SlideShare a Scribd company logo
1 of 29
Download to read offline
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Architectural Patterns and Best
Practices with VMware Cloud on AWS
Andy Reedy, AWS Partner Solutions Architecture
N o v e m b e r 3 0 , 2 0 1 7
A R C 4 0 2
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is VMware Cloud on AWS
On-Demand, VMware Software Defined
Datacenter Delivered as a Cloud Service
ESXi
NSX
vSphere
VSAN
Latest Software
VCSA, ESXi, NSX, VSAN, Managed by VMware
Dynamic Capacity
DRS/HA Compute Cluster (Intel x86)
VSAN Storage Cluster (NVMe Flash)
NSX Network Virtualization (ENA)
Software Defined Data Center
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is VMware Cloud on AWS
Compute
• Bare Metal
• I3.16XL Equivalent
• 36 Cores/72 vCPUs
• 512GiB Memory15TiB*
• NVMe All-Flash Storage
• 25Gb ENA
ESXi
NSX
vSphere
VSAN
Software Defined Data Center
Hypervisor
• ESXi
• 4 to 32 Host Cluster
• Maintained by VMware
• No SSH/Root
• No VIBs/Plugins
Storage
• VSAN
• Aggregate Instance
Storage
• All Flash
(Capacity/Cache)
• No EBS/EFS
• VM Storage Policies
Network and Security
• NSX
• Logical Networks
• North/South Firewalling
• Compute/Management
Gateways
• IPSec Termination
• NAT
vSphere
• VMware Managed
• Delegated Permissions
• Hybrid Linked Mode
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is VMware Cloud on AWS
ESXi
NSX
vSphere
VSAN
Software Defined Data Center
ESXi
vSphere vCentervCenter
Customer
Data Center
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Account structure
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Common use cases
Data center
expansion
Maintain
Consolidation
Migrate
Consolidate
Workload flexibility
Expand
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Getting started
vmc.vmware.com
Create a new SDDC
• SDDC Name
• Number of Hosts (4 to 32)
• AWS Region (Oregon, Virginia)
VMware Cloud on AWS Console
• my.vmware.com credentials
• Organizations
• Identity and Access Management
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Connecting to an AWS account
IAM
Cross Account
Role
AWS
Managed Policy
Customer-Owned
AWS Account
CloudFormation
Template
VMware Cloud on AWS
SDDC Account Customer
IAM UserVMware Cloud
Management Services
vmc.vmware.com
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Accessing VMware Cloud on AWS
• Hybrid Linked-Mode
• Logical network configuration
• Virtual machine administration
• VM storage policies
• Add and remove ESXi hosts
• Console user and role management
• Firewall configuration
• EIP and NAT configuration
• VPN connectivity
vmc.vmware.com
vSphere H5
Web Client
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Underlay and overlay networks
172.31.1.0/24
Logical Network 1
192.168.1.0/24
Logical Network 2
192.168.2.0/24
VM
1
VM
2
Logical Network 1
192.168.1.0/24
Logical Network 2
192.168.2.0/24
VM
3
VM
4
.10 .11
MAC IP VXLANUDP MAC IP PAYLOAD
SRC: 172.31.1.10
DST: 172.31.1.11
SRC: 192.168.1.50
DST: 192.168.1.51
.50 .51
Underlay Overlay
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
VMware Cloud on AWS: Underlay
VMware Cloud on
AWS SDDC Account
NSX
VPC Subnet – x.x.x.x/yy VPC Subnet – x.x.x.x/yy VPC Subnet – x.x.x.x/yy
Management VXLAN Storage
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
VMware Cloud on AWS: Overlay
VMware Cloud on
AWS SDDC Account
NSX
VCSA
NSX
MGR
Management Gateway
(MGW)
Compute Gateway
(CGW)
VM VM
Management Customer Workloads
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Compute Gateway
CGW
Logical
Networks
Connected
AWS
Account
Internet
• North/South Firewall
• NAT
• IPSec VPN Termination
• AWS Account Connectivity
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Customer AWS account connectivity
VMware Cloud on
AWS SDDC Account
Host-1
Host-2
Host-3
Host-4
CGW
Customer Owned
AWS Account
VPC Subnet 1 VPC Subnet 2
VM
Customer
Workloads
Amazon
Redshift
Logical Network
Route Table
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
On-premises connectivity
Customer Data Center
Compute Clusters
VM
vSphere
VM
Management
vSphere
NSX
MGR
CGW
VM
Management
Logical Network 1
VM
MGW
IGW
Internet
Direct
Connect
VMK
VMware Cloud on
AWS SDDC
VGW
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Best practices and considerations
Global IP Address Plan
• On-Premises Data Centers
• Logical Networks
• Management Networks /23 to /16
• AWS Accounts and VPCs—Multiple Regions
• Additional SDDCs
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Best practices and considerations
SDDC to AWS connectivity
• One-to-One SDDC to AWS VPC
• Subnet/AZ placement—cost optimization
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Best practices and considerations
Plan for Workload Mobility
• Connectivity between VPC CIDR and on-premises
environments
• L2 versus L3 VPN
• Direct Connect
• Backups
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Hybrid connectivity
Customer
Datacenters
VMware
Cloud SDDC
Customer-
Owned AWS
Account VPC ENIs for Compute Gateway
L2VPN
IPSec VPN x2
Direct Connect*
IPSec VPN
Direct Connect
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Multi-region
172.29.1.0/24
MS
SQL
MS
SQL
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS
SDDC Account
Customer
AWS Account
Amazon
Redshift
Customer
AWS Account
172.28.1.0/24
US-WEST-2 CA-CENTRAL-1
App1
App1
IPSec
VPN
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Use with ALB
172.29.1.0/24
VM VM
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS
SDDC Account
Customer
AWS Account
ALBIGW
IP Target Group
• 172.31.1.100
• 172.31.1.101
WAF
Visitor
ENI
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Storage
172.29.1.0/24
VM VM
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS
SDDC Account Customer
AWS Account
Amazon S3
VPC Endpoint
ENI
Amazon EFS
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
DNS
VM VM
CGW
Logical Network
172.31.1.0/24
VMware Cloud on AWS
SDDC Account
Customer Owned
AWS Account
VPC Subnet 1 VPC Subnet 2
Simple AD
Amazon
Route 53
ENI
Private
Hosted Zone
VPC DNS
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Best practices and considerations
Security, visibility, and operational auditing
• Two firewall control points: Security Group and NSX CGW
• Enable VPC Flow Logs
• Enable AWS CloudTrail
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Best practices and considerations
Treat this as a cloud service
• Evaluate your consolidation ratios and utilization tolerance
• Leverage elasticity — this is not colocation!
Automation
• VMware Cloud on AWS API
• vSphere
• AWS
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Other considerations
• Logical Networks — Multicast
• ESXi hosts are dedicated — Windows licensing
• Any vSphere supported operating system
• Host oversubscription
• Custom VM geometry — 1vCPU x 64 GB RAM
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Wrap-up
• Wholistic address planning
• Account, VPC, and AZ placement considerations
• Plan for workload mobility
• Treat this as a cloud service
• Automate all-the-things!
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Next Steps
• VMware Cloud on AWS Hands-on-labs (HOL)
• ARC322 - AWS Native Services Integration
• ENT303 - VMware Cloud on AWS Technical Deep Dive
• ENT204 - Unique Integrations Between VMware & AWS
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Thank you!
Pl ease compl ete the survey.

More Related Content

What's hot

DEV326_DevOps Essentials An Introductory Workshop on CICD Practices
DEV326_DevOps Essentials An Introductory Workshop on CICD PracticesDEV326_DevOps Essentials An Introductory Workshop on CICD Practices
DEV326_DevOps Essentials An Introductory Workshop on CICD PracticesAmazon Web Services
 
DEV205_Developing Applications on AWS in the JVM
DEV205_Developing Applications on AWS in the JVMDEV205_Developing Applications on AWS in the JVM
DEV205_Developing Applications on AWS in the JVMAmazon Web Services
 
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...Amazon Web Services
 
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...Using AWS Management Tools to Enable Governance, Compliance, Operational, and...
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...Amazon Web Services
 
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017Serverless DevOps to the Rescue - SRV330 - re:Invent 2017
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017Amazon Web Services
 
NET203_Using Amazon VPC Flow Logs to Do Predictive Security Analytics
NET203_Using Amazon VPC Flow Logs to Do Predictive Security AnalyticsNET203_Using Amazon VPC Flow Logs to Do Predictive Security Analytics
NET203_Using Amazon VPC Flow Logs to Do Predictive Security AnalyticsAmazon Web Services
 
CTD405_Building Serverless Video Workflows
CTD405_Building Serverless Video WorkflowsCTD405_Building Serverless Video Workflows
CTD405_Building Serverless Video WorkflowsAmazon Web Services
 
Dive deep into technical enhancements - re:Invent Come to London 2.0
Dive deep into technical enhancements - re:Invent Come to London 2.0Dive deep into technical enhancements - re:Invent Come to London 2.0
Dive deep into technical enhancements - re:Invent Come to London 2.0Amazon Web Services
 
Containers on AWS - re:Invent Comes to London 2.0
Containers on AWS - re:Invent Comes to London 2.0Containers on AWS - re:Invent Comes to London 2.0
Containers on AWS - re:Invent Comes to London 2.0Amazon Web Services
 
GPSTEC304_Shipping With PorpoiseA K8s Story
GPSTEC304_Shipping With PorpoiseA K8s StoryGPSTEC304_Shipping With PorpoiseA K8s Story
GPSTEC304_Shipping With PorpoiseA K8s StoryAmazon Web Services
 
NET308_VPC Design Scenarios for Real-Life Use Cases
NET308_VPC Design Scenarios for Real-Life Use CasesNET308_VPC Design Scenarios for Real-Life Use Cases
NET308_VPC Design Scenarios for Real-Life Use CasesAmazon Web Services
 
Getting Started with Amazon EC2 Container Service
Getting Started with Amazon EC2 Container ServiceGetting Started with Amazon EC2 Container Service
Getting Started with Amazon EC2 Container ServiceAmazon Web Services
 
MBL310_Building Hybrid and Web Apps with AWS Mobile CLI
MBL310_Building Hybrid and Web Apps with AWS Mobile CLIMBL310_Building Hybrid and Web Apps with AWS Mobile CLI
MBL310_Building Hybrid and Web Apps with AWS Mobile CLIAmazon Web Services
 
DAT316_Report from the field on Aurora PostgreSQL Performance
DAT316_Report from the field on Aurora PostgreSQL PerformanceDAT316_Report from the field on Aurora PostgreSQL Performance
DAT316_Report from the field on Aurora PostgreSQL PerformanceAmazon Web Services
 
STG301_Deep Dive on Amazon S3 and Glacier Architecture
STG301_Deep Dive on Amazon S3 and Glacier ArchitectureSTG301_Deep Dive on Amazon S3 and Glacier Architecture
STG301_Deep Dive on Amazon S3 and Glacier ArchitectureAmazon Web Services
 
MBL201_Progressive Web Apps in the Real World
MBL201_Progressive Web Apps in the Real WorldMBL201_Progressive Web Apps in the Real World
MBL201_Progressive Web Apps in the Real WorldAmazon Web Services
 
CTD201_Introduction to Amazon CloudFront and AWS Lambda@Edge
CTD201_Introduction to Amazon CloudFront and AWS Lambda@EdgeCTD201_Introduction to Amazon CloudFront and AWS Lambda@Edge
CTD201_Introduction to Amazon CloudFront and AWS Lambda@EdgeAmazon Web Services
 
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)Amazon Web Services
 
CON209_Interstella 8888 Learn How to Use Docker on AWS
CON209_Interstella 8888 Learn How to Use Docker on AWSCON209_Interstella 8888 Learn How to Use Docker on AWS
CON209_Interstella 8888 Learn How to Use Docker on AWSAmazon Web Services
 

What's hot (20)

DEV326_DevOps Essentials An Introductory Workshop on CICD Practices
DEV326_DevOps Essentials An Introductory Workshop on CICD PracticesDEV326_DevOps Essentials An Introductory Workshop on CICD Practices
DEV326_DevOps Essentials An Introductory Workshop on CICD Practices
 
DEV205_Developing Applications on AWS in the JVM
DEV205_Developing Applications on AWS in the JVMDEV205_Developing Applications on AWS in the JVM
DEV205_Developing Applications on AWS in the JVM
 
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...
STG309_Deep Dive Using Hybrid Storage with AWS Storage Gateway to Solve On-Pr...
 
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...Using AWS Management Tools to Enable Governance, Compliance, Operational, and...
Using AWS Management Tools to Enable Governance, Compliance, Operational, and...
 
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017Serverless DevOps to the Rescue - SRV330 - re:Invent 2017
Serverless DevOps to the Rescue - SRV330 - re:Invent 2017
 
NET203_Using Amazon VPC Flow Logs to Do Predictive Security Analytics
NET203_Using Amazon VPC Flow Logs to Do Predictive Security AnalyticsNET203_Using Amazon VPC Flow Logs to Do Predictive Security Analytics
NET203_Using Amazon VPC Flow Logs to Do Predictive Security Analytics
 
CTD405_Building Serverless Video Workflows
CTD405_Building Serverless Video WorkflowsCTD405_Building Serverless Video Workflows
CTD405_Building Serverless Video Workflows
 
Serverless Developer Experience
Serverless Developer ExperienceServerless Developer Experience
Serverless Developer Experience
 
Dive deep into technical enhancements - re:Invent Come to London 2.0
Dive deep into technical enhancements - re:Invent Come to London 2.0Dive deep into technical enhancements - re:Invent Come to London 2.0
Dive deep into technical enhancements - re:Invent Come to London 2.0
 
Containers on AWS - re:Invent Comes to London 2.0
Containers on AWS - re:Invent Comes to London 2.0Containers on AWS - re:Invent Comes to London 2.0
Containers on AWS - re:Invent Comes to London 2.0
 
GPSTEC304_Shipping With PorpoiseA K8s Story
GPSTEC304_Shipping With PorpoiseA K8s StoryGPSTEC304_Shipping With PorpoiseA K8s Story
GPSTEC304_Shipping With PorpoiseA K8s Story
 
NET308_VPC Design Scenarios for Real-Life Use Cases
NET308_VPC Design Scenarios for Real-Life Use CasesNET308_VPC Design Scenarios for Real-Life Use Cases
NET308_VPC Design Scenarios for Real-Life Use Cases
 
Getting Started with Amazon EC2 Container Service
Getting Started with Amazon EC2 Container ServiceGetting Started with Amazon EC2 Container Service
Getting Started with Amazon EC2 Container Service
 
MBL310_Building Hybrid and Web Apps with AWS Mobile CLI
MBL310_Building Hybrid and Web Apps with AWS Mobile CLIMBL310_Building Hybrid and Web Apps with AWS Mobile CLI
MBL310_Building Hybrid and Web Apps with AWS Mobile CLI
 
DAT316_Report from the field on Aurora PostgreSQL Performance
DAT316_Report from the field on Aurora PostgreSQL PerformanceDAT316_Report from the field on Aurora PostgreSQL Performance
DAT316_Report from the field on Aurora PostgreSQL Performance
 
STG301_Deep Dive on Amazon S3 and Glacier Architecture
STG301_Deep Dive on Amazon S3 and Glacier ArchitectureSTG301_Deep Dive on Amazon S3 and Glacier Architecture
STG301_Deep Dive on Amazon S3 and Glacier Architecture
 
MBL201_Progressive Web Apps in the Real World
MBL201_Progressive Web Apps in the Real WorldMBL201_Progressive Web Apps in the Real World
MBL201_Progressive Web Apps in the Real World
 
CTD201_Introduction to Amazon CloudFront and AWS Lambda@Edge
CTD201_Introduction to Amazon CloudFront and AWS Lambda@EdgeCTD201_Introduction to Amazon CloudFront and AWS Lambda@Edge
CTD201_Introduction to Amazon CloudFront and AWS Lambda@Edge
 
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)
STG307_Deep Dive on Amazon Elastic File System (Amazon EFS)
 
CON209_Interstella 8888 Learn How to Use Docker on AWS
CON209_Interstella 8888 Learn How to Use Docker on AWSCON209_Interstella 8888 Learn How to Use Docker on AWS
CON209_Interstella 8888 Learn How to Use Docker on AWS
 

Similar to ARC402_Architectural Patterns and Best Practices with VMware Cloud on AWS

VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...
VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...
VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...Amazon Web Services
 
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS Summit
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS SummitVMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS Summit
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS SummitAmazon Web Services
 
VMware Cloud on AWS – Technical Deep Dive.pdf
VMware Cloud on AWS – Technical Deep Dive.pdfVMware Cloud on AWS – Technical Deep Dive.pdf
VMware Cloud on AWS – Technical Deep Dive.pdfAmazon Web Services
 
VMware Cloud on AWS - Technical Deep Dive - AWS Summit Sydney
VMware Cloud on AWS - Technical Deep Dive - AWS Summit SydneyVMware Cloud on AWS - Technical Deep Dive - AWS Summit Sydney
VMware Cloud on AWS - Technical Deep Dive - AWS Summit SydneyAmazon Web Services
 
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdfHybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdfAmazon Web Services
 
Integrating with VMware Cloud on AWS
Integrating with VMware Cloud on AWSIntegrating with VMware Cloud on AWS
Integrating with VMware Cloud on AWSAmazon Web Services
 
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018Amazon Web Services
 
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...Amazon Web Services
 
Sessão Avançada: VMware Cloud na AWS - ENT204 - Sao Paulo Summit
Sessão Avançada: VMware Cloud na AWS -  ENT204 - Sao Paulo SummitSessão Avançada: VMware Cloud na AWS -  ENT204 - Sao Paulo Summit
Sessão Avançada: VMware Cloud na AWS - ENT204 - Sao Paulo SummitAmazon Web Services
 
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptxVMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptxRichieBallyears
 
VMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPTVMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPTAmazon Web Services
 
VMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning SeriesVMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning SeriesAmazon Web Services
 
SRV320 Deep Dive on VMware Cloud on AWS
 SRV320 Deep Dive on VMware Cloud on AWS SRV320 Deep Dive on VMware Cloud on AWS
SRV320 Deep Dive on VMware Cloud on AWSAmazon Web Services
 
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Amazon Web Services
 
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017Amazon Web Services
 
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWS
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWSVMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWS
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWSAmazon Web Services Korea
 
VMware Cloud on AWS -- A Technical Deep Dive PPT
VMware Cloud on AWS -- A Technical Deep Dive PPTVMware Cloud on AWS -- A Technical Deep Dive PPT
VMware Cloud on AWS -- A Technical Deep Dive PPTAmazon Web Services
 
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...Amazon Web Services
 

Similar to ARC402_Architectural Patterns and Best Practices with VMware Cloud on AWS (20)

VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...
VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...
VMware Cloud on AWS: Networking and Storage Best Practices - AWS Online Tech ...
 
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS Summit
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS SummitVMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS Summit
VMware Cloud on AWS: Technical Deep Dive - SRV341 - Chicago AWS Summit
 
VMware Cloud on AWS – Technical Deep Dive.pdf
VMware Cloud on AWS – Technical Deep Dive.pdfVMware Cloud on AWS – Technical Deep Dive.pdf
VMware Cloud on AWS – Technical Deep Dive.pdf
 
VMware Cloud on AWS - Technical Deep Dive - AWS Summit Sydney
VMware Cloud on AWS - Technical Deep Dive - AWS Summit SydneyVMware Cloud on AWS - Technical Deep Dive - AWS Summit Sydney
VMware Cloud on AWS - Technical Deep Dive - AWS Summit Sydney
 
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdfHybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
 
Integrating with VMware Cloud on AWS
Integrating with VMware Cloud on AWSIntegrating with VMware Cloud on AWS
Integrating with VMware Cloud on AWS
 
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018
Get Hands on with VMware Cloud on AWS (ENT329-R1) - AWS re:Invent 2018
 
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...
Running Production Workloads in VMware Cloud on AWS (ENT313-S) - AWS re:Inven...
 
VMware cloud on AWS
VMware cloud on AWSVMware cloud on AWS
VMware cloud on AWS
 
Sessão Avançada: VMware Cloud na AWS - ENT204 - Sao Paulo Summit
Sessão Avançada: VMware Cloud na AWS -  ENT204 - Sao Paulo SummitSessão Avançada: VMware Cloud na AWS -  ENT204 - Sao Paulo Summit
Sessão Avançada: VMware Cloud na AWS - ENT204 - Sao Paulo Summit
 
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptxVMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
 
VMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPTVMware on AWS A Technical Deep Dive PPT
VMware on AWS A Technical Deep Dive PPT
 
VMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning SeriesVMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning Series
 
SRV320 Deep Dive on VMware Cloud on AWS
 SRV320 Deep Dive on VMware Cloud on AWS SRV320 Deep Dive on VMware Cloud on AWS
SRV320 Deep Dive on VMware Cloud on AWS
 
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
Networking, Storage, and Data Protection Deep Dive with VMware Cloud on AWS (...
 
VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28
 
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017
VMware Cloud on AWS Technical Deep Dive - ENT303 - re:Invent 2017
 
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWS
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWSVMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWS
VMware on AWS를 통한 하이브리드 클라우드 구축 적용 - 홍정진, AWS Partner SA/ VMC on AWS
 
VMware Cloud on AWS -- A Technical Deep Dive PPT
VMware Cloud on AWS -- A Technical Deep Dive PPTVMware Cloud on AWS -- A Technical Deep Dive PPT
VMware Cloud on AWS -- A Technical Deep Dive PPT
 
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...
Migrating to VMware on AWS as the First Step Towards the AWS Cloud (GPSCT206)...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

ARC402_Architectural Patterns and Best Practices with VMware Cloud on AWS

  • 1. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Architectural Patterns and Best Practices with VMware Cloud on AWS Andy Reedy, AWS Partner Solutions Architecture N o v e m b e r 3 0 , 2 0 1 7 A R C 4 0 2
  • 2. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is VMware Cloud on AWS On-Demand, VMware Software Defined Datacenter Delivered as a Cloud Service ESXi NSX vSphere VSAN Latest Software VCSA, ESXi, NSX, VSAN, Managed by VMware Dynamic Capacity DRS/HA Compute Cluster (Intel x86) VSAN Storage Cluster (NVMe Flash) NSX Network Virtualization (ENA) Software Defined Data Center
  • 3. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is VMware Cloud on AWS Compute • Bare Metal • I3.16XL Equivalent • 36 Cores/72 vCPUs • 512GiB Memory15TiB* • NVMe All-Flash Storage • 25Gb ENA ESXi NSX vSphere VSAN Software Defined Data Center Hypervisor • ESXi • 4 to 32 Host Cluster • Maintained by VMware • No SSH/Root • No VIBs/Plugins Storage • VSAN • Aggregate Instance Storage • All Flash (Capacity/Cache) • No EBS/EFS • VM Storage Policies Network and Security • NSX • Logical Networks • North/South Firewalling • Compute/Management Gateways • IPSec Termination • NAT vSphere • VMware Managed • Delegated Permissions • Hybrid Linked Mode
  • 4. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is VMware Cloud on AWS ESXi NSX vSphere VSAN Software Defined Data Center ESXi vSphere vCentervCenter Customer Data Center
  • 5. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Account structure
  • 6. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Common use cases Data center expansion Maintain Consolidation Migrate Consolidate Workload flexibility Expand
  • 7. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Getting started vmc.vmware.com Create a new SDDC • SDDC Name • Number of Hosts (4 to 32) • AWS Region (Oregon, Virginia) VMware Cloud on AWS Console • my.vmware.com credentials • Organizations • Identity and Access Management
  • 8. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Connecting to an AWS account IAM Cross Account Role AWS Managed Policy Customer-Owned AWS Account CloudFormation Template VMware Cloud on AWS SDDC Account Customer IAM UserVMware Cloud Management Services vmc.vmware.com
  • 9. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Accessing VMware Cloud on AWS • Hybrid Linked-Mode • Logical network configuration • Virtual machine administration • VM storage policies • Add and remove ESXi hosts • Console user and role management • Firewall configuration • EIP and NAT configuration • VPN connectivity vmc.vmware.com vSphere H5 Web Client
  • 10. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Underlay and overlay networks 172.31.1.0/24 Logical Network 1 192.168.1.0/24 Logical Network 2 192.168.2.0/24 VM 1 VM 2 Logical Network 1 192.168.1.0/24 Logical Network 2 192.168.2.0/24 VM 3 VM 4 .10 .11 MAC IP VXLANUDP MAC IP PAYLOAD SRC: 172.31.1.10 DST: 172.31.1.11 SRC: 192.168.1.50 DST: 192.168.1.51 .50 .51 Underlay Overlay
  • 11. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VMware Cloud on AWS: Underlay VMware Cloud on AWS SDDC Account NSX VPC Subnet – x.x.x.x/yy VPC Subnet – x.x.x.x/yy VPC Subnet – x.x.x.x/yy Management VXLAN Storage
  • 12. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. VMware Cloud on AWS: Overlay VMware Cloud on AWS SDDC Account NSX VCSA NSX MGR Management Gateway (MGW) Compute Gateway (CGW) VM VM Management Customer Workloads
  • 13. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Compute Gateway CGW Logical Networks Connected AWS Account Internet • North/South Firewall • NAT • IPSec VPN Termination • AWS Account Connectivity
  • 14. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Customer AWS account connectivity VMware Cloud on AWS SDDC Account Host-1 Host-2 Host-3 Host-4 CGW Customer Owned AWS Account VPC Subnet 1 VPC Subnet 2 VM Customer Workloads Amazon Redshift Logical Network Route Table
  • 15. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. On-premises connectivity Customer Data Center Compute Clusters VM vSphere VM Management vSphere NSX MGR CGW VM Management Logical Network 1 VM MGW IGW Internet Direct Connect VMK VMware Cloud on AWS SDDC VGW
  • 16. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Best practices and considerations Global IP Address Plan • On-Premises Data Centers • Logical Networks • Management Networks /23 to /16 • AWS Accounts and VPCs—Multiple Regions • Additional SDDCs
  • 17. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Best practices and considerations SDDC to AWS connectivity • One-to-One SDDC to AWS VPC • Subnet/AZ placement—cost optimization
  • 18. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Best practices and considerations Plan for Workload Mobility • Connectivity between VPC CIDR and on-premises environments • L2 versus L3 VPN • Direct Connect • Backups
  • 19. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Hybrid connectivity Customer Datacenters VMware Cloud SDDC Customer- Owned AWS Account VPC ENIs for Compute Gateway L2VPN IPSec VPN x2 Direct Connect* IPSec VPN Direct Connect
  • 20. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Multi-region 172.29.1.0/24 MS SQL MS SQL CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Customer AWS Account Amazon Redshift Customer AWS Account 172.28.1.0/24 US-WEST-2 CA-CENTRAL-1 App1 App1 IPSec VPN
  • 21. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Use with ALB 172.29.1.0/24 VM VM CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Customer AWS Account ALBIGW IP Target Group • 172.31.1.100 • 172.31.1.101 WAF Visitor ENI
  • 22. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Storage 172.29.1.0/24 VM VM CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Customer AWS Account Amazon S3 VPC Endpoint ENI Amazon EFS
  • 23. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DNS VM VM CGW Logical Network 172.31.1.0/24 VMware Cloud on AWS SDDC Account Customer Owned AWS Account VPC Subnet 1 VPC Subnet 2 Simple AD Amazon Route 53 ENI Private Hosted Zone VPC DNS
  • 24. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Best practices and considerations Security, visibility, and operational auditing • Two firewall control points: Security Group and NSX CGW • Enable VPC Flow Logs • Enable AWS CloudTrail
  • 25. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Best practices and considerations Treat this as a cloud service • Evaluate your consolidation ratios and utilization tolerance • Leverage elasticity — this is not colocation! Automation • VMware Cloud on AWS API • vSphere • AWS
  • 26. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Other considerations • Logical Networks — Multicast • ESXi hosts are dedicated — Windows licensing • Any vSphere supported operating system • Host oversubscription • Custom VM geometry — 1vCPU x 64 GB RAM
  • 27. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Wrap-up • Wholistic address planning • Account, VPC, and AZ placement considerations • Plan for workload mobility • Treat this as a cloud service • Automate all-the-things!
  • 28. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Next Steps • VMware Cloud on AWS Hands-on-labs (HOL) • ARC322 - AWS Native Services Integration • ENT303 - VMware Cloud on AWS Technical Deep Dive • ENT204 - Unique Integrations Between VMware & AWS
  • 29. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Thank you! Pl ease compl ete the survey.