VCAP6-NV Deploy - Objective 3.1 - Configure and Manage Logical Load Balancing
VMware NSX-V VCAP6-NV VCIX6-NV HOWTO
Published on 30 July 2017 by Christopher Lewis. Words: 543. Reading Time: 3 mins.
data:image/s3,"s3://crabby-images/f2f52/f2f5241dfd65288cee9fb1f0e2bd541ae1acf4f9" alt=""
Skills and Abilities
Objective 3.1 - Configure and Manage Logical Load Balancing
- Configure the appropriate Load Balancer model for a given application topology.
- Configure SSL off-loading.
- Configure a service monitor to define health check parameters for a specific type of network traffic.
- Optimize a server pool to manage and share backend servers.
- Configure an application profile and rules.
- Configure virtual servers.
Objective Prerequisites
The following prerequisites are assumed for this Objective:
- A working VMware vSphere 6.x environment.
- A working VMware NSX 6.x environment.
Objective Breakdown
Configure the appropriate Load Balancer model for a given application topology
VMware NSX provides two types of Load Balancer, Layer 4 (packet-based) and Layer 7 (socket-based). All NSX LBs are created as Layer 7 unless the Enable Acceleration checkbox as part of the deployment, then a Layer 4 LB created.
There are two types of VMware NSX LB deployment modes, Proxy Mode (one-arm) and Transparent Mode (inline). For more information see the VMware NSX Design Guide .
How to enable and configure an VMware NSX Load Balancer, see HOWTO: Configure VMware NSX Load Balancing
Configure SSL off-loading
There are a few steps to configuring SSL Off-loading:
- Upload the Certificate Chain SSL Certificate.
- Upload the SSL Certificate (or generate a self-signed one) and Private Key.
- Configure an Application Profile for SSL Offloading.
- Assign the Profile to a Virtual Server.
The following steps assume you have logged into VMware vCenter and can locate the appropriate ESG and that Load Balancing is already enabled.
Upload the Certificate Root CA & SubCA SSL Certificate
Navigate to Networking and Security > NSX Edges > [ESG Name] > Manage > Settings > Certificates.
data:image/s3,"s3://crabby-images/42bd6/42bd66367df0495aa068f7b2f3dfc46b55da7564" alt=""
Click Add(+).
data:image/s3,"s3://crabby-images/e0c2c/e0c2c345e3b805e38da5b2cf7d95e854d7ef5257" alt=""
Select CA Certificate.
data:image/s3,"s3://crabby-images/8fc29/8fc29e14aa970f34f593641d10653cd576352b8d" alt=""
Copy the contents of the CA Certificate file (including -----BEGIN CERTIFICATE-----
and -----END CERTIFICATE-----
).
data:image/s3,"s3://crabby-images/ee338/ee338b4243b926728d4062b023f4458fac9b86a1" alt=""
Click OK.
Upload the SSL Certificate (or generate a self-signed one) and Private Key.
Click Add(+).
data:image/s3,"s3://crabby-images/96ec1/96ec17ef115e09f0617788b61145fafe8d918a5e" alt=""
Select Certificate.
data:image/s3,"s3://crabby-images/9d540/9d540863236b2c567fdbd5c8a9a4ca0f31ad7641" alt=""
Copy the contents of the Certificate file (including -----BEGIN CERTIFICATE-----
and -----END CERTIFICATE-----
) and the RSA Key file (including -----BEGIN RSA PRIVATE KEY-----
and -----END RSA PRIVATE KEY-----
).
data:image/s3,"s3://crabby-images/2fd9a/2fd9a06ff4b0ac3d7de591f336606aa41476577a" alt=""
Click OK.
data:image/s3,"s3://crabby-images/0c931/0c931d388d1122ba1cb1063121d7076de0397036" alt=""
Configure an Application Profile for SSL Offloading
Navigate to Networking and Security > NSX Edges > [ESG Name] > Manage > Load Balancer > Application Profiles.
data:image/s3,"s3://crabby-images/65052/65052e74165a5c32078b79c736cf5f9f4b14f4c1" alt=""
Click Add(+).
data:image/s3,"s3://crabby-images/bea5d/bea5daaeca454704fc7a6ccc9fc811d6f5a8337d" alt=""
Enter the Name for the new Application Profile and select HTTPS from the Type dropdown.
data:image/s3,"s3://crabby-images/c469a/c469a04cbd279e01c47b57f1b862cbc09d3e80a1" alt=""
Select Service Certificates and check the Configure Service Certificate checkbox.
data:image/s3,"s3://crabby-images/b4be1/b4be1243d36c0880af9911600517a25c75606029" alt=""
Select the appropriate Service Certificate and click CA Certificates.
data:image/s3,"s3://crabby-images/387ad/387ad54b8b5d1190881801d2a69bbc1ae6f81d73" alt=""
Check the checkbox of the corresponding CA Certificate.
data:image/s3,"s3://crabby-images/bacff/bacff9fe121c58962f4d5777c3f3bab21ba2a1f3" alt=""
Click OK.
data:image/s3,"s3://crabby-images/2319c/2319cc7716191499436e0721e2c4f593b0a101d1" alt=""
Assign the Profile to a Virtual Server
This is no different from the normal process of assigning an Application Profile to a Virtual Server. Therefore, see HOWTO: Configure VMware NSX Load Balancing .
Configure a service monitor to define health check parameters for a specific type of network traffic
I believe I have provided sufficient guidance in the HOWTO: Configure VMware NSX Load Balancing post.
Optimize a server pool to manage and share backend servers
I believe I have provided sufficient guidance in the HOWTO: Configure VMware NSX Load Balancing post.
Configure an application profile and rules
I believe I have provided sufficient guidance in the HOWTO: Configure VMware NSX Load Balancing post.
Configure virtual servers
I believe I have provided sufficient guidance in the HOWTO: Configure VMware NSX Load Balancing post.
Published on 30 July 2017 by Christopher Lewis. Words: 543. Reading Time: 3 mins.
- VCAP6-NV Deploy - Objective 2.3 - Configure and Manage Routing ()
- VCAP6-NV Deploy - Objective 5.3 - Configure and Manage Role Based Access Control ()
- VCAP6-NV Deploy - Objective 8.1 - Administer and Execute calls using the VMware NSX vSphere API ()
- VCAP6-NV Deploy - Objective 2.1 - Create and Manage Logical Switches ()
- VCAP6-NV Deploy - Objective 1.3 - Configure and Manage Transport Zones ()