Configure Global Policies in VMware NSX-T Federation

In this article I will cover creating Global Groups in NSX-T Federation.  Then we will create a policy and a rule to test web traffic in order to show that the new policy/rule applies at both site locations.

Log into the Global Manager

NSX-T Global Manager Groups inventory before any global groups have been created.

In the primary global manager go to Inventory > Groups

Add Group

NSX-T group editor naming the Global-Web-Tier group, setting its region to Global, and opening member selection.

Provide the group a name – my test is for web tier virtual machines

Choose Region as Global

Set Members

NSX-T Select Members dialog for the Global-Web-Tier group before membership criteria are added.

ADD Criteria

Global-Web-Tier membership criterion matching virtual machines whose names contain a specified value.

I am using VM Name as criteria even though I highly recommend leveraging tags in real world

Apply

NSX-T group editor showing Global-Web-Tier with one membership criterion configured and ready to save.

Save

NSX-T Groups inventory showing the saved Global-Web-Tier group with Global scope and member and status controls.

Click view members to ensure all your virtual machines have been added

Global-Web-Tier effective-members view for Dallas showing the DallasPRD-web-01 virtual machine.
Global-Web-Tier effective-members view for Fort Worth showing the Test-web-01 virtual machine.

Toggle between locations to see full list of members

NSX-T Distributed Firewall Application category where a global security policy and rule will be added.

Next we need to configure polices and rules

Security > East West Security > Distributed Firewall > Application

Add Policy

NSX-T Distributed Firewall controls for adding an Application policy and a rule.

Click ellipsis

Add Rule

Global distributed-firewall rule with any source, the Global-Web-Tier destination, HTTP service, and Reject action.

Provide a name – Sources: any – Destinations: Global web tier group – Services: Http – Applied to: Global Web Tier Group – Action Reject

NSX-T interface showing two unpublished changes with Revert and Publish controls.

Publish

Browser error showing a web server refusing the connection after the global distributed-firewall rule is published with Reject action.
Browser error page showing a site cannot be reached because the connection was refused.

Neither web virtual machine works because the rule above is set to reject.  Since this is a Global Rule it is being applied at both Location 1 and Location 2

Global Manager distributed-firewall view while changing the global web rule from Reject to Allow before publishing.

Change the rule to allow

PUBLISH

Dallas datacenter web-server page loading successfully after the global firewall rule is changed to Allow.
Fort Worth secondary-location web-server page loading successfully after the global firewall rule is changed to Allow.

As you can now see the web pages are working from a workstation outside of the NSX-T network.

Continue reading

How to deploy VMware NSX-T 3.2 Edge Node & Edge Cluster

Explore another guide in this topic and build on what you have just read. Read the article

Leave a Reply

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading