Academy/VVS/Network Visibility
This solution targets VCF 5.2

Intelligent Network Visibility for VMware Cloud Foundation

VCF 5.2architectvcdxnetworkautomationPages 436-480

VMware Aria Operations for Networks provides network monitoring, troubleshooting, and flow analysis across the SDDC. A single Extra-Large platform node (with option to scale to a cluster) is deployed on the cross-instance NSX segment, and one Large collector node per VCF instance is deployed on the local-instance NSX segment for data collection from vCenter Server (vSphere Distributed Switch NetFlow) and NSX Manager (IPFIX for distributed firewall).

Key Components: NSX, Aria Operations, SDDC Manager, vCenter, ESXi, Workspace ONE

Platform Nodes: Single Extra Large platform node on cross-instance NSX segment; option to scale to cluster.

Design Decisions
Implementation
Operations
VCDX Defense
Quiz (15)
Flashcards (15)

32 design decisions

DD-IDDecisionQuality
INV-VAON-CFG-019keeps 1-month default to minimize storage.Manageability

Decision: keeps 1-month default to minimize storage.

Rationale: Alert Notifications

Implication: INV-VAON-CFG-020: configure outbound SMTP for alerts to administrators/operators; select relevant system alerts.

Component: VAON

INV-VAON-CFG-020: configure outbound SMTP for alerts to administrators/operators; select relevant system alerts.Manageability

Decision: : configure outbound SMTP for alerts to administrators/operators; select relevant system alerts.

Rationale: Data Sources

Implication: vCenterConfigure vCenter data source per workload domain; enable NetFlow on each vSphere Distributed Switch (IPFIX) — Aria Ops for Networks auto-updates vDS settings.

Component: VAON

INV-VAON-CFG-001Deploy Aria Ops for Networks as non-clustered, single platform node in default mgmt cluster.Manageability

Decision: Deploy Aria Ops for Networks as non-clustered, single platform node in default mgmt cluster.

Rationale: Capacity for 10,000 VMs/objects; scale-out possible.

Implication: 100% CPU/RAM reservation for platform node.

Component: VAON

INV-VAON-CFG-002Deploy single collector node in default mgmt cluster.Manageability

Decision: Deploy single collector node in default mgmt cluster.

Rationale: Minimum 1 collector required to feed platform.

Implication: 100% CPU/RAM reservation for collector.

Component: VAON

INV-VAON-CFG-003Use Aria Suite Lifecycle in corresponding VCF instance to deploy.Manageability

Decision: Use Aria Suite Lifecycle in corresponding VCF instance to deploy.

Rationale: Lifecycle manages binaries; automated deployment.

Implication: Must deploy Aria Suite Lifecycle via SDDC Manager.

Component: VAON

INV-VAON-CFG-004Protect all nodes with vSphere HA.Availability

Decision: Protect all nodes with vSphere HA.

Rationale: Availability objective.

Implication: Ensure spare cluster capacity for HA.

Component: VAON

INV-VAON-CFG-005Place platform and collector nodes in dedicated VM folders.Manageability

Decision: Place platform and collector nodes in dedicated VM folders.

Rationale: Organization.

Implication: Create folders in vCenter.

Component: VAON

INV-VAON-CFG-007In multi-AZ, add VMs to first AZ VM group.Manageability

Decision: In multi-AZ, add VMs to first AZ VM group.

Rationale: Ensure AZ1 hosting.

Implication: Update VM group after stretched cluster creation.

Component: VAON

INV-VAON-CFG-008In multi-instance, deploy collector per instance using same Aria Suite Lifecycle environment.Manageability

Decision: In multi-instance, deploy collector per instance using same Aria Suite Lifecycle environment.

Rationale: Consistent deployment per instance.

Implication: Each collector registered with platform node.

Component: VAON

INV-VAON-CFG-010Deploy platform node with Extra Large brick.Manageability

Decision: Deploy platform node with Extra Large brick.

Rationale: Capacity for 10,000 VMs/8M flows; Network Verification & Assurance, Flow-based Application Discovery require XL.

Implication: More resources required in mgmt cluster.

Component: VAON

INV-VAON-CFG-011If VMs exceed 10,000 or object limits reached, scale out to platform cluster by adding nodes via AriManageability

Decision: If VMs exceed 10,000 or object limits reached, scale out to platform cluster by adding nodes via Aria Suite Lifecycle.

Rationale: Growth capacity.

Implication: Additional resources in mgmt cluster.

Component: VAON

INV-VAON-CFG-012Deploy collector as Large.Manageability

Decision: Deploy collector as Large.

Rationale: Sufficient for design-target flows; more can be added.

Implication: 8-10 vCPUs/16 GB per collector.

Component: VAON

INV-VAON-NET-001Platform nodes on cross-instance NSX segment.Manageability

Decision: Platform nodes on cross-instance NSX segment.

Rationale: Multi-instance DR support.

Implication: Requires NSX overlay.

Component: VAON

INV-VAON-NET-002Collector nodes on local-instance NSX segment.Manageability

Decision: Collector nodes on local-instance NSX segment.

Rationale: Local flow collection.

Implication: Requires NSX overlay.

Component: VAON

INV-VAON-NET-004Static IP addresses.Manageability

Decision: Static IP addresses.

Rationale: Reliability, conflict avoidance.

Implication: IP address management discipline.

Component: VAON

INV-VAON-NET-007Forward/reverse DNS for each node.Manageability

Decision: Forward/reverse DNS for each node.

Rationale: FQDN accessibility.

Implication: Maintain DNS records.

Component: VAON

INV-VAON-NET-008NTP on each node.AvailabilitySecurity

Decision: NTP on each node.

Rationale: Accurate time synchronization.

Implication: Requires redundant NTP; firewalls allow NTP.

Component: VAON

INV-VAON-LCM-001Use Aria Suite Lifecycle for LCM.Manageability

Decision: Use Aria Suite Lifecycle for LCM.

Rationale: Manages binaries and upgrades.

Implication: Aria Suite Lifecycle deployed via SDDC Manager.

Component: VAON

INV-VAON-CFG-013Configure vCenter data source per management/VI workload domain vCenter.Manageability

Decision: Configure vCenter data source per management/VI workload domain vCenter.

Rationale: Network visibility for vSphere networking.

Implication: Configure per region/domain.

Component: VAON

INV-VAON-CFG-014Enable NetFlow on each vSphere Distributed Switch.Manageability

Decision: Enable NetFlow on each vSphere Distributed Switch.

Rationale: IPFIX flow collection.

Implication: Aria Ops for Networks updates vDS NetFlow settings automatically.

Component: VAON

INV-VAON-CFG-015Configure NSX Manager data source per workload domain.Manageability

Decision: Configure NSX Manager data source per workload domain.

Rationale: NSX network visibility.

Implication: Per-region/domain configuration.

Component: VAON

INV-VAON-CFG-016Enable IPFIX for distributed firewall.Security

Decision: Enable IPFIX for distributed firewall.

Rationale: Flow collection via IPFIX.

Implication: DFW must be enabled; service account needs Enterprise Admin.

Component: VAON

INV-VAON-CFG-017Enable latency metric collection on NSX data source.Performance

Decision: Enable latency metric collection on NSX data source.

Rationale: Latency metrics from NSX Transport Nodes.

Implication: Allow TCP 1991 from ESXi to collector.

Component: VAON

INV-VAON-CFG-018Use NSX Local Manager as data source for NSX Federation environments.Manageability

Decision: Use NSX Local Manager as data source for NSX Federation environments.

Rationale: NSX Global Manager not supported as data source; Federation data fetched from Local Managers.

Implication: Configure per Local Manager.

Component: VAON

INV-VAON-SEC-001Limit local accounts, apply least privilege, assign service roles to AD groups.Manageability

Decision: Limit local accounts, apply least privilege, assign service roles to AD groups.

Rationale: Accountability and auditability.

Implication: Manage service accounts and groups in AD.

Component: VAON

INV-VAON-SEC-004Custom vCenter role with minimum privileges; AD service account per workload domain vCenter.Manageability

Decision: Custom vCenter role with minimum privileges; AD service account per workload domain vCenter.

Rationale: Least privilege integration.

Implication: Maintain role and service account.

Component: VAON

INV-VAON-SEC-006NSX client certificate credential with Enterprise Admin role.ManageabilitySecurity

Decision: NSX client certificate credential with Enterprise Admin role.

Rationale: Certificate-based, no password.

Implication: Manage certificates and keys.

Component: VAON

INV-VAON-SEC-007Configure local user password expiration/complexity/lockout.Manageability

Decision: Configure local user password expiration/complexity/lockout.

Rationale: Align with org/compliance.

Implication: Applies only to support/consoleuser; manage via appliance console.

Component: VAON

INV-VAON-SEC-010Rotate support and consoleuser passwords on schedule via Aria Suite Lifecycle.Manageability

Decision: Rotate support and consoleuser passwords on schedule via Aria Suite Lifecycle.

Rationale: Default expiration applies.

Implication: Manage per node.

Component: VAON

INV-VAON-SEC-011CA-signed cert with FQDNs of platform/collector in SAN.Security

Decision: CA-signed cert with FQDNs of platform/collector in SAN.

Rationale: Encrypted external UI/API.

Implication: Replace cert when adding nodes.

Component: VAON

INV-VAON-SEC-012Use SHA-2 or higher.Manageability

Decision: Use SHA-2 or higher.

Rationale: SHA-1 deprecated.

Implication: CA must support SHA-2+.

Component: VAON

INV-MON-IOM-001Add Ping adapter for platform (default collector group) and collector (local-instance collector grouAvailabilityManageability

Decision: Add Ping adapter for platform (default collector group) and collector (local-instance collector group).

Rationale: Availability metrics in Aria Operations.

Implication: Manual adapter addition.

Component: MON

Prerequisites

  • VCF management domain operational
  • DNS/NTP configured
  • CA infrastructure in place

Implementation Procedure

Implementation

VCF 5.2.x healthy; captured inputs in Intelligent Network Visibility tab of Planning & Preparation Workbook.

Aria Suite Lifecycle deployed; Workspace ONE Access clustered; Operations + Aria Automation optional.

Active Directory, DNS, NTP, CA in place; Aria Ops for Networks OVA downloaded.

Implementation Methods

Powershell

Use PowerValidatedSolutions module; menu entry for Intelligent Network Visibility (INV) — Generate JSON Spec → Verify Prereqs → Generate Cert → End-to-End Deployment → Configuration.

UI

Follow VCF version-specific Aria Suite Lifecycle deployment and WS1 Access integration (similar to IOM). Then: Add Aria Ops for Networks product in Aria Suite Lifecycle; deploy platform node on cross-instance segment; deploy collector per VCF instance on local-instance segment. Register collector with platform node. Configure vCenter data sources with custom role + AD service account (enable NetFlow on vDS). Configure NSX data sources with client cert (Enterprise Admin); enable IPFIX for DFW; enable latency metric collection. Configure SMTP and alert notifications. Configure user roles via WS1 Access integration. Replace cert; configure retention.

External Services / Integration Points

Active Directory (AD)

DNS

NTP

CA

Configuration Values

Data SourcesvCenter (NetFlow on vDS), NSX Local Manager (IPFIX for DFW, latency collection TCP 1991), NSX Federation uses Local Manager only

Retention1 month (default) for all categories

SmtpConfigure outbound SMTP in Aria Ops for Networks settings

Reservation100% CPU and RAM reservation automatically applied

Additional Instance

For additional VCF instance, add a collector node to the local-instance NSX segment, register with platform node, configure vCenter and NSX data sources for the new workload domains, enable NetFlow/IPFIX, allow TCP 1991 for latency.

Day-2 Operations Tasks

Operations

As needed

Personas

As needed

NameRole

As needed

Cloud AdminAria Ops for Networks Admin service role

As needed

Network OperatorAria Ops for Networks User

As needed

AuditorAria Ops for Networks Auditor (read-only)

As needed

Operational Verification

As needed

Certificate Management

As needed

Generate CA-signed cert including all FQDNs; import via Aria Suite Lifecycle or appliance UI; restart services.

As needed

Password Management

As needed

Monitoring Points

  • Verify platform node operational, data sources OK, flows visible, authentication via WS1 Access successful.
  • MonitoringPing adapters in Aria Operations for platform and collector nodes (INV-MON-IOM-001..003).

Troubleshooting

DRSupports DR via failover of platform node between VCF instances.
Cause:
Fix:

Likely Panelist Questions

Q: Why did you choose this architecture?

See design decisions for rationale

Trade-off Analysis

1-month retention default trades long-term analysis for storage efficiency.

Chosen:

Justification:

Trade-Offs Analysis

Chosen:

Justification:

Quiz — Network Visibility

0/15
Q1
Which brick size is required for Network Verification & Assurance?
  • Small
  • Medium
  • Large
  • Extra Large
INV-VAON-CFG-010: Extra Large brick is required for Network Verification & Assurance and Flow-based Application Discovery features.
Q2
Where is the platform node placed?
  • Local-instance NSX segment
  • Cross-instance NSX segment
  • Management VLAN
  • NSX Tier-0 uplink VLAN
INV-VAON-NET-001: Cross-instance segment to support multi-instance DR.
Q3
What authentication method is used for NSX data source?
  • AD user/pass
  • Local NSX admin
  • Client certificate credential with Enterprise Admin
  • API token
INV-VAON-SEC-006: Client certificate-based; no password lifecycle.
Q4
How are NSX Federation deployments integrated?
  • Global Manager as data source
  • Local Managers as data source
  • No federation support
  • SDDC Manager integration
INV-VAON-CFG-018: Global Manager is not supported; use Local Managers.
Q5
What port is required from ESXi hosts to the collector for latency metric collection?
  • TCP 443
  • TCP 1991
  • UDP 6081
  • TCP 8080
INV-VAON-CFG-017: TCP 1991 must be permitted.
Q6
What is the default retention period chosen by design?
  • 1 month
  • 3 months
  • 6 months
  • 13 months
INV-VAON-CFG-019: 1-month default minimizes storage and effort.
Q7
What CPU/RAM reservation policy applies to platform and collector?
  • 50%
  • 75%
  • 100% CPU and RAM
  • None
Implication of INV-VAON-CFG-001/002: 100% reservation.
Q8
How many collector nodes are deployed per VCF instance by default?
  • 0
  • 1
  • 2
  • 3
INV-VAON-CFG-002/008: One collector per VCF instance.
Q9
What tool performs LCM of Aria Ops for Networks?
  • SDDC Manager
  • Aria Suite Lifecycle
  • vCenter
  • NSX Manager
INV-VAON-LCM-001: Aria Suite Lifecycle manages binaries and upgrades.
Q10
What is enabled on vSphere Distributed Switches for flow collection?
  • sFlow
  • NetFlow (IPFIX)
  • SPAN
  • VXLAN
INV-VAON-CFG-014: NetFlow is enabled on each vDS.
Q11
Which service role is granted to the NSX integration account?
  • Auditor
  • Network Admin
  • Enterprise Admin
  • Security Admin
INV-VAON-SEC-006: Enterprise Admin role is required.
Q12
What DRS rule is applied in multi-AZ?
  • VM-VM affinity
  • VM/Host rule binding platform/collector to AZ1 host group
  • Anti-affinity across AZs
  • None
Logical design uses DRS VM/Host rule to pin to AZ1 host group.
Q13
What happens to vDS NetFlow settings when data source is added?
  • Manual config required
  • Aria Ops for Networks auto-updates each vDS
  • vCenter disables NetFlow
  • Only VLAN switch supported
INV-VAON-CFG-014 implication: Aria Ops for Networks automatically updates NetFlow settings on each cluster's vDS.
Q14
What is the max flows capacity at the Extra Large brick?
  • 1M flows
  • 4M flows
  • 8M flows
  • 16M flows
INV-VAON-CFG-010: XL supports up to 10,000 VMs and 8M flows.
Q15
Which local accounts are managed for password policy?
  • root and admin
  • support and consoleuser
  • aria and netops
  • installer and adm
INV-VAON-SEC-007..010: support and consoleuser local accounts.

Flashcards — Network Visibility

Card 1 of 15
Platform node brick size and why?
Extra Large — required for Network Verification & Assurance and Flow-based Application Discovery; supports 10,000 VMs / 8M flows.

Labs

Deploy Aria Ops for Networks and configure data sources

Deploy XL platform node + Large collector, configure vCenter (NetFlow) and NSX (IPFIX) data sources.

Starting State: VCF 5.2 instance with Aria Suite Lifecycle; WS1 Access clustered; AD/CA/DNS ready.

Configure SMTP alert notifications and retention

Set up email notifications for selected alerts and validate default 1-month retention.

Starting State: Aria Ops for Networks operational; SMTP server reachable.

Extend to a second VCF instance

Add a local-instance collector for VCF instance B and configure its data sources.

Starting State: Instance A with platform and collector; instance B brought up and healthy.

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.