Advanced Load Balancing for VMware Cloud Foundation
Implements centralized, enterprise-grade load balancing using VMware NSX Advanced Load Balancer (Avi Load Balancer) for VCF. Provides load balancing, GSLB, WAF, application analytics, and container ingress. Supports Enterprise with Cloud Services, Enterprise, and Basic editions. Scales up to 400 Service Engines per Controller cluster.
Key Components: NSX, Avi Load Balancer, SDDC Manager, vCenter, ESXi
Logical Design: Three-tier: Avi Controller cluster (control plane, 3 nodes in HA, in mgmt domain), Service Engines (data plane, in VI WLDs or dedicated Edge WLD), and Cloud Connectors (ecosystem integration). NSX-T Cloud Connector is the integration used in this VVS — one per NSX transport zone. Each Avi deployment associates with one NSX-T Data Center deployment; multiple Avi deployments per VCF when multiple NSX-T instances exist.
9 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| AVI-VI-VC-001 | Multi-AZ: add Controller nodes to first AZ VM group | Manageability |
Decision: Multi-AZ: add Controller nodes to first AZ VM group Rationale: Powered on in primary AZ hosts Implication: Must update VM group after 2nd AZ impl Component: VI | ||
| AVI-VI-VC-002 | Create VM group for Avi SE VMs | Manageability |
Decision: Create VM group for Avi SE VMs Rationale: Manage as group; add to VM/Host rules Implication: User must add SE VMs manually Component: VI | ||
| AVI-VI-VC-003 | Should-run VM-Host affinity: all SEs on first AZ hosts | Manageability |
Decision: Should-run VM-Host affinity: all SEs on first AZ hosts Rationale: SEs in first AZ during normal operation Implication: No SEs in 2nd AZ; all apps active in first AZ Component: VI | ||
| AVI-VI-VC-004 | Anti-affinity VM/Host rule for Controller VMs | Availability |
Decision: Anti-affinity VM/Host rule for Controller VMs Rationale: vSphere places for max HA Implication: No significant trade-offs identified for this decision. Component: VI | ||
| AVI-VI-VC-005 | VM group for Controller VMs | Manageability |
Decision: VM group for Controller VMs Rationale: Manage as group Implication: Manual addition Component: VI | ||
| AVI-VI-VC-006 | vSphere HA restart priority High + host isolation Disabled for Controllers/SEs | AvailabilityRecoverabilitySecurity |
Decision: vSphere HA restart priority High + host isolation Disabled for Controllers/SEs Rationale: Fast recovery Implication: No significant trade-offs identified for this decision. Component: VI | ||
| AVI-VI-VC-007 | Content Library on mgmt domain for Controller OVA | Manageability |
Decision: Content Library on mgmt domain for Controller OVA Rationale: Operationally easy deployment Implication: Unnecessary if using vRO/Ansible automation Component: VI | ||
| AVI-VI-VC-008 | Content Library per VI WLD for SE OVA | Manageability |
Decision: Content Library per VI WLD for SE OVA Rationale: Cloud Connector requires Content Library for SE creation Implication: No significant trade-offs identified for this decision. Component: VI | ||
| AVI-VI-VC-010 | Deploy Controllers on VCF management network | Manageability |
Decision: Deploy Controllers on VCF management network Rationale: Ease of mgmt, floating cluster VIP Implication: No significant trade-offs identified for this decision. Component: VI | ||
Prerequisites
- Environment per Before You Apply This Guidance
- 4 reserved mgmt IPs (3 Controllers + 1 cluster VIP)
- Functioning DNS
- vCenter and NSX-T service accounts with AviRole
- Content Library (one in mgmt domain for Controller OVA; one per VI WLD for SE OVA)
- Easy Deploy Appliance
Implementation Procedure
Implementation
DescriptionVMware Flings automation appliance deployed in mgmt domain; provides web interface (https://easy_deploy_ip/menu) to orchestrate Avi deployment for VCF
Steps
Download Easy Deploy OVA from flings.vmware.com
Upload Easy Deploy OVA to Content Library (sfo-m01-avic)
- Deploy Easy Deploy VM (sfo-m01-easydeploy) to mgmt domain
- Open https://<easy_deploy_ip>/menu
- Upload Avi Controller image (via Customer Connect or manual OVA)
- Register VCF environment with SDDC Manager FQDN/credentials; receive Unlock Passphrase
Initialize deployment per WLD: select image, deployment size, datacenter/cluster/datastore, content library, credentials, cluster option (3-node), DNS, network port group, network/CIDR, gateway
Provide 3 Controller IPs + cluster VIP
Deploy (takes up to 1 hour); rollback available on failure
Manual Deployment
Deploy Avi Controller VMs (3) from OVA to mgmt domain (sizing: 8 vCPU, 24 GB RAM, 208 GB disk, 8×base clock CPU reservation, 24 GB mem reservation)
Power on Controllers; access first via HTTPS; create admin account
Configure DNS, NTP, SMTP (from=admin@avicontroller.net)
Tenant Settings: 'Share IP route domain across tenants'; SEs managed within Provider; tenant SE access Read
Navigate Administration > Controller > Edit; Name cluster; provide cluster IP + node IPs; save
Replace Portal Certificate (Templates > Security > SSL/TLS Certificates > Create > Controller Certificate > CSR)
Replace Secure Channel Certificate
Apply license (Enterprise with Cloud Services preferred; Cloud Services registration; or paste license keys for Enterprise/Basic)
Setup alerting: Syslog (to vRealize Log Insight with Avi content pack), Email, SNMP, Control Scripts (Enterprise only)
Create Tenants (Option 1: config isolation; Option 2: config+data isolation via CLI)
Create NSX-T Cloud Connector for each TZ requiring LB
Create Service Engine Group(s) per tenant/WLD
- Deploy sample load-balanced application to verify
- Tenant Creation CLI
- Option 1 (config isolation only): CLI commands create Tenant
- Option 2 (config + data isolation): CLI commands
- Se Group Creation Settings
Day-2 Operations Tasks
Operations
As neededPersonas
As neededNameRole
As neededVI AdminSystem Administrator / Tenant Admin (Enterprise Administrator)
As neededSecurity AdminSecurity-scoped role
As neededTenant AdminEnterprise Administrator within tenant
As neededOperational Verification
As neededController
As neededNSX T Cloud Connector
As neededCertificate Management
As neededMonitoring Points
- Verify all 3 Controllers show State=Active in Administration > Controller
- Verify cluster VIP reachable
- Verify system health dashboards
- Verify Cloud Connector shows Ready state
- Verify SE image uploaded to VI WLD Content Library
- Verify test SE deployment succeeds
- Monitoring And AlertingAVI-CTLR-035: enable System alerts (VS, SSL, SE, Controller, CC). Integrate with Aria Operations for Logs via syslog (Avi conte
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Tenancy strategy (config vs. config+data isolation) — trade-off of isolation vs. SE resource consumption
Chosen:
Justification:
Trade-Offs Analysis
Chosen:
Justification:
Tenancy: no isolation (admin), config isolation (shared SEs), or full isolation (dedicated SEs) — resource vs. blast radius
Chosen:
Justification:
Active/Active (elastic) vs. Legacy Active/Standby (client IP preserved)
Chosen:
Justification:
Basic Edition (NSX LB replacement) vs. Enterprise (full feature set + Cloud Services)
Chosen:
Justification:
Quiz — Advanced Load Balancing
- VI workload domain
- Management domain
- Edge workload domain
- Dedicated NSX Manager cluster
- 50
- 100
- 200
- 400
- <5 ms
- <10 ms
- <25 ms
- <75 ms
- <10 ms
- <25 ms
- <50 ms
- <75 ms
- Per NSX Manager only
- Per vCenter only
- Per NSX Manager + transport zone
- Per VLAN
- Load balancing
- Active/Active SE HA
- HTTPS listener
- Self-signed cert replacement
- Multiple segments per Tier-1
- One segment per Tier-1 for data networks
- Unlimited
- Depends on MTU
- Upgrade NSX-T first
- Upgrade Avi first, check compatibility matrix
- Upgrade simultaneously
- Upgrade vCenter first
- 22
- 443
- 8443
- 9443
- Annually
- Every 6 months
- Every 3 months
- Every 30 days
- All 3
- 2
- 1
- 0 (form auto)
- 5 GB
- 10 GB
- 15 GB
- 30 GB
- Reserves CPU for management
- Dedicates a core for packet processing on SEs with 4+ vCPU
- Pins SE to a specific host
- Increases memory reservation
- Provider/Admin
- Config isolation
- Config + Data isolation
- No isolation
- Root password on all ESXi hosts
- SDDC Manager FQDN and credentials
- vCenter SSO admin only
- Avi license file
Flashcards — Advanced Load Balancing
Labs
Deploy Avi Controller Cluster Using Easy Deploy
Use VMware Easy Deploy Fling to orchestrate a 3-node Avi Controller cluster in a VCF management domain integrated with a VI workload domain's NSX-T and vCenter.
Starting State: Healthy VCF 5.2 with VI WLD; SDDC Manager admin creds; 4 reserved mgmt IPs; functioning DNS; Avi OVA available via Customer Connect.
Create Tenants, NSX-T Cloud Connector, and SE Groups
Configure Avi infrastructure: create tenants for isolation, NSX-T Cloud Connector for a VI WLD transport zone, and Service Engine Groups with Active/Active HA.
Starting State: Avi Controller cluster deployed; vCenter + NSX-T service accounts (AviRole) created; SE Content Library on target VI WLD.
Deploy a Sample Load-Balanced Application
Create a Virtual Service for a web application on an NSX overlay segment using Active/Active SE placement, HTTPS with CA-signed cert, and health monitors.
Starting State: Cloud Connector Ready; SE Group with Active/Active HA; back-end web servers (2+) running on NSX overlay segment accessible from Tier-1.