7.0

Table Of Contents
Depending on the compute resource, you can select a transport zone that identifies a vSphere endpoint.
A transport zone specifies the hosts and clusters that can be associated with logical switches created
within the zone. A transport zone can span multiple vSphere clusters. The blueprint and the reservations
used in the provisioning must have the same transport zone setting. Transport zones are defined in the
NSX and vCloud Networking and Security environments. See NSX Administration Guide.
Using Security Components in the Blueprint Canvas
You can add NSX security components to the canvas to make their configured settings available to one or
more vSphere machine components in the blueprint.
Security groups, tags, and policies are configured outside of vRealize Automation in the NSX application.
The network and security component settings that you add to the blueprint design canvas are derived
from your NSX configuration and require that you have installed the NSX plug-in and run data collection
for the NSX inventory for vSphere clusters. Network and security components are specific to NSX and are
available for use with vSphere machine components only. For information about configuring NSX, see
NSX Administration Guide.
You can add security controls to blueprints by configuring security groups, tags, and policies for the
vSphere compute resource in NSX. After you run data collection, the security configurations are available
for selection in vRealize Automation.
Security Group
A security group is a collection of assets or grouping objects from the vSphere inventory that is mapped
to a set of security policies, for example distributed firewall rules and third party security service
integrations such as anti-virus and intrusion detection. The grouping feature enables you to create custom
containers to which you can assign resources, such as virtual machines and network adapters, for
distributed firewall protection. After a group is defined, you can add the group as source or destination to
a firewall rule for protection.
You can add security groups to a blueprint, in addition to the security groups specified in the reservation.
Security groups are managed in the source resource. For information about managing security groups for
various resource types, see the vendor documentation.
You can add an NSX existing or on-demand security group to the blueprint canvas.
Security Tag
A security tag is a qualifier object or categorizing entry that you can use as a grouping mechanism. You
define the criteria that an object must meet to be added to the security group you are creating. This gives
you the ability to include machines by defining a filter criteria with a number of parameters supported to
match the search criteria. For example, you can add all of the machines tagged with a specified security
tag to a security group.
You can add a security tag to the blueprint canvas.
Configuring vRealize Automation
VMware, Inc. 304