Users Guide
Cloud Foundation and SDDC design
considerations
VMware Cloud Foundation relies on a set of key infrastructure services to be made available externally. You must configure these external
services before you begin deployment.
NOTE: This section is universal for Cloud Foundation deployments regardless of hardware platform. The content in this
section is also available in the VMware Cloud Foundation Planning and Preparation Guide, and is included here for
reference. The original content in the VMware website includes additional sections which are not in the scope of this
document.
Topics:
• External services overview
• Physical network requirements
• Network pools
• VLANs and IP subnets
• Host names and IP addresses
External services overview
Many external services are required for the initial deployment of Cloud Foundation and for the deployment of other optional components
such as vRealize Operations or vRealize Automation. The following table lists the required and optional external services and
dependencies:
Table 2. Required and optional external services and dependencies
Service Purpose
Active Directory (AD)
(Optional) Provides authentication and authorization.
NOTE: AD is required if you are deploying vRealize
Automation.
Dynamic Host Configuration Protocol (DHCP) Provides automated IP address allocation for VXLAN Tunnel
Endpoints (TEPs).
Domain Name Service (DNS) Provides name resolution for the various components in the
solution.
Network Time Protocol (NTP) Synchronizes time between the various components.
Simple Message Transfer Protocol (SMTP) (Optional) Provides method for email alerts.
Certificate Authority (CA)
(Optional) Allows replacement of the initial self-signed certificates
that are used by Cloud Foundation.
NOTE: A CA is required if you are deploying vRealize
Automation.
Active Directory
Cloud Foundation uses Active Directory (AD) for authentication and authorization to resources. The Active Directory services must be
reachable by the components that are connected to the management and vRealize networks.
You must configure user and group accounts in AD before adding them to the SDDC manager and assigning privileges.
7
Cloud Foundation and SDDC design considerations 27