Academy/VVS/Cross Cloud Mobility
This solution targets VCF 5.2

Cross Cloud Mobility for VMware Cloud Foundation

VCF 5.2architectvcdxautomationPages 826-861

Establishes business workload mobility and migrates workloads between a VMware Cloud Foundation instance and a VMware Cloud on AWS SDDC using the VMware HCX service. HCX extends on-premises networks to VMware Cloud on AWS, enabling live migration with no re-IP. Main objective is to provide the ability to move business workloads between an on-premises VCF platform and a VMware Cloud platform (hybrid cloud).

Key Components: NSX, vCenter, ESXi

Logical Design: Two-site hybrid: VMware Cloud Foundation (on-premises private cloud) with vCenter Server, ESXi clusters, and HCX Connector appliance; VMware Cloud on AWS (public cloud) with vCenter Server, ESXi clusters, and HCX Manager (HCX Cloud). A unidirectional site pairing is created from the on-prem HCX Connector to HCX Cloud, and a Service Mesh deploys interconnect-dedicated HCX appliances at each site to provide network extension, vMotion, bulk migration, and replication services.

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

27 design decisions

DD-IDDecisionQuality
CCM-CDP-CFG-001Deploy HCX Connector appliance in default management vSphere clusterManageabilitySecurity

Decision: Deploy HCX Connector appliance in default management vSphere cluster

Rationale: Required for secure communication between VCF instance and VMware HCX

Implication: HCX Connector must connect to the Internet through a firewall

Component: CDP

CCM-CDP-CFG-002Protect HCX Connector with vSphere HAAvailability

Decision: Protect HCX Connector with vSphere HA

Rationale: Supports availability objective without manual intervention during ESXi host failure

Implication: No significant trade-offs identified for this decision.

Component: CDP

CCM-CDP-CFG-003Place HCX Connector in designated VM folderManageability

Decision: Place HCX Connector in designated VM folder

Rationale: Organizes appliances in management domain vSphere inventory

Implication: Must create VM folder before or during deployment

Component: CDP

CCM-CDP-CFG-004In multi-AZ, add HCX Connector to first AZ VM groupManageability

Decision: In multi-AZ, add HCX Connector to first AZ VM group

Rationale: Ensures HCX Connector runs on primary AZ hosts group

Implication: Must update VM group after second AZ implementation

Component: CDP

CCM-CDP-NET-001Place HCX Connector on management VLANManageability

Decision: Place HCX Connector on management VLAN

Rationale: Same network as VCF components; consistent deployment model

Implication: No significant trade-offs identified for this decision.

Component: CDP

CCM-CDP-NET-002Allocate statically assigned IPs from management VLANManageability

Decision: Allocate statically assigned IPs from management VLAN

Rationale: Deployment stability and simplified maintenance

Implication: Requires precise IP address management

Component: CDP

CCM-CDP-NET-003Configure forward and reverse DNS records for HCX ConnectorSecurity

Decision: Configure forward and reverse DNS records for HCX Connector

Rationale: Access via FQDN instead of IP only

Implication: DNS record required; firewalls must allow DNS traffic

Component: CDP

CCM-CDP-NET-004Configure DNS servers on HCX ConnectorAvailabilitySecurity

Decision: Configure DNS servers on HCX Connector

Rationale: Accurate name resolution

Implication: HA DNS infrastructure required; firewall rules for DNS; two or more DNS servers required

Component: CDP

CCM-CDP-NET-005Configure NTP servers for HCX ConnectorAvailabilitySecurity

Decision: Configure NTP servers for HCX Connector

Rationale: Accurate time sync; prevent time mismatch with dependencies

Implication: HA NTP infrastructure; firewall rules for NTP; two or more NTP servers required

Component: CDP

CCM-AWS-CFG-001Deploy VMware Cloud on AWS mobility SDDC with minimum of 2 nodesManageability

Decision: Deploy VMware Cloud on AWS mobility SDDC with minimum of 2 nodes

Rationale: Pre-provisioned mobility SDDC remains available; single-node expires after 60 days

Implication: Pre-provisioned SDDC incurs regular charge

Component: AWS

CCM-AWS-CFG-002Configure management gateway to allow access to mobility SDDC vCenter over InternetManageability

Decision: Configure management gateway to allow access to mobility SDDC vCenter over Internet

Rationale: Users can access vCenter UI over Internet

Implication: Must manually manage access using NSX group

Component: AWS

CCM-HCX-CFG-001Register HCX Connector with VI workload domain vCenter ServerManageability

Decision: Register HCX Connector with VI workload domain vCenter Server

Rationale: Installs HCX plug-ins for vCenter integration

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-002Register HCX Connector with VI workload domain NSX ManagerManageability

Decision: Register HCX Connector with VI workload domain NSX Manager

Rationale: Required to enable networking configuration

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-003Register HCX Connector with SSO domain of VI workload domain vCenterManageability

Decision: Register HCX Connector with SSO domain of VI workload domain vCenter

Rationale: Creates dedicated VMware HCX roles within vCenter

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-004Pair HCX Connector with HCX Cloud serviceSecurity

Decision: Pair HCX Connector with HCX Cloud service

Rationale: Establishes unidirectional communication for Service Mesh

Implication: HCX Connector must reach Internet via firewall; proxy configuration is external to this solution

Component: HCX

CCM-HCX-CFG-005Create management network profile with Management and HCX Uplink traffic typesManageability

Decision: Create management network profile with Management and HCX Uplink traffic types

Rationale: Provides management network configuration for HCX service appliances

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-006Assign management network profile pool of 5 IPs from VI workload domain management VLANManageability

Decision: Assign management network profile pool of 5 IPs from VI workload domain management VLAN

Rationale: Dynamic IP assignment to HCX service appliances

Implication: Requires static IP pool from management VLAN

Component: HCX

CCM-HCX-CFG-007Create vMotion network profile with vMotion traffic typeManageability

Decision: Create vMotion network profile with vMotion traffic type

Rationale: Provides vMotion network for HCX service appliances

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-008Assign vMotion network profile pool of 5 IPs from VI workload domain vMotion VLANManageability

Decision: Assign vMotion network profile pool of 5 IPs from VI workload domain vMotion VLAN

Rationale: Dynamic IP assignment

Implication: Requires static IP pool from vMotion VLAN

Component: HCX

CCM-HCX-CFG-009Create compute profile activating all available HCX servicesManageability

Decision: Create compute profile activating all available HCX services

Rationale: Defines compute/storage/network used by Service Mesh

Implication: Services activated depend on HCX license applied

Component: HCX

CCM-HCX-CFG-010Assign VI workload domain cluster to compute profileManageability

Decision: Assign VI workload domain cluster to compute profile

Rationale: Provides compute capacity for interconnect appliances

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-011Assign vSphere resource pool as compute profile containerManageability

Decision: Assign vSphere resource pool as compute profile container

Rationale: Groups interconnect appliances with resource priorities

Implication: Must create resource pool before configuration

Component: HCX

CCM-HCX-CFG-012Assign VM folder as compute profile containerManageability

Decision: Assign VM folder as compute profile container

Rationale: Organizes appliances in inventory

Implication: Must create VM folder before configuration

Component: HCX

CCM-HCX-CFG-013Assign management and vMotion network profiles to compute profileManageability

Decision: Assign management and vMotion network profiles to compute profile

Rationale: Network settings for interconnect appliances

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-HCX-CFG-014Create Service Mesh between VCF instance and VMware Cloud on AWS SDDCManageability

Decision: Create Service Mesh between VCF instance and VMware Cloud on AWS SDDC

Rationale: Provides interconnect enabling network extension without re-IP

Implication: No significant trade-offs identified for this decision.

Component: HCX

CCM-CDP-LCM-001Manually upgrade HCX Connector using built-in toolsManageability

Decision: Manually upgrade HCX Connector using built-in tools

Rationale: Upgrade package must be downloaded and applied

Implication: No significant trade-offs identified for this decision.

Component: CDP

CCM-CDP-LCM-002Use VMware Cloud Services automatic over-the-air upgrade for HCX ConnectorManageability

Decision: Use VMware Cloud Services automatic over-the-air upgrade for HCX Connector

Rationale: Upgrades pushed automatically by HCX Cloud service

Implication: No significant trade-offs identified for this decision.

Component: CDP

Prerequisites

  • VCF version listed in Support Matrix
  • Environment configured per Before You Apply This Guidance
  • Cross Cloud Mobility tab of Planning and Preparation Workbook completed
  • Healthy VCF instance (see Operations Guide)
  • Required DNS forward/reverse records in place
  • Active Directory domain controllers available; service accounts created
  • Microsoft CA available; CertGenVVS utility downloaded
  • VMware Cloud on AWS account with Organization Owner/Administrator role
  • HCX licensed and available for download from Customer Connect
  • PowerShell Automation
  • Modules
  • PowerValidatedSolutions 2.12.0
  • VMware.PowerCLI 13.3.0
  • ImportExcel 7.8.9
  • PowerVCF 2.4.0
  • Menu Steps

Implementation Procedure

Implementation

Start PowerShell and create folder structure ($drive, $parentFolder, certificates, binaries, generatedJsons)
Start-ValidatedSolutionMenu with protectedWorkbook path

Enter 13. (CCM) Cross Cloud Mobility

  1. Generate JSON Specification File
  2. Verify Prerequisites
  3. End-to-End Deployment
  4. Configuration (solution interoperability)

UI Implementation Steps

Define custom role in vSphere for HCX integration (least privilege)

Configure service account permissions in vCenter Server

Create VM & Template folder for HCX Connector on management domain vCenter

Create VM & Template folder and resource pool on VI workload domain vCenter for auto-deployed HCX appliances

Configure service account permissions in NSX Manager (HCX-to-NSX integration)

Deploy HCX Connector appliance OVA to management domain

Replace HCX Connector self-signed certificate with CA-signed cert

(If multi-AZ) Add HCX Connector appliance to first AZ VM group

Pair on-premises vSphere with HCX Cloud (unidirectional site pairing)

Create Network Profiles (management and vMotion, with IP pools)

Create Compute Profile in HCX (activate all services, VI WLD cluster as resource, resource pool, VM folder, both network profiles)
Create Service Mesh between VCF instance and VMware Cloud on AWS HCX Cloud

High Level Stages

  1. Plan and prepare VCF environment (P&P Workbook)
  2. Prepare VCF instance (define custom vSphere role, configure service account permissions, create VM folder)
  3. Configure VMware Cloud on AWS (deploy mobility SDDC, configure vCenter Server access)
  4. Configure VMware HCX (deploy HCX to VMC on AWS, deploy HCX Connector appliance, replace self-signed certificate, site pairing, create network profiles, create compute profile, create Service Mesh)

External Services / Integration Points

  • Active Directory (authentication/authorization)
  • DNS
  • NTP

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

Name: Cloud Admin

As needed

NameCloud Admin

As needed

ResponsibilityAdmin access to solution environment

As needed

Roles

As needed

Organization Owner

As needed

VMware Cloud on AWS Administrator

As needed

VMware Cloud on AWS NSX Cloud Admin

As needed

VMware HCX Administrator

As needed

Monitoring Points

  • Verify VMware Cloud Services status page: HCX service and SDDC region operational
  • Verify HCX Service Mesh via vSphere Client > HCX > Interconnect > Service Mesh tab; all hexagons green
  • Verify operational state
  • MonitoringConfigure monitoring/alerting via adjacent VVS (see VMware Cloud Foundation Validated Solutions).

Troubleshooting

Run diagnostics from Service Mesh More menu if issues
Cause:
Fix:
Config File/etc/security/faillock.conf
Cause:
Fix:

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Failure Scenarios

Multi-AZ: VM/Host rule pins appliance to first AZ; vSphere HA recovers in AZ failure
Impact:
Mitigation:
Internet dependency: HCX Connector outage if firewall breaks egress to HCX Cloud
Impact:
Mitigation:

Trade-off Analysis

Minimum 2-node mobility SDDC to avoid 60-day expiration of 1-node SDDC (CCM-AWS-CFG-001) — trade-off: cost vs. permanence

Chosen:

Justification:

Manual LCM of HCX Connector vs. automated OTA of HCX Cloud creates operational asymmetry to be managed

Chosen:

Justification:

Trade-Offs Analysis

Chosen:

Justification:

Cost of mobility SDDC (always-on charge) vs. 60-day expiration of 1-node SDDC

Chosen:

Justification:

Overlay NSX-backed extension (preferred for feature richness) vs. more IP pool consumption as network containers grow

Chosen:

Justification:

Quiz — Cross Cloud Mobility

0/15
Q1
In Cross Cloud Mobility, where is the HCX Connector appliance deployed?
  • VI workload domain default cluster
  • Management domain default vSphere cluster
  • VMware Cloud on AWS SDDC
  • Dedicated edge workload domain
Per CCM-CDP-CFG-001, the HCX Connector is deployed in the default management vSphere cluster to establish secure communication between VCF and HCX.
Q2
What is the minimum node count recommended for a VMware Cloud on AWS mobility SDDC?
  • 1 node
  • 2 nodes
  • 3 nodes
  • 4 nodes
CCM-AWS-CFG-001: deploy a minimum of two nodes; a single-node SDDC expires after 60 days.
Q3
Which traffic types are assigned to the HCX management network profile?
  • Management only
  • vMotion only
  • Management and HCX Uplink
  • All four traffic types
CCM-HCX-CFG-005 assigns Management and HCX Uplink traffic types to the management network profile; vMotion is a separate profile.
Q4
How many static IPs must be allocated per HCX network profile IP pool?
  • 3
  • 5
  • 10
  • Varies — at least 5 per profile
Design decisions CCM-HCX-CFG-006 and -008 assign pools of 5 IPs each for management and vMotion; the exact count depends on scale.
Q5
Which direction is HCX site pairing established in this solution?
  • Bidirectional
  • Unidirectional from HCX Cloud to HCX Connector
  • Unidirectional from HCX Connector to HCX Cloud
  • Mesh
CCM-HCX-CFG-004: HCX Connector pairs unidirectionally outbound to HCX Cloud, simplifying firewall egress design.
Q6
What is replaced on the HCX Connector after deployment for secure connectivity?
  • SSH host keys
  • Self-signed certificate with CA-signed certificate
  • NTP configuration
  • Root password
The self-signed HCX Connector certificate is replaced with a CA-signed (root + intermediate) certificate, generated via CertGenVVS.
Q7
For multi-AZ deployments, what must you do with the HCX Connector appliance after the second AZ is activated?
  • Clone it to AZ2
  • Add it to the first AZ VM group
  • Deploy a second HCX Connector in AZ2
  • No action needed
CCM-CDP-CFG-004 requires adding the HCX Connector to the first AZ VM group to ensure it runs on primary AZ hosts.
Q8
Which component of HCX provides automatic over-the-air updates?
  • HCX Connector
  • HCX Cloud service
  • HCX Interconnect appliance
  • HCX Network Extension appliance
CCM-CDP-LCM-002: HCX Cloud automatically pushes OTA updates; HCX Connector requires manual upgrade per CCM-CDP-LCM-001.
Q9
What menu option in the Validated Solution PowerShell menu initiates Cross Cloud Mobility configuration?
  • 05
  • 11
  • 13
  • 07
Option 13. (CCM) Cross Cloud Mobility is the entry for the Cross Cloud Mobility solution.
Q10
Which construct abstracts a distributed port group, standard port group, or NSX logical switch for HCX appliance placement?
  • Compute profile
  • Network profile
  • Service Mesh
  • Site pair
A network profile is an abstraction of a port group (or logical switch) plus Layer 3 properties; it is a sub-component of a compute profile.
Q11
What happens at shutdown of the full VCF stack with HCX Connector?
  • HCX Connector shuts down last
  • HCX Connector shuts down first
  • HCX Connector is left running
  • Only HCX Cloud shuts down
HCX Connector is the first VM to shut down and the last to start up per VCF shutdown/startup order.
Q12
The HCX Connector appliance local 'admin' account default maxdays password expiration setting is:
  • 0
  • 90
  • -1 (never expires)
  • 99999
Per Table 610, the admin user has maxdays=-1 (never expires) by default; root has maxdays=99999.
Q13
Which two external services are required for HCX Connector backups?
  • vCenter snapshots and Veeam
  • FTP or SFTP servers
  • Azure Blob and AWS S3
  • NFS and iSCSI
HCX Connector supports backups to FTP/SFTP servers with schedule configuration.
Q14
Which HCX registration enables the creation of dedicated HCX roles in vCenter Server?
  • Registration with vCenter only
  • Registration with NSX Manager
  • Registration with the SSO domain of the VI WLD vCenter
  • Registration with SDDC Manager
CCM-HCX-CFG-003: SSO registration enables dedicated VMware HCX roles inside vCenter.
Q15
What construct from NSX is consumed for network extension in this validated solution?
  • NSX VLAN transport zone
  • NSX Logical Overlay
  • NSX Edge uplink
  • NSX Federation
The solution consumes the NSX Logical Overlay construct for extending NSX logical segments via HCX.

Flashcards — Cross Cloud Mobility

Card 1 of 15
What does HCX Connector do?
Deployed in the on-premises VCF management domain; manages communication between VCF and the HCX Manager in VMware Cloud on AWS. Unidirectional site pair is initiated from Connector to HCX Cloud.

Labs

Deploy HCX Connector and Site-Pair to HCX Cloud

Deploy HCX Connector in management domain, register with vCenter/NSX/SSO, apply CA-signed cert, and establish unidirectional site pair with HCX Cloud on a VMC on AWS mobility SDDC.

Starting State: Healthy VCF 5.2 instance with VI workload domain; mobility SDDC deployed on VMC on AWS (2+ nodes); CertGenVVS utility ready; AD service accounts created; DNS A/PTR records in place.

Build a Service Mesh for Cross Cloud Mobility

Create management and vMotion network profiles, compute profile, and Service Mesh with all HCX services activated.

Starting State: Site pair established. VM folder and resource pool exist on VI WLD vCenter. Static IP pool of 5 addresses reserved from management VLAN and 5 from vMotion VLAN.

Password Policy Hardening of HCX Connector

Configure password expiration, complexity, and lockout policies on the HCX Connector per organizational security standards.

Starting State: HCX Connector deployed and operational; SSH access as admin enabled.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.