7.4

Table Of Contents
Table 331. NSX Settings Tab Settings
Setting Description
Transport zone Select an existing NSX transport zone to contain the network or networks
that the provisioned machine deployment can use.
A transport zone defines which clusters the networks can span. When
provisioning machines, if a transport zone is specified in a reservation and in
a blueprint, the transport zone values must match. Only the transport zones
that are applicable to the current tenant are available.
A transport zone is only required for blueprints that have an on-demand
network. For security groups, security tags, and load balancers, the transport
zone is optional. If you do not specify a transport zone, the endpoint is
determined by the location of the security group, security tag, or network that
the load balancer connects to.
Edge and routed gateway reservation policy Select an NSX Edge or routed gateway reservation policy. This reservation
policy applies to routed gateways and to all edges that are deployed as part
of provisioning. There is only one edge provisioned per deployment.
For routed networks, edges are not provisioned, but you can use a
reservation policy to select a reservation with the routed gateways to be
used for routed network provisioning.
When vRealize Automation provisions a machine with NAT or routed
networking, it provisions a routed gateway as the network router. The Edge
or routed gateway is a management machine that consumes compute
resources like other virtual machines but manages the network
communications all machine in that deployment. The reservation used to
provision the Edge or routed gateway determines the external network used
for NAT and load balancer virtual IP addresses. As a best practice, use
separate management clusters for management machines such as NSX
Edges.
App isolation Select the App isolation check box to use the app isolation security policy
configured in NSX. The app isolation policy is applied to all vSphere machine
components in the blueprint. You can optionally add NSX security groups
and tags to allow vRealize Orchestrator to open the isolated network
configuration to allow additional paths in and out of the app isolation.
Properties Tab
Custom properties you add at the blueprint level apply to the entire blueprint, including all components.
However, they can be overridden by custom properties assigned later in the precedence chain. For more
information about order of precedence for custom properties, see Custom Properties Reference.
Configuring vRealize Automation
VMware, Inc. 381