack_300925.xlsx). Prefixes, credentials ..

## Instructions

Here you will be using NSX-T to host your DHCP server and you will create a DHCP. Then you'll add a network segment and specify the DHCP IP address range.
Expand All @@ -21,11 +25,3 @@ Here you will be using NSX-T to host your DHCP server and you will create a DHCP
### Note
This DHCP server automatically gets connected to the default Tier 1 Gateway

4. You can now log on to NSX Manager in AVS and verify that the DHCP server is attached to the Tier1 Gateway

![](./Images/01-NSX-DHCP/NSX_image4.png)

> [!NOTE]
> The settings and changes above are for demonstration purposes only and are not required for the lab to function.


Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

[Previous Challenge Solution](./01-NSX-DHCP.md) - **[Home](../Readme.md)** - [Next Challenge Solution](./03-NSX-Add-DNS-Forwarder.md)

### Note

All the data needed is in the excel file: [AVSMicroHackData](../Lab/info/datos_Microhack_300925.xlsx). Prefixes, credentials ..

## Add a Network Segment
1. In NSX-T Manager, select Networking > Segments, and then select Add Segment.

Expand All @@ -15,7 +19,7 @@

![](./Images/02-NSX-Add-Segment/NSXSegment003.PNG)

5. Add DHCP range to your segment such that the VM's attached to this segment can recieve IP address dynamically
5. Add DHCP range to your segment such that the VM's attached to this segment can receive IP address dynamically

![](./Images/02-NSX-Add-Segment/NSXSegment004.PNG)

Expand All @@ -24,8 +28,8 @@
### Note
The IP address needs to be on a non-overlapping RFC1918 address block, which ensures connection to the VMs on the new segment.

7. Create a VM from the ISO file in the Content Library (SERVER_EVAL_x64FRE_en-us.iso) and attach it to the segment you just created.
8. Power on the VM and verify that it has received an IP address from the DHCP server.
7. Test the DHCP Server
Enter into the nested vCenter, change the network settings of the virtual machine named server01 to the network adapter belonging to the segment. Check that the virtual machine gets the IP of the created segment.

### Hint

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,15 +18,6 @@

![](./Images/03-NSX-Add-DNS-Forwarder/DNS4.png)

4. For this Microhack there was also a nested VMware cluster deployed which is running inside the AVS cluster. This nested cluster is reachable from the Jumbox-VM under https://10.1.1.2/ and the credentials are availble in the provided Azure Key Vault.

5. In the on-premise VMware clusters there are two VMs running. One is a Windows 2022 Domain Controller and the other is a domain-joined Windows 2022 server.

6. Find the hostname of the domain-joined server.

7. Verify from the VM created in last challenge that it can resolve the hostname of the domain-joined on-prem server.


### Note :

These DNS zones are a prerequisite for LDAP configuration for NSX.
These DNS zones are a prerequisite for LDAP configuration for NSX.
Original file line number Diff line number Diff line change
Expand Up @@ -2,133 +2,136 @@

[Previous Challenge Solution](./03-NSX-Add-DNS-Forwarder.md) - **[Home](../Readme.md)** - [Next Challenge Solution](./05-HCX-Site-Pair.md)


## Deploy HCX Manager Appliance On-Prem

1. Log in to the On Prem SDDC by login to your Azure jumpbox and by navigating to portal.azure.com. Log on to the jumpbox using the Bastion host and key in the username and password provided within the Azure Key Vault for your team.
1. Log in to the On Prem SDDC by login to your Azure jumpbox and by navigating to portal.azure.com. Log on to the jumpbox using the Bastion host and key in the username and password provided in the excel file: [AVSMicroHackData](../Lab/info/datos_Microhack_300925.xlsx)

2. Log into the portal and create a License Key for HCX Manager.

![](./Images/04-HCX-Manager-Appliance/HCX_OVA1.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA1.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA3.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA3.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA4.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA4.png)

3. Log into the vcenter and download the ova for the HCX Manager Appliance from the DataStore as shown in the image

2. Log into the HCX Manager of the AVS SDDC and get a download link for the HCX Manager Appliance
![](./Images/04-HCX-Manager-Appliance/HCX_OVA30.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA5.png)
4. Deploy the HCX Manager OVA into the On-Prem vCenter

![](./Images/04-HCX-Manager-Appliance/HCX_OVA6.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA31.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA7.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA32.png)

3. Import the link into you onprem SDDC and download the HCX Manager OVA file
![](./Images/04-HCX-Manager-Appliance/HCX_OVA33.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA8.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA34.png)

4. Deploy the HCX Manager OVA file into your On-Prem vCenter
![](./Images/04-HCX-Manager-Appliance/HCX_OVA35.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA9.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA10.png)

Make sure to select the correct network for the HCX Manager Appliance:
Make sure to select the correct network for the HCX Manager Appliance:

OnPrem-management-1-1
OnPrem-management-1-1

![](./Images/04-HCX-Manager-Appliance/HCX_OVA11.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA36.png)

Set the password for the HCX Manager Appliance
Set the password for the HCX Manager Appliance

![](./Images/04-HCX-Manager-Appliance/HCX_OVA12.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA37.png)

Make sure to set the correct IP for the HCX Manager Appliance: 10.1.1.9
Make sure to set the correct IP for the HCX Manager Appliance: 10.1.1.9

Prefix Length: 27
Prefix Length: 27

Set the correct DNS and Gateway for the HCX Manager Appliance:
Set the correct DNS and Gateway for the HCX Manager Appliance:

Gateway: 10.1.1.1
Gateway: 10.1.1.1

DNS: 1.1.1.1
![](./Images/04-HCX-Manager-Appliance/HCX_OVA38.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA13.png)
DNS: 1.1.1.1

5. Power on the HCX Manager Appliance
![](./Images/04-HCX-Manager-Appliance/HCX_OVA14.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA39.png)

Finish the wizard

![](./Images/04-HCX-Manager-Appliance/HCX_OVA15.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA40.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA16.png)
5. Power on the HCX Manager Appliance

![](./Images/04-HCX-Manager-Appliance/HCX_OVA41.png)

## Configure HCX Manager Appliance On-Prem

1. Log on to the AVS private Cloud for your team in Azure Portal from where you will need to get a activation key for the HCX manager On-Prem
6. Log on to the AVS private Cloud for your team in Azure Portal from where you will need to get a activation key for the HCX manager On-Prem

![](./Images/04-HCX-Manager-Appliance/HCX_OVA17.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA17.png)

2. In the Azure VMware Solution portal, go to Manage > Add-ons > Migration using HCX > Connect with on-premise using HCX keys > Add > , specify the HCX Key Name (example as shown in the screenshot), and then select Add.
7. In the Azure VMware Solution portal, go to Manage > Add-ons > Migration using HCX > Connect with on-premise using HCX keys > Add > , specify the HCX Key Name (example as shown in the screenshot), and then select Add.

![](./Images/04-HCX-Manager-Appliance/HCX_OVA18.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA18.png)

3. Use the admin credentials to sign in to the on-premises VMware HCX Manager at https://10.1.1.9:9443.
7. Use the admin credentials to sign in to the on-premises VMware HCX Manager at https://10.1.1.9:9443.

![](./Images/04-HCX-Manager-Appliance/HCX_OVA19.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA42.png)


### TIP
### TIP
The admin user password is set during the VMware HCX Manager OVA file deployment.

4. In Licensing, enter your key for HCX Advanced Key and select Activate.

![](./Images/04-HCX-Manager-Appliance/HCX_OVA20.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA21.png)

### Important TIP
VMware HCX Manager must have open internet access or a proxy configured.
8. A wizard will be run for configuring:

5. In Datacentre Location, specify New York, Unted States of America and press continue
Region

![](./Images/04-HCX-Manager-Appliance/HCX_OVA22.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA43.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA23.png)
### TIP
Use the same region where AVS was deployed for this MicroHack

6. In System Name, modify the name or accept the default and select Continue.
System Name

![](./Images/04-HCX-Manager-Appliance/HCX_OVA24.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA44.png)

7. Select Yes, Continue.
Vcenter Link
![](./Images/04-HCX-Manager-Appliance/HCX_OVA45.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA25.png)
### TIP
Configure the URL for the On-Prem Vcenter

8. In Connect your vCenter, provide the FQDN or IP address of your vCenter server and the appropriate credentials, and then select Continue. Use the Azure Key Vault for this.
It will ask you to Install the Root Certificate from On-Prem vCenter
![](./Images/04-HCX-Manager-Appliance/HCX_OVA46.png)

![](./Images/04-HCX-Manager-Appliance/HCX_OVA26.png)
Configure SSO/PSC

![](./Images/04-HCX-Manager-Appliance/HCX_OVA27.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA47.png)

9. In Configure SSO/PSC, provide the FQDN or IP address of your Platform Services Controller (PSC), and then select Continue. In this case the the PSC is the same as the On-Prem vCenter server. The URL is:
### TIP
It´s the same URL than the On-Prem vCenter

https://10.1.1.2
Activate HCX

![](./Images/04-HCX-Manager-Appliance/HCX_OVA28.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA48.png)

## TIP
For that, copy and paste the key from:

10. Verify that the information entered is correct and select Restart.
![](./Images/04-HCX-Manager-Appliance/HCX_OVA51.png)

!![](./Images/04-HCX-Manager-Appliance/HCX_OVA29.png)
Restart the Appliance
![](./Images/04-HCX-Manager-Appliance/HCX_OVA49.png)

### Note
You'll experience a delay after restarting before being prompted for the next step.

After the services restart, you'll see vCenter showing as green on the screen that appears. Both vCenter and SSO must have the appropriate configuration parameters, which should be the same as the previous screen.

14. Once HCX Appliance is restarted, log on to the HCX Manager UI – https://10.1.1.9:9443
10. Once HCX Appliance is restarted, log on to the HCX Manager UI – https://10.1.1.9:9443

15. Go to Configuration -> vSphere Role Mapping -> replace System Administrator and Enterprise Administrator user groups with the following custom domain (instead of vsphere.local).
11. Go to Configuration -> HCX Role Mapping -> replace System Administrator and Enterprise Administrator user groups with the following custom domain (instead of vsphere.local).

Replace the domain name with **avs.lab**
Replace the domain name with **avs.lab\administrators**

![](./Images/04-HCX-Manager-Appliance/HCX_image14.png)
![](./Images/04-HCX-Manager-Appliance/HCX_OVA50.png)
Loading