How do I connect a Site Recovery Manager
instance on an Oracle
Cloud VMware Solution SDDC to
a VMware Site
Recovery instance on a VMware Cloud on AWS SDDC
Oracle
Cloud VMware Solution
SDDC to
a VMware Site
Recovery
instance on a VMware Cloud on AWS SDDCThis use case provides
instructions for connecting a
Site
Recovery Manager
instance on an Oracle
Cloud VMware Solution
SDDC site to a VMware Site
Recovery
instance on a VMware Cloud
on AWS
SDDC. You must use a VPN connection to access VMware Site
Recovery
on VMware Cloud
on AWS
and the Site
Recovery Manager
instance on Oracle
Cloud VMware Solution
.Verify that you have deployed
Site
Recovery Manager
and
vSphere
Replication
on
Oracle
Cloud VMware Solution
. See Setting Up Site Recovery Manager on Oracle Cloud VMware Solution. Activate VMware Site
Recovery
VMware Site
Recovery
To use your
Site
Recovery Manager
instance on an Oracle
Cloud VMware Solution
SDDC with a VMware Site
Recovery
service, you must activate the VMware Site
Recovery
service on a VMware
Cloud
™ on AWS
SDDC. - Verify that you have deployed a Software-Defined Data Center (SDDC) onVMware Cloud™ on AWS.
- Log in to theVMware Cloud on AWSConsole at https://vmc.vmware.com.
- Click your SDDC, and then clickIntegrated Services.
- Select Site Recovery and clickActivate.
- Read the information on the Activate Site Recovery page and clickActivate.
Set the NSX-T Edge Management Gateway Firewall Rules for VMware Site
Recovery
NSX-T
Edge Management Gateway Firewall Rules for VMware Site
Recovery
To enable
VMware Site
Recovery
on your SDDC environment that uses VMware NSX-T
®, you must create firewall rules between your VMware Cloud
on AWS
SDDC and the Management Gateway. After the initial firewall rules configuration, you can add, edit or delete any rules as needed.- Log in to theVMware Cloud on AWSConsole at https://vmc.vmware.com.
- Select.
- ClickAdd New Rule.
- Enter the management gateway rule parameters.Management gateway controls management traffic that flows in and out of the SDDC.OptionDescriptionNameEnter a descriptive name for the rule.SourceClickSet Sourceand enter or select one of the following options:
- SelectAnyto allow traffic from any source address or address range.Although you can selectAnyas the source address in a firewall rule, usingAnyas the source address in this firewall rule can enable attacks on your SDDC and might lead to compromise of your SDDC. As a best practice, configure this firewall rule to allow access only from trusted source addresses. See VMware Knowledge Base article 84154.
- SelectSystem Defined Groupsand select one of the following source options.
- vCenterto allow traffic from your SDDC'svCenter Server
- Site Recovery Managerto allow traffic from your SDDC'sSite Recovery Manager.
- vSphere Replicationto allow traffic from your SDDC'svSphere Replication.
- SelectUser Defined Groupsto enter the name and CIDR IP range of a remote network.
DestinationClickSet Destinationand enter or select one of the following options:- SelectAnyto allow traffic to any destination address or address range.
- SelectSystem Defined Groupsand select one of the following destination options.
- vCenterto allow traffic to your SDDC'svCenter Server.
- Site Recovery Managerto allow traffic to your SDDC'sSite Recovery Manager.
- vSphere Replicationto allow traffic to your SDDC'svSphere Replication.
- SelectUser Defined Groupsto enter the name and CIDR IP range of a remote network.
ServiceSelect one of the services to apply the rule to.- HTTPS (TCP 443) applies tovCenter ServerandvSphere Replicationas destinations.
- VMware Site RecoverySRM applies only toSite Recovery Manageras a destination.
- VMware Site RecoveryvSphere Replicationapplies only tovSphere Replicationas a destination.
ActionThe only action available for management gateway firewall rules isAllow. - Repeat the previous step to apply the following firewall rules forVMware Site Recovery.NameSourceDestinationServiceActionRemote SRM tovCenter ServerUser-Defined Group that includes the remoteSite Recovery ManagerIP address.vCenterHTTPS (TCP 443)AllowRemote VR tovCenter ServerUser-Defined Group that includes the remotevSphere ReplicationIP address.vCenterHTTPS (TCP 443)AllowRemote network toSRM(SRM Server Management)User-Defined Group that includes the remoteSite Recovery ManagerandvSphere ReplicationIP addresses.Site Recovery ManagerVMware Site Recovery SRMAllowRemote network toVR(VM Replication)User-Defined Group that includes the remoteESXihosts IP addresses.vSphere ReplicationVMware Site Recovery vSphere ReplicationAllowRemote network toVR(VR Server Management)or User-Defined Group that includes the remoteSite Recovery ManagerandvSphere ReplicationIP addresses.vSphere ReplicationVMware Site Recovery vSphere ReplicationAllowRemote network toVR(UI and API)User-Defined Group that includes the remote browser IP address.vSphere ReplicationVMware Site Recovery vSphere ReplicationAllowSRM(HTTPS) to remote networkSite Recovery ManagerAny or User-Defined Group that includes the remotePlatform Services ControllerandvCenter ServerIP addresses.AnyAllowVR(HTTPS) to remote networkvSphere ReplicationAny or User-Defined Group that includes the remotePlatform Services ControllerandvCenter ServerIP addresses.AnyAllowSRM(SRM Server Management) to remote networkSite Recovery ManagerAny or User-Defined Group that includes the remoteSite Recovery ManagerIP address.AnyAllowVR(SRM Server Management) to remote networkvSphere ReplicationAny or User-Defined Group that includes the remoteSite Recovery ManagerIP address.AnyAllowESXi(VM Replication) to remote networkESXiAny or User-Defined Group that includes the remotevSphere ReplicationIP addresses (combinedvSphere Replicationappliance and any add-onvSphere Replicationappliances).AnyAllowSRM(VR Server Management) to remote networkSite Recovery ManagerAny or User-Defined Group that includes the remotevSphere ReplicationIP address.AnyAllowVR(VR Server Management) to remote networkvSphere ReplicationAny or User-Defined Group that includes the remotevSphere ReplicationIP address.AnyAllow
- ClickPublish.
After the firewall rules are created, they are shown in the Management Gateway Edge Firewall list.
Connect the Site
Recovery Manager Server instances on the Oracle
Cloud VMware Solution SDDC and the VMware Cloud
on AWS SDDC
Site
Recovery Manager Server
instances on the Oracle
Cloud VMware Solution
SDDC and the VMware Cloud
on AWS
SDDCBefore you can protect your
virtual machines between an
Oracle
Cloud VMware Solution
SDDC and a VMware Cloud
on AWS
SDDC and the reverse, you must connect the Site
Recovery Manager Server
and vSphere
Replication
instances on the protected and the recovery sites. This
procedure is known as site pairing.- In thevSphere Client, click .
- Click theNew Site Pairbutton.
- Select the first site from the list. Enter the address of thePlatform Services Controllerfor theSite Recovery Manager Serveron theVMware Cloud on AWSsite, provide the user name and password, and clickNext.
- Select thevCenter Serverand the services you want to pair, and clickNext.
- On theReady to completepage, review the pairing settings, and clickFinish.
The protected and the recovery sites are
connected. The pair appears under
Site Pairs
on the
Site
Recovery
Home tab.