The Google Cloud VMware Engine service includes NSX-T for workload networking and security features such as microsegmentation and firewall policies. This page explains how to create and manage network segments for your workloads using NSX-T Manager.
Before you begin
- Create a private cloud and confirm that its status is Operational.
- VMware Engine service gives you administrator access by default. If you prefer role based access control (RBAC) for NSX-T, then you must setup vIDM (VMware Identity Manager). Please file a support ticket if you require RBAC for NSX-T.
- Allocate address ranges for the following purposes:
- DHCP service
- A subnet for the workload network segment
Access NSX-T Manager from the VMware Engine portal
- Access the VMware Engine portal.
- On the navigation menu, click Resources.
- Click the Private cloud name corresponding to the private cloud where you want to create workload network segments using NSX-T.
- In Resources for your selected private cloud, click the vSphere Management Network tab.
- Click the FQDN corresponding to NSX Manager.
Log into NSX-T
If you are logging into NSX-T for the first time and you have not set up vIDM, enter the following default credentials:
- User name:
If you have set up vIDM and connected it to your identity source, such as Active Directory, use your identity source credentials.
Set up DHCP service for the workload network segment
- In NSX-T Manager, click the Networking tab.
- As the dashboard shows, the service creates one Tier-0 and one Tier-1 gateway.
- Set up DHCP service for your workloads. NSX-T has support for DHCP-Relay as well. For information about provisioning, see DHCP Relay. To provision a DHCP server, under IP Management, select DHCP.
- Select Add Server.
- For Server type, select DHCP server.
- Provide a DHCP Service IP Address range.
- Click Save.
- Attach this DHCP service to the relevant Tier-1 gateway. A default Tier-1 gateway has already been provisioned by the service. In the navigation pane, under Connectivity, click Tier-1 Gateways.
- Click the vertical ellipses. Select Edit.
- In the IP Address Management field, click No IP Allocation Set.
- Set Type to DHCP Local Server and select the DHCP Server that you just created.
- Click Save.
- Click Close Editing. You can now create a workload network segment.
Creating a workload network segment
- In the navigation pane, under Connectivity, click Segments.
- Select Add Segment.
- Name your segment and, from the Connected Gateway & Type drop-down list, select Tier1 to connect to Tier1 Gateway.
- Click Set Subnets.
- Click Add Subnets.
- In the Gateway IP/Prefix Length field, enter the subnet range. Specify
the subnet range with .1 in the last octet, for example,
- Specify the DHCP Ranges and click ADD.
- In Segment, select TZ-OVERLAY | Overlay from the drop-down list.
- Click Save. You can now select this network segment in vCenter while creating a VM.
In a given region, you can set up at most 100 unique routes from VMware Engine to your VPC network using private service access. This includes, for example, private cloud management CIDRs, NSX-T workload segments, and HCX network CIDRs. This limit includes all private clouds in the region.