Intelligent Network Visibility for VMware Cloud Foundation
VMware Aria Operations for Networks provides network monitoring, troubleshooting, and flow analysis across the SDDC. A single Extra-Large platform node (with option to scale to a cluster) is deployed on the cross-instance NSX segment, and one Large collector node per VCF instance is deployed on the local-instance NSX segment for data collection from vCenter Server (vSphere Distributed Switch NetFlow) and NSX Manager (IPFIX for distributed firewall).
Key Components: NSX, Aria Operations, SDDC Manager, vCenter, ESXi, Workspace ONE
Platform Nodes: Single Extra Large platform node on cross-instance NSX segment; option to scale to cluster.
32 design decisions
| DD-ID | Decision | Quality |
|---|---|---|
| INV-VAON-CFG-019 | keeps 1-month default to minimize storage. | Manageability |
Decision: keeps 1-month default to minimize storage. Rationale: Alert Notifications Implication: INV-VAON-CFG-020: configure outbound SMTP for alerts to administrators/operators; select relevant system alerts. Component: VAON | ||
| INV-VAON-CFG-020 | : configure outbound SMTP for alerts to administrators/operators; select relevant system alerts. | Manageability |
Decision: : configure outbound SMTP for alerts to administrators/operators; select relevant system alerts. Rationale: Data Sources Implication: vCenterConfigure vCenter data source per workload domain; enable NetFlow on each vSphere Distributed Switch (IPFIX) — Aria Ops for Networks auto-updates vDS settings. Component: VAON | ||
| INV-VAON-CFG-001 | Deploy Aria Ops for Networks as non-clustered, single platform node in default mgmt cluster. | Manageability |
Decision: Deploy Aria Ops for Networks as non-clustered, single platform node in default mgmt cluster. Rationale: Capacity for 10,000 VMs/objects; scale-out possible. Implication: 100% CPU/RAM reservation for platform node. Component: VAON | ||
| INV-VAON-CFG-002 | Deploy single collector node in default mgmt cluster. | Manageability |
Decision: Deploy single collector node in default mgmt cluster. Rationale: Minimum 1 collector required to feed platform. Implication: 100% CPU/RAM reservation for collector. Component: VAON | ||
| INV-VAON-CFG-003 | Use Aria Suite Lifecycle in corresponding VCF instance to deploy. | Manageability |
Decision: Use Aria Suite Lifecycle in corresponding VCF instance to deploy. Rationale: Lifecycle manages binaries; automated deployment. Implication: Must deploy Aria Suite Lifecycle via SDDC Manager. Component: VAON | ||
| INV-VAON-CFG-004 | Protect all nodes with vSphere HA. | Availability |
Decision: Protect all nodes with vSphere HA. Rationale: Availability objective. Implication: Ensure spare cluster capacity for HA. Component: VAON | ||
| INV-VAON-CFG-005 | Place platform and collector nodes in dedicated VM folders. | Manageability |
Decision: Place platform and collector nodes in dedicated VM folders. Rationale: Organization. Implication: Create folders in vCenter. Component: VAON | ||
| INV-VAON-CFG-007 | In multi-AZ, add VMs to first AZ VM group. | Manageability |
Decision: In multi-AZ, add VMs to first AZ VM group. Rationale: Ensure AZ1 hosting. Implication: Update VM group after stretched cluster creation. Component: VAON | ||
| INV-VAON-CFG-008 | In multi-instance, deploy collector per instance using same Aria Suite Lifecycle environment. | Manageability |
Decision: In multi-instance, deploy collector per instance using same Aria Suite Lifecycle environment. Rationale: Consistent deployment per instance. Implication: Each collector registered with platform node. Component: VAON | ||
| INV-VAON-CFG-010 | Deploy platform node with Extra Large brick. | Manageability |
Decision: Deploy platform node with Extra Large brick. Rationale: Capacity for 10,000 VMs/8M flows; Network Verification & Assurance, Flow-based Application Discovery require XL. Implication: More resources required in mgmt cluster. Component: VAON | ||
| INV-VAON-CFG-011 | If VMs exceed 10,000 or object limits reached, scale out to platform cluster by adding nodes via Ari | Manageability |
Decision: If VMs exceed 10,000 or object limits reached, scale out to platform cluster by adding nodes via Aria Suite Lifecycle. Rationale: Growth capacity. Implication: Additional resources in mgmt cluster. Component: VAON | ||
| INV-VAON-CFG-012 | Deploy collector as Large. | Manageability |
Decision: Deploy collector as Large. Rationale: Sufficient for design-target flows; more can be added. Implication: 8-10 vCPUs/16 GB per collector. Component: VAON | ||
| INV-VAON-NET-001 | Platform nodes on cross-instance NSX segment. | Manageability |
Decision: Platform nodes on cross-instance NSX segment. Rationale: Multi-instance DR support. Implication: Requires NSX overlay. Component: VAON | ||
| INV-VAON-NET-002 | Collector nodes on local-instance NSX segment. | Manageability |
Decision: Collector nodes on local-instance NSX segment. Rationale: Local flow collection. Implication: Requires NSX overlay. Component: VAON | ||
| INV-VAON-NET-004 | Static IP addresses. | Manageability |
Decision: Static IP addresses. Rationale: Reliability, conflict avoidance. Implication: IP address management discipline. Component: VAON | ||
| INV-VAON-NET-007 | Forward/reverse DNS for each node. | Manageability |
Decision: Forward/reverse DNS for each node. Rationale: FQDN accessibility. Implication: Maintain DNS records. Component: VAON | ||
| INV-VAON-NET-008 | NTP on each node. | AvailabilitySecurity |
Decision: NTP on each node. Rationale: Accurate time synchronization. Implication: Requires redundant NTP; firewalls allow NTP. Component: VAON | ||
| INV-VAON-LCM-001 | Use Aria Suite Lifecycle for LCM. | Manageability |
Decision: Use Aria Suite Lifecycle for LCM. Rationale: Manages binaries and upgrades. Implication: Aria Suite Lifecycle deployed via SDDC Manager. Component: VAON | ||
| INV-VAON-CFG-013 | Configure vCenter data source per management/VI workload domain vCenter. | Manageability |
Decision: Configure vCenter data source per management/VI workload domain vCenter. Rationale: Network visibility for vSphere networking. Implication: Configure per region/domain. Component: VAON | ||
| INV-VAON-CFG-014 | Enable NetFlow on each vSphere Distributed Switch. | Manageability |
Decision: Enable NetFlow on each vSphere Distributed Switch. Rationale: IPFIX flow collection. Implication: Aria Ops for Networks updates vDS NetFlow settings automatically. Component: VAON | ||
| INV-VAON-CFG-015 | Configure NSX Manager data source per workload domain. | Manageability |
Decision: Configure NSX Manager data source per workload domain. Rationale: NSX network visibility. Implication: Per-region/domain configuration. Component: VAON | ||
| INV-VAON-CFG-016 | Enable IPFIX for distributed firewall. | Security |
Decision: Enable IPFIX for distributed firewall. Rationale: Flow collection via IPFIX. Implication: DFW must be enabled; service account needs Enterprise Admin. Component: VAON | ||
| INV-VAON-CFG-017 | Enable latency metric collection on NSX data source. | Performance |
Decision: Enable latency metric collection on NSX data source. Rationale: Latency metrics from NSX Transport Nodes. Implication: Allow TCP 1991 from ESXi to collector. Component: VAON | ||
| INV-VAON-CFG-018 | Use NSX Local Manager as data source for NSX Federation environments. | Manageability |
Decision: Use NSX Local Manager as data source for NSX Federation environments. Rationale: NSX Global Manager not supported as data source; Federation data fetched from Local Managers. Implication: Configure per Local Manager. Component: VAON | ||
| INV-VAON-SEC-001 | Limit local accounts, apply least privilege, assign service roles to AD groups. | Manageability |
Decision: Limit local accounts, apply least privilege, assign service roles to AD groups. Rationale: Accountability and auditability. Implication: Manage service accounts and groups in AD. Component: VAON | ||
| INV-VAON-SEC-004 | Custom vCenter role with minimum privileges; AD service account per workload domain vCenter. | Manageability |
Decision: Custom vCenter role with minimum privileges; AD service account per workload domain vCenter. Rationale: Least privilege integration. Implication: Maintain role and service account. Component: VAON | ||
| INV-VAON-SEC-006 | NSX client certificate credential with Enterprise Admin role. | ManageabilitySecurity |
Decision: NSX client certificate credential with Enterprise Admin role. Rationale: Certificate-based, no password. Implication: Manage certificates and keys. Component: VAON | ||
| INV-VAON-SEC-007 | Configure local user password expiration/complexity/lockout. | Manageability |
Decision: Configure local user password expiration/complexity/lockout. Rationale: Align with org/compliance. Implication: Applies only to support/consoleuser; manage via appliance console. Component: VAON | ||
| INV-VAON-SEC-010 | Rotate support and consoleuser passwords on schedule via Aria Suite Lifecycle. | Manageability |
Decision: Rotate support and consoleuser passwords on schedule via Aria Suite Lifecycle. Rationale: Default expiration applies. Implication: Manage per node. Component: VAON | ||
| INV-VAON-SEC-011 | CA-signed cert with FQDNs of platform/collector in SAN. | Security |
Decision: CA-signed cert with FQDNs of platform/collector in SAN. Rationale: Encrypted external UI/API. Implication: Replace cert when adding nodes. Component: VAON | ||
| INV-VAON-SEC-012 | Use SHA-2 or higher. | Manageability |
Decision: Use SHA-2 or higher. Rationale: SHA-1 deprecated. Implication: CA must support SHA-2+. Component: VAON | ||
| INV-MON-IOM-001 | Add Ping adapter for platform (default collector group) and collector (local-instance collector grou | AvailabilityManageability |
Decision: Add Ping adapter for platform (default collector group) and collector (local-instance collector group). Rationale: Availability metrics in Aria Operations. Implication: Manual adapter addition. Component: MON | ||
Prerequisites
- VCF management domain operational
- DNS/NTP configured
- CA infrastructure in place
Implementation Procedure
Implementation
VCF 5.2.x healthy; captured inputs in Intelligent Network Visibility tab of Planning & Preparation Workbook.
Aria Suite Lifecycle deployed; Workspace ONE Access clustered; Operations + Aria Automation optional.
Active Directory, DNS, NTP, CA in place; Aria Ops for Networks OVA downloaded.
Implementation Methods
Powershell
Use PowerValidatedSolutions module; menu entry for Intelligent Network Visibility (INV) — Generate JSON Spec → Verify Prereqs → Generate Cert → End-to-End Deployment → Configuration.
UI
Follow VCF version-specific Aria Suite Lifecycle deployment and WS1 Access integration (similar to IOM). Then: Add Aria Ops for Networks product in Aria Suite Lifecycle; deploy platform node on cross-instance segment; deploy collector per VCF instance on local-instance segment. Register collector with platform node. Configure vCenter data sources with custom role + AD service account (enable NetFlow on vDS). Configure NSX data sources with client cert (Enterprise Admin); enable IPFIX for DFW; enable latency metric collection. Configure SMTP and alert notifications. Configure user roles via WS1 Access integration. Replace cert; configure retention.
External Services / Integration Points
Active Directory (AD)
DNS
NTP
CA
Configuration Values
Data SourcesvCenter (NetFlow on vDS), NSX Local Manager (IPFIX for DFW, latency collection TCP 1991), NSX Federation uses Local Manager only
Retention1 month (default) for all categories
SmtpConfigure outbound SMTP in Aria Ops for Networks settings
Reservation100% CPU and RAM reservation automatically applied
Additional Instance
For additional VCF instance, add a collector node to the local-instance NSX segment, register with platform node, configure vCenter and NSX data sources for the new workload domains, enable NetFlow/IPFIX, allow TCP 1991 for latency.
Day-2 Operations Tasks
Operations
As neededPersonas
As neededNameRole
As neededCloud AdminAria Ops for Networks Admin service role
As neededNetwork OperatorAria Ops for Networks User
As neededAuditorAria Ops for Networks Auditor (read-only)
As neededOperational Verification
As neededCertificate Management
As neededGenerate CA-signed cert including all FQDNs; import via Aria Suite Lifecycle or appliance UI; restart services.
As neededPassword Management
As neededMonitoring Points
- Verify platform node operational, data sources OK, flows visible, authentication via WS1 Access successful.
- MonitoringPing adapters in Aria Operations for platform and collector nodes (INV-MON-IOM-001..003).
Troubleshooting
Likely Panelist Questions
Q: Why did you choose this architecture?
See design decisions for rationale
Trade-off Analysis
1-month retention default trades long-term analysis for storage efficiency.
Chosen:
Justification:
Trade-Offs Analysis
Chosen:
Justification:
Quiz — Network Visibility
- Small
- Medium
- Large
- Extra Large
- Local-instance NSX segment
- Cross-instance NSX segment
- Management VLAN
- NSX Tier-0 uplink VLAN
- AD user/pass
- Local NSX admin
- Client certificate credential with Enterprise Admin
- API token
- Global Manager as data source
- Local Managers as data source
- No federation support
- SDDC Manager integration
- TCP 443
- TCP 1991
- UDP 6081
- TCP 8080
- 1 month
- 3 months
- 6 months
- 13 months
- 50%
- 75%
- 100% CPU and RAM
- None
- 0
- 1
- 2
- 3
- SDDC Manager
- Aria Suite Lifecycle
- vCenter
- NSX Manager
- sFlow
- NetFlow (IPFIX)
- SPAN
- VXLAN
- Auditor
- Network Admin
- Enterprise Admin
- Security Admin
- VM-VM affinity
- VM/Host rule binding platform/collector to AZ1 host group
- Anti-affinity across AZs
- None
- Manual config required
- Aria Ops for Networks auto-updates each vDS
- vCenter disables NetFlow
- Only VLAN switch supported
- 1M flows
- 4M flows
- 8M flows
- 16M flows
- root and admin
- support and consoleuser
- aria and netops
- installer and adm
Flashcards — Network Visibility
Labs
Deploy Aria Ops for Networks and configure data sources
Deploy XL platform node + Large collector, configure vCenter (NetFlow) and NSX (IPFIX) data sources.
Starting State: VCF 5.2 instance with Aria Suite Lifecycle; WS1 Access clustered; AD/CA/DNS ready.
Configure SMTP alert notifications and retention
Set up email notifications for selected alerts and validate default 1-month retention.
Starting State: Aria Ops for Networks operational; SMTP server reachable.
Extend to a second VCF instance
Add a local-instance collector for VCF instance B and configure its data sources.
Starting State: Instance A with platform and collector; instance B brought up and healthy.