7.2

Table Of Contents
Using Security Components in the Design Canvas
You can add NSX security components to the design canvas to make their configured settings available
to one or more vSphere machine components in the blueprint.
Security groups, tags, and policies are configured outside of vRealize Automation in the NSX application.
The network and security component settings that you add to the design canvas are derived from your
NSX configuration and require that you have installed the NSX plug-in and run data collection for the NSX
inventory for vSphere clusters. Network and security components are specific to NSX and are available
for use with vSphere machine components only. For information about configuring NSX, see NSX
Administration Guide.
You can add security controls to blueprints by configuring security groups, tags, and policies for the
vSphere compute resource in NSX. After you run data collection, the security configurations are available
for selection in vRealize Automation.
Security Group
A security group is a collection of assets or grouping objects from the vSphere inventory that is mapped
to a set of security policies, for example distributed firewall rules and third party security service
integrations such as anti-virus and intrusion detection. The grouping feature enables you to create custom
containers to which you can assign resources, such as virtual machines and network adapters, for
distributed firewall protection. After a group is defined, you can add the group as source or destination to
a firewall rule for protection.
You can add security groups to a blueprint, in addition to the security groups specified in the reservation.
Security groups are managed in the source resource. For information about managing security groups for
various resource types, see the vendor documentation.
You can add an NSX existing or on-demand security group to the design canvas.
Security Tag
A security tag is a qualifier object or categorizing entry that you can use as a grouping mechanism. You
define the criteria that an object must meet to be added to the security group you are creating. This gives
you the ability to include machines by defining a filter criteria with a number of parameters supported to
match the search criteria. For example, you can add all of the machines tagged with a specified security
tag to a security group.
You can add a security tag to the design canvas.
Security Policy
A security policy is a set of endpoint, firewall, and network introspection services that can be applied to a
security group. You can add security policies to a vSphere virtual machine by using an on-demand
security group in a blueprint. You cannot add a security policy directly to a reservation. After data
collection, the security policies that have been defined in NSX for a compute resource are available for
selection in a blueprint.
Configuring vRealize Automation
VMware, Inc. 366