7.2

Table Of Contents
n
Log in to the vRealize Orchestrator client as an administrator.
n
Verify that you ran the Create NSX endpoint vRO work flow.
Procedure
1 Click the Workflow tab and select NSX > NSX workflows for VCAC.
2 Run the Create NSX endpoint workflow and respond to prompts.
3 Run the Enable security policy support for overlapping subnets workflow.
4 Select the NSX endpoint as the input parameter for the workflow.
Use the IP address you specified when you created the vSphere endpoint to register an NSX
instance.
After you run this workflow, the distributed firewall rules defined in the security policy are applied only on
the vNICs of the security group members to which this security policy is applied.
What to do next
Apply the applicable security features for the blueprint.
Administrator Requirements for Provisioning NSX Universal Objects
To provision machines in a cross-vCenter deployment when using NSX universal objects such as an edge
gateway or load balancer, you must provision to a region in which the compute NSX manager has the
primary role.
There is only one primary NSX manager in a cross-vCenter NSX environment. To provision machines in a
cross-vCenter deployment, the machines must reside in a region in which the NSX compute manager has
the primary role. Provisioning fails when the machines exist in a region in which the compute NSX
manager has the secondary role.
You can use NSX local objects, such as a local edge gateway or load balancer. When using NSX local
objects, you must also use a region-specific NSX local transport zone and object virtual wire. You can
configure vRealize Automation reservations to use the local transport zone and virtual wires for
deployments in that local region.
See the VMware Knowledge Base article Deployment of vRealize Automation blueprints with NSX objects
fail (2147240) at http://kb.vmware.com/kb/2147240 for more information.
See the NSX Administration Guide and Cross-vCenter NSX Installation Guide for information about how
to configure and assign the primary NSX manager role for a cross-vCenter deployment.
Checklist for Preparing For Third-Party IPAM Provider Support
You can obtain IP addresses and ranges for use in network profile definition from a supported third-party
IPAM provider, such as Infoblox.
Configuring vRealize Automation
VMware, Inc. 13