Posts

My Best Wishes for 2021

Image
  Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect and CTO Ambassador --- After a year of many challenges, may 2021 bring you and your loved ones a lot of joy and happiness.  Thanks to my Customers and Partners that motivate me with new challenges. This blog is for you all. Thanks to my Team and Colleagues for referring this blog so often internally and externally. And last but not least, thanks to all my readers !! One year we just want to forget My  last day in the  office was on March 10 having a meeting with a large organisation. Since then it was working from home like many of us. I am so lucky to work for a company like  VMware that gave us all the tools and flexibility to work from anywhere. Commuting from home to work My commuting resumes itself to 13 stairs from my home office in the first floor to the living room downstairs. I found myself working much more hours. Difficult to "switch" from work to home.  Nobody likes traffic jams but I found myself mis

CTO Ambassador

Image
  Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- Got a nice surprise in my mailbox today announcing my nomination to the CTO Ambassador program: I am super happy about that. It is a great recognition from VMware and a very special program. I want to thank everyone that helped me and pushed me to achieve this and in particular: Nico Vibert , my buddy who reviewed my application deeply and insisted to talk about my Cisco career.  Roberto Canton , that gave me the most important directions on what to include in my application. Katherine Lightner , for the continuous support she gives to me and to her team. The success of a manager is the success of the team. What is the CTO Ambassador program? The CTO Ambassador program is run by the VMware Office of the CTO.  The CTO Ambassadors are members of a small group of our most experienced and talented customer facing, individual contributor technologists.  They are pre-sales systems engineers (SEs), technical account managers

Adding VMware Transit Connect to Egress VPC (Part 3)

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- UPDATE 6 NOV 2020 : Github terraform code here Finally, here is Part 3 of this blog "series" around Egress VPC. Part 1 is  here and Part 2 is  here After setting up the  Egress VPC in part 1 and adding a VPN connected SDDC in part 2 I want to connect the SDDC and the Apps VPCs via a VMware Transit Connect a.k.a. VMware managed Transit gateway. Lab Setup Creating an SDDC Group I have described in deep details the way to create SDDC group and attach Customer VPCs in this article . Let's go and do that quickly. Create an SDDC group and Attach the SDDC. This step will create the vTGW. Under "VPC Connectivity" tab, configure the Customer AWS  account number so the vTGW resource can be shared. On Customer AWS console, go to RAM (Resource Access Manager) and look for "Resources shared  with me" Accept the vTGW resource Connecting Apps VPCs We have now accepted the shared vTGW resource and

Adding a VMware Cloud on AWS SDDC to an Egress VPC (Part 2)

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- As a follow up to Part 1 on Egress VPC here , I want to add an SDDC to the picture and allow the Virtual Machines on the NSX networks to go out to internet via the Egress VPC and NAT Gateways. Lab Setup Similarly to the setup in Part 1, I will now connect an SDDC with VPN to the TGW like this: Generic considerations Since we want the SDDC internet access via the Egress VPC for Security reasons, we will need a global 0.0.0.0/0 route on the VPN. That's now basically cutting the SDDC IGW access. Because of that, we will need to take care of 2 things: How to access vCenter if we don't have internet on the  SDDC? How do we resolve DNS ? Point 1 For vCenter access I decided to use the SDDC attached VPC via the ENI and deploy a Windows JumpHost there. The attached VPC has its own Internet Gateway. The vCenter resolution will now need to be changed to "Private IP" as described below: Point 2 The DNS default for

Egress VPC and AWS Transit Gateway (Part1)

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- Usually my blog posts are customer driven and recently I have been working on a design that would include an Egress VPC and AWS Transit Gateway. This customer is going to use both VMware Managed Transit Gateway and also AWS Transit Gateway. I will split this post in 3 parts: The Egress VPC - this article Adding a VMC SDDC to the Egress VPC here Adding VMware Managed Transit Gateway here Why do we need an Egress VPC? Numerous posts on AWS site  will describe how to build an Egress VPC and the subtleties of the various route tables of the TGW and the Egress VPC itself. The main goal is to have ONE Internet gateway only  that will allow workloads to go out to internet on the Egress VPC. One of the most important point is redundancy and multi-availability zones. Applications usually reside in private subnets, while NAT Gateways reside in a public subnet. NAT Gateways To focus the Internet access to a single point, we can cre

VMware Transit Connect and SDDC Grouping

Image
Gilles Chekroun Lead VMware Cloud on AWS Solutions Architect --- First of all, I need to say that this is one of my longest post with a lot of new information and features around networking with AWS and SDDC together. With the  recent release of VMware Cloud on AWS ver 1.12 , a major networking feature is now available and that is the VMware Managed Transit Gateway,  also known as VMware Transit Connect. This post will go through a detailed description of what that feature is and the networking capabilities it opens. VMware Transit Connect Until now, the only way to connect an SDDC to a Transit Gateway was via VPN. Route based VPN is described in a previous post here  and how to use PowerCLI for Route based VPN here . By default, AWS creates 2 VPN tunnels and supports Equal Cost Multi-Path (ECMP). Adding more tunnels will certainly add more bandwidth. The VPN tunnels are terminated in the SDDC and a maximum of 4 tu