Warning! The content within this article is over 36 months old and, therefore, may be out of date.
VCAP6-NV Deploy - Objective 4.2 - Configure and Manage Service Composer
VMware NSX-V VCAP6-NV VCIX6-NV HOWTO
Published on 7 September 2017 by Christopher Lewis. Words: 451. Reading Time: 3 mins.
Objective 4.2 - Configure and Manage Service Composer
Objective Overview
- Create/configure Service Composer according to a deployment plan:
- Configure Security Groups
- Configure Security Policies
- Configure Activity Monitoring for a Security Policy
- Create/edit/delete Security Tags
- Create a Security Tag
- Edit a Security Tag
- Assign a Security Tag
- Detach a Security Tag
- Delete a Security Tag
- Configure Network Introspection
- Configure Guest Introspection
Objective Prerequisites
The following prerequisites are assumed for this Objective:
- A working VMware vSphere 6.x environment.
- A working VMware NSX 6.x environment.
Objective Breakdown
Create/configure Service Composer according to a deployment plan:
Configure Security Groups
Note:
These steps assume you are not even logged into vCenter Server. Skip the first few steps if you are!
- Using your favourite web browser, navigate to the vCenter Server login page (
https://vcenter.fqdn).

- Enter appropriate User name and Password and click Login.

- Click Networking and Security.

- Click Service Composer.

- Click Security Policies tab and then click New Security Group.

- Enter a Name for the new Security Group and click Next.

- Specify the membership requirements for the dynamic membership and click Next.

- Select the Object Type (dropdown), move the objects to the Select Objects list and click Next.

- Select the Object Type (dropdown), move the objects to the Select Objects list and click Next.

- Click Finish.

Configure Security Policies
Note:
These steps assume you are not even logged into vCenter Server. Skip the first few steps if you are!
- Using your favourite web browser, navigate to the vCenter Server login page (
https://vcenter.fqdn).

- Enter appropriate User name and Password and click Login.

- Click Networking and Security.

- Click Service Composer.

- Click Security Policies tab and then New Security Policy.

- Type the Name of the new Policy, (optionally) select the Inherit Security Policy check box and select a Parent Policy (dropdown), then click OK.

Note:
We’re skipping guest introspection services as i haven’t configured anything.
- Click Next.

- Click Add(+).

- Type the Name for the new Firewall Rule and select an Action option (Allow, Reject or Block). (Optional) (Optional) At Source, click Change to choose an Object as the source. (Optional) At Destination, click Change to choose an Object as the destination. (Optional) At Service, click Change to choose the Service type (HTTPS,HTTP etc). At Status, select the Enabled option and (optional) click the Log option.

- Click OK and add additional rules as required.

- Click Next.

- Click Next.

- Click Finish.

Assigning the Security Policy to a Security Group
- Right Click on the Security Policy.

- Click Apply Policy.

- Check the Security Group to apply the Security Policy too.

- Click OK.

Configure Activity Monitoring for a Security Policy
Watch this space!
Create/Edit/Remove Security Tags
See HOWTO: Configure VMware NSX Security Tags
Configure Network Introspection
Watch this space!
Configure Guest Introspection
Watch this space!
Published on 7 September 2017 by Christopher Lewis. Words: 451. Reading Time: 3 mins.
Related Post(s):
About the Author:

Name: Christopher Lewis
Twitter/X: thecloudxpert
Role: Domain Expert - VCF Automation & VCF Operations
Company: Broadcom
Recent Posts by Christopher Lewis:
Blog Categories:
vmware260
certification91
vrealize automation80
vcap48
nsx45
nsx v41
vmworld36
vrealize suite lifecycle manager20
vrealize suite14
vrealize orchestrator13
aria automation9
general9
vexpert9
vmware aria automation9
vsphere9
powercli8
microsoft7
active directory6
powershell6
windows6
certificate authority5
certificates5
vcf5
vmug5
vmware aria operations5
vrealize operations manager5
vsan5
vcenter4
vmware cloud3
aria operations2
aws2
home lab2
vcap62
vcix2
vmware explore2
vmware identity manager2
vrealize business2
Top Tags:
vmware 99+
vrealize automation 74
vcap6 cma 48
vcap6 45
nsx v 43
vcap6 nv 37
vcix6 nv 36
vmworld 35
howto 33
barcelona 24
vrealize orchestrator 21
vrslcm 20
vexpert 19
api 18
vmworld 2016 13
vra 13
certificates 12
vmware aria 12
vsphere 12
vrealize suite lifecycle manager 11
multi tenancy 9
vcap 9
vmware aria automation 9
vmworld 2017 9
platform services controller 8
powercli 8
vmug 8
vrealize operations 8
certification 7
microsoft 7
powershell 7
vsan 7
active directory 6
psc 6
