PBO1295BU VMware Validated Design for Remote/Branch Office Technical Overview VMworld 2017 Content: Not for publication ##VMworld #PBO1295BU
Disclaimer This presentation may contain product features that are currently under development. This overview of new technology represents no commitment from VMware to deliver these features in any generally available product. Features are subject to change, and must not be included in contracts, purchase orders, or sales agreements of any kind. Technical feasibility and market demand will affect final delivery. Pricing and packaging for any new technologies or features discussed or presented have not been determined. CONFIDENTIAL 2
PBO1295BU VMware Validated Design for Remote/Branch Office Technical Overview Jim McMahon II Mike Brown VMworld 2017 Content: Not for publication #VMworld #PBO1295BU
Agenda 1 Overview 2 Physical Infrastructure Design 3 Virtual Infrastructure Design 4 Storage 5 Cloud Management 6 Operations 7 Backup and Disaster Recovery #PBO1295BU CONFIDENTIAL 4
Overview
VMware Validated Design for ROBO Built on top of VMware Validated Design for Software Defined Datacenter Supplement design by connecting up to 10 small sites Local core SDDC functions per site Two deployment models Centralized Decentralized #PBO1295BU CONFIDENTIAL
Regions in VVD ROBO Multiple regions support Disaster Recovery Support Data Privacy Laws Tenant data in region/country Distance between Regions can be large Countries East/West Coast Cities, i.e San Francisco (SFO) and Los Angeles (LAX) #PBO1295BU CONFIDENTIAL
About Hubs, Remote and Branch Office Sites Hubs Central point of provisioning/operations Support SDDC platform Can be dedicated to ROBOs Ensure continuous ROBO data availability DR\DA between Regions SLA dashboards Insight to ROBO investment Trending analysis Remote\Branch Offices Small location(s) Limited Datacenter capabilities Provides specific services Minimal IT investment Low SLA and connectivity requirements Can operate independently of Hub(s) Run <= 100 workloads #PBO1295BU CONFIDENTIAL
Physical Infrastructure Design
Disaster Recovery Regional Zones: Hub and Spoke A single region may refer to geo, i.e. North America 2x hubs support geo region Hub supports up to 10 ROBOs No shared SSO with hub Forward ROBO data Hub(s) replicate for DR KPI dashboards using Region/Site tag (vrli) VMworld 2017 Geo-Region: North America Geo-Region: North America Region A: SFO Availability Zone Availability Zone Disaster Recovery Region B: LAX Availability Zone Region A: SFO Availability Zone Availability Zone NOTE: Actual number of sites supported varies w/ connectivity and monitored objects Data Forwarding Data Forwarding Region A Robo X Content: Not for publication Data Forwarding Availability Zone Availability Zone Region A Robo X Availability Zone Availability Zone Region B: LAX Availability Availability Zone #PBO1295BU CONFIDENTIAL 10 Data Forwarding
ROBO POD Architecture Single POD design Min. 4 ESXi hosts Share SDDC roles Resource pools reserve Mgmt/Edge resources vsan recommended (scale, low overhead) External storage supported NFS for vrli extents Trunk LAN/WAN connectivity #PBO1295BU CONFIDENTIAL 11
ROBO POD Networking Spine/Leaf recommended Simplifies design 1x vds Future scale WAN/MPLS/DCI link(s) trunked to all hosts Only NSX ESGs connected External site connectivity may be through core VMworld 2017 Min 2x 10 GbE Uplinks to leaf Content: Not for publication #PBO1295BU CONFIDENTIAL 12
Virtual Infrastructure Design
vsphere Cluster Configuration Min 4x ESXi hosts; Actual size varies Single cluster managed by vcenter Server Appliance HA/DRS configured 4x Resource Pools Mgmt/Edge/Compute RP reservation = Total required VM resources +10% buffer Apps share based resource pool <= 100 VM s of average size (Windows 2012 R2; 4x8x60) Proactive capacity management #PBO1295BU CONFIDENTIAL 14
ROBO ESXi vds Configuration Min 2x uplinks 1x vds required in the ROBO POD All Internet/Intranet connectivity trunked in Use portgroups All networks but vsan Layer 3 Even vmotion #PBO1295BU CONFIDENTIAL 15
ROBO vcenter Server Design 1x VCSA with embedded Platform Services Controller Simplified design Low overhead/site Manage site locally during WAN/MPLS failure Use vcsa Update Manager Deploy Update Manager Download Service Limit vcenter Internet access #PBO1295BU CONFIDENTIAL 16
NSX Architecture 1:1 vcenter/nsx Manager Non-universal objects Single controller cluster 1x NSX Domain/site Simplified design Hub connectivity failure? Managed locally ROBO Cluster - Region x vcenter SSO Domain ROBO vcenter Server NSX Manager NSX Controller 1 NSX Controller 2 VMworld 2017 Content: Not for publication NSX Controller 3 Controller Cluster #PBO1295BU CONFIDENTIAL 17
ROBO NSX for vsphere Consolidated stack Provide network/security services Management Workloads No dedicated Edge Cluster Anti-Affinity rules Prevent controllers on same host #PBO1295BU CONFIDENTIAL 18
ROBO Routing Non-universal DLR/LS Local routing/switching components N/S dynamic routing Scales easily Common protocol at hub VMworld 2017 ToR Switches BGPECMP DLR Controller ROBO A BGPECMP NSX N/S Edges Distributed Logical Router Transit Logical Switch Logical Switches ToR Switches ROBO B BGPECMP NSX N/S Edges BGPECMP DLR Controller Content: Not for publication #PBO1295BU CONFIDENTIAL 19
ROBO Virtual Application Network Design - Example ECMP ESG for high availability App(s) deployed on VXLAN SDDC operations and automation are placed on NSX Logical Switch Minimize access to management VMworld 2017 Content: Not for publication #PBO1295BU CONFIDENTIAL 20
Storage
Storage Overview vsan for ROBO sites Simple Scales quickly Traditional block/nfs supported NFS extents for Log Insight archives Consider for templates; share between cluster(s) VMworld 2017 Content: Not for publication #PBO1295BU CONFIDENTIAL 22
vsan Everywhere Scales automatically if necessary Use vsan Ready Nodes All-flash where possible Cheaper at scale 10 GbE required Min 4x ESXi hosts 1x Storage Policy Requires min L2 IGMP at ToR L3 IGMP to span PODs/DCs NOTE: Multicast req. removed from vsan 6.6 #PBO1295BU CONFIDENTIAL 23
Cloud Management ROBO Services Management with vrealize Automation
vrealize Automation Region A ROBO(s) managed by Regional vra Deployed with VVD for SDDC Additional vra may be required for scale Proxy agents in each ROBO #PBO1295BU CONFIDENTIAL 25
ROBO vrealize Automation Resources 1x vcenter, embedded PSC 1x NSX Manager 1x cluster of resources Only admin access to site #PBO1295BU CONFIDENTIAL 26
ROBO Tenant Design Create non-default tenant Default Tenant isolation Fabric Group per ROBO Allow future ROBO isolation Business Groups for BUs Transparency Share services & resources #PBO1295BU CONFIDENTIAL 27
vsphere Integration vsphere Content Library Template Synchronization Scale additional ROBOs Template synchronization 1-way from hub to ROBOs Ensures gold standard Granular Isolation Adminitrators Endpoints #PBO1295BU CONFIDENTIAL 28
Operations Monitor, Trend, and Root Cause
vrealize Operations Remote Collection Conceptual Design vrops cluster manage ROBO sites only Centralized ROBO analytics 2x Remote Collectors/site Min. 3x medium analytics nodes 3 rd party MPs or EPOPs will impact scale Use vrops Sizing Calculator #PBO1295BU CONFIDENTIAL 30
SDDC vrealize Operations Design Logical Network Design Regional Cluster vrops Cluster deployed to Hub in Region A Use udlr/uls Placeholder for DR in Region B Protect with SRM Ensures continuous ROBO analytics VMworld 2017 Content: Not for publication #PBO1295BU CONFIDENTIAL 31
ROBO vrealize Operations Design Logical Remote and Branch Office Site Network Design vrealize Operations Manager remote collectors on VXLAN Metric collection local per region Minimize data loss Localized metric collection per SDDC ROBO Close to SDDC apps #PBO1295BU CONFIDENTIAL 32
vrealize Log Insight ROBO Logical Design Log Insight cluster per Region 3x node vli cluster at ROBOs Small Forward Region A/B Tag with site nomenclature Archive locally if required ROBO vli integrated with ROBO vrops ROBO Trending, Cap. Mgmt. Root Cause Analysis #PBO1295BU CONFIDENTIAL 33
vrealize Log Insight ROBO Network Design No DR for ROBO cluster in Region A Data forward to Region A/B ROBO cluster on VXLAN Firewall port open to forward from ROBO Single port Small attack surface #PBO1295BU CONFIDENTIAL 34
Backup and Recovery
ROBO Data Protection Use vsphere APIs for Data Protection (VADP) compatible platform vsphere Data Protection Store backups on different storage Backups stored locally Recovery independent of Hub Recover during WAN failure 36
Intelligent Operations Updates New to Intelligent Operations? Start with Free Assessments vsphere Optimization Assessment (VOA) Optimize SDDC and Hybrid Cloud Time to value in days vmware.com/assessment/voa Hybrid Cloud Assessment (HCA) Compare private and public cloud costs Time to value in < 1 hour vmware.com/hybrid-cloudassessment.html Already using vrealize? Upgrade to vrealize Operations 6.6 Upgrade to vrops 6.6 Visit our new upgrade center: vmware.com/go/vrops/upgrade Power User? Get Certified VMware Digital Badge Complete your online certification exam VMware Digital Badges: vmware.com/go/vrops201 7badge Meet the experts at the Education & Certification Lounge: VM Village Visit the Certification Exam Center: Jasmine EFG, Level 3 37