7.0

Table Of Contents
Security Policy
A security policy is a set of endpoint, firewall, and network introspection services that can be applied to a
security group. You can add security policies to a vSphere virtual machine by using an on-demand
security group in a blueprint. You cannot add a security policy directly to a reservation. After data
collection, the security policies that have been defined in NSX for a compute resource are available for
selection in a blueprint.
App Isolation
When App isolation is enabled, a separate security policy is created. App isolation uses a logical firewall
to block all inbound and outbound traffic to the applications in the blueprint. Component machines that are
provisioned by a blueprint that contains an app isolation policy can communicate with each other but
cannot connect outside the firewall unless other security groups are added to the blueprint with security
policies that allow access.
Add an Existing Security Group Component
You can add an existing security group component to the design canvas in preparation for associating its
settings to one or more machine components or other available component types in the blueprint.
You can use an existing security group component to add an NSX security group to the design canvas
and configure its settings for use with vSphere machine components and Software or XaaS components
that pertain to vSphere.
You can add multiple network and security components to the blueprint design canvas.
Prerequisites
n
Create and configure a security group in NSX. See Configuring vRealize Automation and NSX
Administration Guide.
n
Verify that the NSX plug-in for vRealize Automation is installed and that the NSX inventory has
executed successfully for your cluster .
To use NSX configurations in vRealize Automation, you must install the NSX plug-in and run data
collection.
n
Log in to the vRealize Automation console as an infrastructure architect.
n
Open a new or existing blueprint in the design canvas by using the Design tab.
Procedure
1 Click Network & Security in the Categories section to display the list of available network and
security components.
2 Drag an Existing Security Group component onto the design canvas.
3 Select an existing security group from the Security Group drop-down menu.
4 Click OK.
5 Click Finish to save the blueprint as draft or continue configuring the blueprint.
Configuring vRealize Automation
VMware, Inc. 305