Cross Cloud Mobility for VMware Cloud Foundation
Establishes business workload mobility and migrates workloads between a VMware Cloud Foundation instance and a VMware Cloud on AWS SDDC using the VMware HCX service. HCX extends on-premises networks to VMware Cloud on AWS, enabling live migration with no re-IP. Main objective is to provide the ability to move business workloads between an on-premises VCF platform and a VMware Cloud platform (hybrid cloud).
Key Components: NSX, vCenter, ESXi
Logical Design: Two-site hybrid: VMware Cloud Foundation (on-premises private cloud) with vCenter Server, ESXi clusters, and HCX Connector appliance; VMware Cloud on AWS (public cloud) with vCenter Server, ESXi clusters, and HCX Manager (HCX Cloud). A unidirectional site pairing is created from the on-prem HCX Connector to HCX Cloud, and a Service Mesh deploys interconnect-dedicated HCX appliances at each site to provide network extension, vMotion, bulk migration, and replication services.
27 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| CCM-CDP-CFG-001 | Deploy HCX Connector appliance in default management vSphere cluster | ManageabilitySecurity |
Decision: Deploy HCX Connector appliance in default management vSphere cluster Rationale: Required for secure communication between VCF instance and VMware HCX Implication: HCX Connector must connect to the Internet through a firewall Component: CDP | ||
| CCM-CDP-CFG-002 | Protect HCX Connector with vSphere HA | Availability |
Decision: Protect HCX Connector with vSphere HA Rationale: Supports availability objective without manual intervention during ESXi host failure Implication: No significant trade-offs identified for this decision. Component: CDP | ||
| CCM-CDP-CFG-003 | Place HCX Connector in designated VM folder | Manageability |
Decision: Place HCX Connector in designated VM folder Rationale: Organizes appliances in management domain vSphere inventory Implication: Must create VM folder before or during deployment Component: CDP | ||
| CCM-CDP-CFG-004 | In multi-AZ, add HCX Connector to first AZ VM group | Manageability |
Decision: In multi-AZ, add HCX Connector to first AZ VM group Rationale: Ensures HCX Connector runs on primary AZ hosts group Implication: Must update VM group after second AZ implementation Component: CDP | ||
| CCM-CDP-NET-001 | Place HCX Connector on management VLAN | Manageability |
Decision: Place HCX Connector on management VLAN Rationale: Same network as VCF components; consistent deployment model Implication: No significant trade-offs identified for this decision. Component: CDP | ||
| CCM-CDP-NET-002 | Allocate statically assigned IPs from management VLAN | Manageability |
Decision: Allocate statically assigned IPs from management VLAN Rationale: Deployment stability and simplified maintenance Implication: Requires precise IP address management Component: CDP | ||
| CCM-CDP-NET-003 | Configure forward and reverse DNS records for HCX Connector | Security |
Decision: Configure forward and reverse DNS records for HCX Connector Rationale: Access via FQDN instead of IP only Implication: DNS record required; firewalls must allow DNS traffic Component: CDP | ||
| CCM-CDP-NET-004 | Configure DNS servers on HCX Connector | AvailabilitySecurity |
Decision: Configure DNS servers on HCX Connector Rationale: Accurate name resolution Implication: HA DNS infrastructure required; firewall rules for DNS; two or more DNS servers required Component: CDP | ||
| CCM-CDP-NET-005 | Configure NTP servers for HCX Connector | AvailabilitySecurity |
Decision: Configure NTP servers for HCX Connector Rationale: Accurate time sync; prevent time mismatch with dependencies Implication: HA NTP infrastructure; firewall rules for NTP; two or more NTP servers required Component: CDP | ||
| CCM-AWS-CFG-001 | Deploy VMware Cloud on AWS mobility SDDC with minimum of 2 nodes | Manageability |
Decision: Deploy VMware Cloud on AWS mobility SDDC with minimum of 2 nodes Rationale: Pre-provisioned mobility SDDC remains available; single-node expires after 60 days Implication: Pre-provisioned SDDC incurs regular charge Component: AWS | ||
| CCM-AWS-CFG-002 | Configure management gateway to allow access to mobility SDDC vCenter over Internet | Manageability |
Decision: Configure management gateway to allow access to mobility SDDC vCenter over Internet Rationale: Users can access vCenter UI over Internet Implication: Must manually manage access using NSX group Component: AWS | ||
| CCM-HCX-CFG-001 | Register HCX Connector with VI workload domain vCenter Server | Manageability |
Decision: Register HCX Connector with VI workload domain vCenter Server Rationale: Installs HCX plug-ins for vCenter integration Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-002 | Register HCX Connector with VI workload domain NSX Manager | Manageability |
Decision: Register HCX Connector with VI workload domain NSX Manager Rationale: Required to enable networking configuration Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-003 | Register HCX Connector with SSO domain of VI workload domain vCenter | Manageability |
Decision: Register HCX Connector with SSO domain of VI workload domain vCenter Rationale: Creates dedicated VMware HCX roles within vCenter Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-004 | Pair HCX Connector with HCX Cloud service | Security |
Decision: Pair HCX Connector with HCX Cloud service Rationale: Establishes unidirectional communication for Service Mesh Implication: HCX Connector must reach Internet via firewall; proxy configuration is external to this solution Component: HCX | ||
| CCM-HCX-CFG-005 | Create management network profile with Management and HCX Uplink traffic types | Manageability |
Decision: Create management network profile with Management and HCX Uplink traffic types Rationale: Provides management network configuration for HCX service appliances Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-006 | Assign management network profile pool of 5 IPs from VI workload domain management VLAN | Manageability |
Decision: Assign management network profile pool of 5 IPs from VI workload domain management VLAN Rationale: Dynamic IP assignment to HCX service appliances Implication: Requires static IP pool from management VLAN Component: HCX | ||
| CCM-HCX-CFG-007 | Create vMotion network profile with vMotion traffic type | Manageability |
Decision: Create vMotion network profile with vMotion traffic type Rationale: Provides vMotion network for HCX service appliances Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-008 | Assign vMotion network profile pool of 5 IPs from VI workload domain vMotion VLAN | Manageability |
Decision: Assign vMotion network profile pool of 5 IPs from VI workload domain vMotion VLAN Rationale: Dynamic IP assignment Implication: Requires static IP pool from vMotion VLAN Component: HCX | ||
| CCM-HCX-CFG-009 | Create compute profile activating all available HCX services | Manageability |
Decision: Create compute profile activating all available HCX services Rationale: Defines compute/storage/network used by Service Mesh Implication: Services activated depend on HCX license applied Component: HCX | ||
| CCM-HCX-CFG-010 | Assign VI workload domain cluster to compute profile | Manageability |
Decision: Assign VI workload domain cluster to compute profile Rationale: Provides compute capacity for interconnect appliances Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-011 | Assign vSphere resource pool as compute profile container | Manageability |
Decision: Assign vSphere resource pool as compute profile container Rationale: Groups interconnect appliances with resource priorities Implication: Must create resource pool before configuration Component: HCX | ||
| CCM-HCX-CFG-012 | Assign VM folder as compute profile container | Manageability |
Decision: Assign VM folder as compute profile container Rationale: Organizes appliances in inventory Implication: Must create VM folder before configuration Component: HCX | ||
| CCM-HCX-CFG-013 | Assign management and vMotion network profiles to compute profile | Manageability |
Decision: Assign management and vMotion network profiles to compute profile Rationale: Network settings for interconnect appliances Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-HCX-CFG-014 | Create Service Mesh between VCF instance and VMware Cloud on AWS SDDC | Manageability |
Decision: Create Service Mesh between VCF instance and VMware Cloud on AWS SDDC Rationale: Provides interconnect enabling network extension without re-IP Implication: No significant trade-offs identified for this decision. Component: HCX | ||
| CCM-CDP-LCM-001 | Manually upgrade HCX Connector using built-in tools | Manageability |
Decision: Manually upgrade HCX Connector using built-in tools Rationale: Upgrade package must be downloaded and applied Implication: No significant trade-offs identified for this decision. Component: CDP | ||
| CCM-CDP-LCM-002 | Use VMware Cloud Services automatic over-the-air upgrade for HCX Connector | Manageability |
Decision: Use VMware Cloud Services automatic over-the-air upgrade for HCX Connector Rationale: Upgrades pushed automatically by HCX Cloud service Implication: No significant trade-offs identified for this decision. Component: CDP | ||
Prerequisites
- VCF version listed in Support Matrix
- Environment configured per Before You Apply This Guidance
- Cross Cloud Mobility tab of Planning and Preparation Workbook completed
- Healthy VCF instance (see Operations Guide)
- Required DNS forward/reverse records in place
- Active Directory domain controllers available; service accounts created
- Microsoft CA available; CertGenVVS utility downloaded
- VMware Cloud on AWS account with Organization Owner/Administrator role
- HCX licensed and available for download from Customer Connect
- PowerShell Automation
- Modules
- PowerValidatedSolutions 2.12.0
- VMware.PowerCLI 13.3.0
- ImportExcel 7.8.9
- PowerVCF 2.4.0
- Menu Steps
Implementation Procedure
Implementation
Start PowerShell and create folder structure ($drive, $parentFolder, certificates, binaries, generatedJsons)
Start-ValidatedSolutionMenu with protectedWorkbook path
Enter 13. (CCM) Cross Cloud Mobility
- Generate JSON Specification File
- Verify Prerequisites
- End-to-End Deployment
- Configuration (solution interoperability)
UI Implementation Steps
Define custom role in vSphere for HCX integration (least privilege)
Configure service account permissions in vCenter Server
Create VM & Template folder for HCX Connector on management domain vCenter
Create VM & Template folder and resource pool on VI workload domain vCenter for auto-deployed HCX appliances
Configure service account permissions in NSX Manager (HCX-to-NSX integration)
Deploy HCX Connector appliance OVA to management domain
Replace HCX Connector self-signed certificate with CA-signed cert
(If multi-AZ) Add HCX Connector appliance to first AZ VM group
Pair on-premises vSphere with HCX Cloud (unidirectional site pairing)
Create Network Profiles (management and vMotion, with IP pools)
Create Compute Profile in HCX (activate all services, VI WLD cluster as resource, resource pool, VM folder, both network profiles)
Create Service Mesh between VCF instance and VMware Cloud on AWS HCX Cloud
High Level Stages
- Plan and prepare VCF environment (P&P Workbook)
- Prepare VCF instance (define custom vSphere role, configure service account permissions, create VM folder)
- Configure VMware Cloud on AWS (deploy mobility SDDC, configure vCenter Server access)
- Configure VMware HCX (deploy HCX to VMC on AWS, deploy HCX Connector appliance, replace self-signed certificate, site pairing, create network profiles, create compute profile, create Service Mesh)
External Services / Integration Points
- Active Directory (authentication/authorization)
- DNS
- NTP
Day-2 Operations Tasks
Operations
As neededPersonas
As neededName: Cloud Admin
As neededNameCloud Admin
As neededResponsibilityAdmin access to solution environment
As neededRoles
As neededOrganization Owner
As neededVMware Cloud on AWS Administrator
As neededVMware Cloud on AWS NSX Cloud Admin
As neededVMware HCX Administrator
As neededMonitoring Points
- Verify VMware Cloud Services status page: HCX service and SDDC region operational
- Verify HCX Service Mesh via vSphere Client > HCX > Interconnect > Service Mesh tab; all hexagons green
- Verify operational state
- MonitoringConfigure monitoring/alerting via adjacent VVS (see VMware Cloud Foundation Validated Solutions).
Troubleshooting
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Failure Scenarios
Trade-off Analysis
Minimum 2-node mobility SDDC to avoid 60-day expiration of 1-node SDDC (CCM-AWS-CFG-001) — trade-off: cost vs. permanence
Chosen:
Justification:
Manual LCM of HCX Connector vs. automated OTA of HCX Cloud creates operational asymmetry to be managed
Chosen:
Justification:
Trade-Offs Analysis
Chosen:
Justification:
Cost of mobility SDDC (always-on charge) vs. 60-day expiration of 1-node SDDC
Chosen:
Justification:
Overlay NSX-backed extension (preferred for feature richness) vs. more IP pool consumption as network containers grow
Chosen:
Justification:
Quiz — Cross Cloud Mobility
- VI workload domain default cluster
- Management domain default vSphere cluster
- VMware Cloud on AWS SDDC
- Dedicated edge workload domain
- 1 node
- 2 nodes
- 3 nodes
- 4 nodes
- Management only
- vMotion only
- Management and HCX Uplink
- All four traffic types
- 3
- 5
- 10
- Varies — at least 5 per profile
- Bidirectional
- Unidirectional from HCX Cloud to HCX Connector
- Unidirectional from HCX Connector to HCX Cloud
- Mesh
- SSH host keys
- Self-signed certificate with CA-signed certificate
- NTP configuration
- Root password
- Clone it to AZ2
- Add it to the first AZ VM group
- Deploy a second HCX Connector in AZ2
- No action needed
- HCX Connector
- HCX Cloud service
- HCX Interconnect appliance
- HCX Network Extension appliance
- 05
- 11
- 13
- 07
- Compute profile
- Network profile
- Service Mesh
- Site pair
- HCX Connector shuts down last
- HCX Connector shuts down first
- HCX Connector is left running
- Only HCX Cloud shuts down
- 0
- 90
- -1 (never expires)
- 99999
- vCenter snapshots and Veeam
- FTP or SFTP servers
- Azure Blob and AWS S3
- NFS and iSCSI
- Registration with vCenter only
- Registration with NSX Manager
- Registration with the SSO domain of the VI WLD vCenter
- Registration with SDDC Manager
- NSX VLAN transport zone
- NSX Logical Overlay
- NSX Edge uplink
- NSX Federation
Flashcards — Cross Cloud Mobility
Labs
Deploy HCX Connector and Site-Pair to HCX Cloud
Deploy HCX Connector in management domain, register with vCenter/NSX/SSO, apply CA-signed cert, and establish unidirectional site pair with HCX Cloud on a VMC on AWS mobility SDDC.
Starting State: Healthy VCF 5.2 instance with VI workload domain; mobility SDDC deployed on VMC on AWS (2+ nodes); CertGenVVS utility ready; AD service accounts created; DNS A/PTR records in place.
Build a Service Mesh for Cross Cloud Mobility
Create management and vMotion network profiles, compute profile, and Service Mesh with all HCX services activated.
Starting State: Site pair established. VM folder and resource pool exist on VI WLD vCenter. Static IP pool of 5 addresses reserved from management VLAN and 5 from vMotion VLAN.
Password Policy Hardening of HCX Connector
Configure password expiration, complexity, and lockout policies on the HCX Connector per organizational security standards.
Starting State: HCX Connector deployed and operational; SSH access as admin enabled.