Install NCP in a Tanzu Application Service
EnvironmentLast Updated October 11, 2024
NCP is installed through the Tanzu
Application Service (TAS) Ops Manager graphical user interface.
- A fresh installation of Ops Manager,NSX, and TAS. Make sure that Ops Manager is installed first, thenNSX, and then TAS. For more information, see the Tanzu Application Service documentation.
- If you are running TAS 2.13, you must download the Jammy stemcell.
- Download the NCP installation file for TAS.The file name isVMware-NSX-T.<version>.<build>.pivotal.
- Log in to Ops Manager as an administrator.
- ClickImport a Product.
- Select the file that was downloaded.
- Click theOps Manager Director for VMware vSpheretile.
- In theSettingstab forvCenter Config, selectNSX Networkingand forNSX Mode, selectNSX-T.
- In theNSX CA Certfield, provide the certificate in PEM format.
- ClickSave.
- ClickInstallation Dashboardin the upper left corner to return to the dashboard.
- Click theTanzu Application Servicetile.
- In theSettingstab, selectNetworkingin the navigation pane.
- UnderContainer Network Interface Plugin, selectExternal.
- ClickInstallation Dashboardin the upper left corner to return to the dashboard.
- ClickSave.
- ClickInstallation Dashboardin the upper left corner to return to the dashboard.
- Click theVMware NSX-Ttile.
- Enter the address of theNSX Manager.
- Select the method forNSX Managerauthentication.OptionActionClient Certificate AuthenticationProvide the certificate and private key for NSX Manager.Basic Authentication with Username and PasswordProvide the NSX Manager administrator user name and password.
- In theNSX Manager CA Certfield, provide the certificate.
- ClickSave.
- SelectNCPin the navigation pane.
- Enter theTAS Foundation Name.This string uniquely identifies a TAS foundation in NSX API. This string is also used as the prefix in the names of NSX resources created by NCP for the TAS foundation.
- Enter theOverlay Transport Zone.
- Enter theTier-0 Router.
- Specify one or moreIP Blocks of Container Networks.
- ClickAdd.
- EnterIP Block Name. It can be a new or existing IP block.
- For a new IP block only, specify the block in CIDR format, for example, 10.1.0.0/16.
- Specify the subnet prefix of the container networks.
- ClickEnable SNAT for Container Networksto enable SNAT.
- Specify one or moreIP Pools used to provide External (NAT) IP Address to Org Networks.
- ClickAdd.
- EnterIP Pool Name. It can be a new or existing IP pool.
- For a new IP pool only, specify the IP addresses by providing the CIDR and the IP ranges.
- Enter theTop Firewall Section Marker.
- Enter theBottom Firewall Section Marker.
- Enable or disable the following options.OptionDefault ValueLog Dropped Application TrafficDisabled. If enabled, traffic that is dropped due to a firewall rule will be logged.Enable Debug Level for NCP LoggingEnabled.
- ClickSave.
- SelectNSX Node Agentin the navigation pane.
- CheckEnable Debug Level of Logging for NSX Node Agentto enable debug level logging.
- ClickSave.
- ClickInstallation Dashboardin the upper left corner to return to the dashboard.
- ClickApply Changes.