Academy/VVS/Advanced Load Balancing
This solution targets VCF 5.2

Advanced Load Balancing for VMware Cloud Foundation

VCF 5.2architectvcdxnetworkautomationPages 938-1040

Implements centralized, enterprise-grade load balancing using VMware NSX Advanced Load Balancer (Avi Load Balancer) for VCF. Provides load balancing, GSLB, WAF, application analytics, and container ingress. Supports Enterprise with Cloud Services, Enterprise, and Basic editions. Scales up to 400 Service Engines per Controller cluster.

Key Components: NSX, Avi Load Balancer, SDDC Manager, vCenter, ESXi

Logical Design: Three-tier: Avi Controller cluster (control plane, 3 nodes in HA, in mgmt domain), Service Engines (data plane, in VI WLDs or dedicated Edge WLD), and Cloud Connectors (ecosystem integration). NSX-T Cloud Connector is the integration used in this VVS — one per NSX transport zone. Each Avi deployment associates with one NSX-T Data Center deployment; multiple Avi deployments per VCF when multiple NSX-T instances exist.

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

9 design decisions

DD-IDDecisionQuality
AVI-VI-VC-001Multi-AZ: add Controller nodes to first AZ VM groupManageability

Decision: Multi-AZ: add Controller nodes to first AZ VM group

Rationale: Powered on in primary AZ hosts

Implication: Must update VM group after 2nd AZ impl

Component: VI

AVI-VI-VC-002Create VM group for Avi SE VMsManageability

Decision: Create VM group for Avi SE VMs

Rationale: Manage as group; add to VM/Host rules

Implication: User must add SE VMs manually

Component: VI

AVI-VI-VC-003Should-run VM-Host affinity: all SEs on first AZ hostsManageability

Decision: Should-run VM-Host affinity: all SEs on first AZ hosts

Rationale: SEs in first AZ during normal operation

Implication: No SEs in 2nd AZ; all apps active in first AZ

Component: VI

AVI-VI-VC-004Anti-affinity VM/Host rule for Controller VMsAvailability

Decision: Anti-affinity VM/Host rule for Controller VMs

Rationale: vSphere places for max HA

Implication: No significant trade-offs identified for this decision.

Component: VI

AVI-VI-VC-005VM group for Controller VMsManageability

Decision: VM group for Controller VMs

Rationale: Manage as group

Implication: Manual addition

Component: VI

AVI-VI-VC-006vSphere HA restart priority High + host isolation Disabled for Controllers/SEsAvailabilityRecoverabilitySecurity

Decision: vSphere HA restart priority High + host isolation Disabled for Controllers/SEs

Rationale: Fast recovery

Implication: No significant trade-offs identified for this decision.

Component: VI

AVI-VI-VC-007Content Library on mgmt domain for Controller OVAManageability

Decision: Content Library on mgmt domain for Controller OVA

Rationale: Operationally easy deployment

Implication: Unnecessary if using vRO/Ansible automation

Component: VI

AVI-VI-VC-008Content Library per VI WLD for SE OVAManageability

Decision: Content Library per VI WLD for SE OVA

Rationale: Cloud Connector requires Content Library for SE creation

Implication: No significant trade-offs identified for this decision.

Component: VI

AVI-VI-VC-010Deploy Controllers on VCF management networkManageability

Decision: Deploy Controllers on VCF management network

Rationale: Ease of mgmt, floating cluster VIP

Implication: No significant trade-offs identified for this decision.

Component: VI

Prerequisites

  • Environment per Before You Apply This Guidance
  • 4 reserved mgmt IPs (3 Controllers + 1 cluster VIP)
  • Functioning DNS
  • vCenter and NSX-T service accounts with AviRole
  • Content Library (one in mgmt domain for Controller OVA; one per VI WLD for SE OVA)
  • Easy Deploy Appliance

Implementation Procedure

Implementation

DescriptionVMware Flings automation appliance deployed in mgmt domain; provides web interface (https://easy_deploy_ip/menu) to orchestrate Avi deployment for VCF

Steps

Download Easy Deploy OVA from flings.vmware.com

Upload Easy Deploy OVA to Content Library (sfo-m01-avic)

  • Deploy Easy Deploy VM (sfo-m01-easydeploy) to mgmt domain
  • Open https://<easy_deploy_ip>/menu
  • Upload Avi Controller image (via Customer Connect or manual OVA)
  • Register VCF environment with SDDC Manager FQDN/credentials; receive Unlock Passphrase

Initialize deployment per WLD: select image, deployment size, datacenter/cluster/datastore, content library, credentials, cluster option (3-node), DNS, network port group, network/CIDR, gateway

Provide 3 Controller IPs + cluster VIP

Deploy (takes up to 1 hour); rollback available on failure

Manual Deployment

Deploy Avi Controller VMs (3) from OVA to mgmt domain (sizing: 8 vCPU, 24 GB RAM, 208 GB disk, 8×base clock CPU reservation, 24 GB mem reservation)

Power on Controllers; access first via HTTPS; create admin account

Configure DNS, NTP, SMTP (from=admin@avicontroller.net)

Tenant Settings: 'Share IP route domain across tenants'; SEs managed within Provider; tenant SE access Read

Navigate Administration > Controller > Edit; Name cluster; provide cluster IP + node IPs; save

Replace Portal Certificate (Templates > Security > SSL/TLS Certificates > Create > Controller Certificate > CSR)

Replace Secure Channel Certificate

Apply license (Enterprise with Cloud Services preferred; Cloud Services registration; or paste license keys for Enterprise/Basic)

Setup alerting: Syslog (to vRealize Log Insight with Avi content pack), Email, SNMP, Control Scripts (Enterprise only)

Create Tenants (Option 1: config isolation; Option 2: config+data isolation via CLI)

Create NSX-T Cloud Connector for each TZ requiring LB

Create Service Engine Group(s) per tenant/WLD

  • Deploy sample load-balanced application to verify
  • Tenant Creation CLI
  • Option 1 (config isolation only): CLI commands create Tenant
  • Option 2 (config + data isolation): CLI commands
  • Se Group Creation Settings

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

NameRole

As needed

VI AdminSystem Administrator / Tenant Admin (Enterprise Administrator)

As needed

Security AdminSecurity-scoped role

As needed

Tenant AdminEnterprise Administrator within tenant

As needed

Operational Verification

As needed

Controller

As needed

NSX T Cloud Connector

As needed

Certificate Management

As needed

Monitoring Points

  • Verify all 3 Controllers show State=Active in Administration > Controller
  • Verify cluster VIP reachable
  • Verify system health dashboards
  • Verify Cloud Connector shows Ready state
  • Verify SE image uploaded to VI WLD Content Library
  • Verify test SE deployment succeeds
  • Monitoring And AlertingAVI-CTLR-035: enable System alerts (VS, SSL, SE, Controller, CC). Integrate with Aria Operations for Logs via syslog (Avi conte

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Initializing more than one Controller before cluster formation (AVI-CTLR-001) — cluster creation will fail
Impact:
Mitigation:
Failing to replace Secure Channel Certificate — future SEs trust the default self-signed cert
Impact:
Mitigation:
Single Controller Content Library but no SE Content Library in VI WLD — SE deployment fails
Impact:
Mitigation:
Exceeding 10 ms latency between Controllers (quorum loss)
Impact:
Mitigation:
Multi-AZ: Controllers + SEs in first AZ with DRS/HA failover
Impact:
Mitigation:

Trade-off Analysis

Tenancy strategy (config vs. config+data isolation) — trade-off of isolation vs. SE resource consumption

Chosen:

Justification:

Trade-Offs Analysis

Chosen:

Justification:

Tenancy: no isolation (admin), config isolation (shared SEs), or full isolation (dedicated SEs) — resource vs. blast radius

Chosen:

Justification:

Active/Active (elastic) vs. Legacy Active/Standby (client IP preserved)

Chosen:

Justification:

Basic Edition (NSX LB replacement) vs. Enterprise (full feature set + Cloud Services)

Chosen:

Justification:

Quiz — Advanced Load Balancing

0/15
Q1
In VCF, where are the Avi Load Balancer Controllers deployed?
  • VI workload domain
  • Management domain
  • Edge workload domain
  • Dedicated NSX Manager cluster
AVI-VI-VC-010: Controllers deploy in the VCF management network/domain. SEs deploy in VI or Edge WLDs.
Q2
The maximum Service Engines per Avi Controller cluster is:
  • 50
  • 100
  • 200
  • 400
Design objective: up to 400 Service Engines per Controller cluster.
Q3
What is the Controller-to-Controller latency requirement?
  • <5 ms
  • <10 ms
  • <25 ms
  • <75 ms
AVI-CTLR-024: quorum requires <10 ms between Controllers.
Q4
What is the Controller-to-Service Engine latency requirement?
  • <10 ms
  • <25 ms
  • <50 ms
  • <75 ms
AVI-CTLR-025: heartbeats/data sync requires <75 ms.
Q5
NSX-T Cloud Connector scope is:
  • Per NSX Manager only
  • Per vCenter only
  • Per NSX Manager + transport zone
  • Per VLAN
NSX-T Cloud Connector is scoped to an NSX Manager cluster endpoint + an NSX transport zone.
Q6
Which feature is ONLY available in Enterprise Edition (not Basic)?
  • Load balancing
  • Active/Active SE HA
  • HTTPS listener
  • Self-signed cert replacement
AVI-CTLR-020: Basic Edition only supports Legacy Active/Standby; Active/Active requires Enterprise.
Q7
For an overlay-backed NSX-T Cloud Connector, how many segments per Tier-1?
  • Multiple segments per Tier-1
  • One segment per Tier-1 for data networks
  • Unlimited
  • Depends on MTU
AVI-CTLR-010: one overlay segment per Tier-1 router when used as a data network.
Q8
What should you do first in a maintenance window when upgrading both Avi and NSX-T?
  • Upgrade NSX-T first
  • Upgrade Avi first, check compatibility matrix
  • Upgrade simultaneously
  • Upgrade vCenter first
AVI-CTLR-028: upgrade Avi BEFORE NSX-T/vCenter to maintain Cloud Connector compatibility.
Q9
What port is used for secure key exchange between Controllers and SEs?
  • 22
  • 443
  • 8443
  • 9443
Port 8443/TCP is used for Controller-SE and Controller-Controller secure key exchange.
Q10
Which password rotation cadence is recommended for the Avi admin account?
  • Annually
  • Every 6 months
  • Every 3 months
  • Every 30 days
AVI-CTLR-031: rotate passwords at least every 3 months.
Q11
How many Controller nodes must be initialized when forming the cluster?
  • All 3
  • 2
  • 1
  • 0 (form auto)
AVI-CTLR-001: initialize only 1; the other 2 must be uninitialized to join the cluster.
Q12
Default SE storage footprint for VMware deployments:
  • 5 GB
  • 10 GB
  • 15 GB
  • 30 GB
15 GB is the default for SEs deployed in VMware clouds. Minimum formula: (2 × RAM) + 5 GB or 10 GB, whichever is greater.
Q13
What is the purpose of 'Dedicated Dispatcher CPU' setting?
  • Reserves CPU for management
  • Dedicates a core for packet processing on SEs with 4+ vCPU
  • Pins SE to a specific host
  • Increases memory reservation
AVI-CTLR-016: dedicates one core for packet processing on SEs with 4+ vCPUs, enabling high-PPS pipeline.
Q14
Which isolation tenancy mode is NOT available in Basic Edition?
  • Provider/Admin
  • Config isolation
  • Config + Data isolation
  • No isolation
Basic Edition does not provide tenant isolation; Enterprise supports Provider, Config isolation, and Config+Data isolation.
Q15
What is required for Avi Easy Deploy to orchestrate Avi deployment?
  • Root password on all ESXi hosts
  • SDDC Manager FQDN and credentials
  • vCenter SSO admin only
  • Avi license file
Easy Deploy registers with the SDDC Manager using its FQDN and credentials, then generates an Unlock Passphrase for encrypted VCF registration data.

Flashcards — Advanced Load Balancing

Card 1 of 15
Avi Controller cluster size and quorum
3-node cluster; 2 of 3 nodes must be up for control plane. Leader election; cluster VIP floats to leader.

Labs

Deploy Avi Controller Cluster Using Easy Deploy

Use VMware Easy Deploy Fling to orchestrate a 3-node Avi Controller cluster in a VCF management domain integrated with a VI workload domain's NSX-T and vCenter.

Starting State: Healthy VCF 5.2 with VI WLD; SDDC Manager admin creds; 4 reserved mgmt IPs; functioning DNS; Avi OVA available via Customer Connect.

Create Tenants, NSX-T Cloud Connector, and SE Groups

Configure Avi infrastructure: create tenants for isolation, NSX-T Cloud Connector for a VI WLD transport zone, and Service Engine Groups with Active/Active HA.

Starting State: Avi Controller cluster deployed; vCenter + NSX-T service accounts (AviRole) created; SE Content Library on target VI WLD.

Deploy a Sample Load-Balanced Application

Create a Virtual Service for a web application on an NSX overlay segment using Active/Active SE placement, HTTPS with CA-signed cert, and health monitors.

Starting State: Cloud Connector Ready; SE Group with Active/Active HA; back-end web servers (2+) running on NSX overlay segment accessible from Tier-1.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.