Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save explicitworkload/d5741d9de1cc3d5d76242ea94f7c4a77 to your computer and use it in GitHub Desktop.

Select an option

Save explicitworkload/d5741d9de1cc3d5d76242ea94f7c4a77 to your computer and use it in GitHub Desktop.

Revisions

  1. @papivot papivot revised this gist Feb 28, 2022. 1 changed file with 2 additions and 2 deletions.
    4 changes: 2 additions & 2 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -70,8 +70,8 @@ open ports to ALL IPs corresponding to - ,,,,,
    [account_name].tmc.cloud.vmware.com and ,,,,,
    extensions.aws-usw2.tmc.cloud.vmware.com,,,,,
    ,,,,,
    2. This doc assumes there is no firewall WITHIN,,,,,
    a subnet/VLAN,,,,,
    2. This doc assumes there is no firewall,,,,,
    WITHIN a subnet/VLAN,,,,,
    ,,,,,
    3. Supervisor Workload IP Range & ,,,,,
    Workload Cluster IP Range ,,,,,
  2. @papivot papivot revised this gist Feb 28, 2022. 1 changed file with 7 additions and 4 deletions.
    11 changes: 7 additions & 4 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -63,14 +63,17 @@ vCenter Server,Supervisor Management IP Range,443,TCP,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    ,,,,,
    Notes,,,,,
    Notes:-,,,,,
    ,,,,,
    "1. For TMC, if firewalls do not allow wildcard ",,,,,
    open ports to ALL IPs corresponding to - ,,,,,
    [account_name].tmc.cloud.vmware.com and ,,,,,
    extensions.aws-usw2.tmc.cloud.vmware.com,,,,,
    ,,,,,
    2. This doc assumes there is no firewall WITHIN a subnet/VLAN,,,,,
    2. This doc assumes there is no firewall WITHIN,,,,,
    a subnet/VLAN,,,,,
    ,,,,,
    3. Supervisor Workload IP Range* and Workload Cluster IP Range ,,,,,
    are the same subnet/VLAN for the Primary Supervisor Namespace,,,,,
    3. Supervisor Workload IP Range & ,,,,,
    Workload Cluster IP Range ,,,,,
    are the same subnet/VLAN for the,,,,,
    Primary Supervisor Namespace,,,,,
  3. @papivot papivot revised this gist Feb 28, 2022. 1 changed file with 76 additions and 73 deletions.
    149 changes: 76 additions & 73 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -1,73 +1,76 @@
    Source IP Address,Destination IP Address,Port Display,Protocol,Optional/Manditory,Use,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Client,Service Installer VM,22,TCP,,SSH,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access,,,,,,,,,,,,,
    Client,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    Client,Workload Cluster IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    Client,Workload Cluster IP Range,30000-32767,TCP ,(Optional),IF Nodeport Support is requried,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,NTP ,,,,,,,,,,,,,
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity,,,,,,,,,,,,,
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,,,,,,,,,,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Service Installer VM,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Service Installer VM,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Configuration,,,,,,,,,,,,,
    Service Installer VM,vCenter Server,443,TCP,,WCP Configuration ,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,,HTTP Workload,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,Cluster Access,,,,,,,,,,,,,
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional - configure content library from VC UI,,,,,,,,,,,,,
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Supervisor Management IP Range,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,Content Library,,,,,,,,,,,,,
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,AKO connecivity,,,,,,,,,,,,,
    Supervisor Management IP Range,vCenter Server,443,TCP,,Critical !!!,,,,,,,,,,,,,
    Supervisor Management IP Range,NSX ALB VIP Network IP Range,6443,TCP,,Supervisor cluster -> Workload cluster config,,,,,,,,,,,,,
    Supervisor Management IP Range,Workload Cluster IP Range,6443,TCP,,VM Operator and TKC VM communication,,,,,,,,,,,,,
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Supervisor Management IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Supervisor Management IP Range,Private registry,443,TCP,(Optional),,,,,,,,,,,,,,
    Supervisor Management IP Range,TSM and TO (to be expanded later),443,TCP,(Optional),SaaS connecitivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Workload IP Range*,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Supervisor Workload IP Range*,Supervisor Management IP Range,6443,TCP,,,,,,,,,,,,,,,
    Supervisor Workload IP Range*,Workload Cluster IP Range,6443,TCP,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Workload Cluster IP Range,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Workload Cluster IP Range,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Workload Cluster IP Range,NSX ALB VIP Network IP Range,6443,TCP,,,,,,,,,,,,,,,
    Workload Cluster IP Range,NSX ALB Controller(s),443,TCP,(Optional),While using AKOO on guest cluster,,,,,,,,,,,,,
    Workload Cluster IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Workload Cluster IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Workload Cluster IP Range,Private registry,443,TCP,(Optional),,,,,,,,,,,,,,
    Workload Cluster IP Range,TSM and TO (to be expanded later) ,443,TCP,(Optional),SaaS connecitivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,443,TCP,,Superisor Cluster,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,6443,TCP,,Superisor Cluster,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,6443,TCP,,Workload Cluster ,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,80,TCP,(Optional),HTTP Workload,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,443,TCP,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Notes,,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    "For TMC, if firewalls does not allow wildcard then ",all IPs of - ,,,,,,,,,,,,,,,,,
    [account].tmc.cloud.vmware.com and ,extensions.aws-usw2.tmc.cloud.vmware.com,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Assuming no firewall within a subnet/VLAN,,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Workload IP Range* and Workload Cluster IP Range are the same for the Primary Supervisor Namespace,,,,,,,,,,,,,,,,,,
    Source IP Address,Destination IP Address,Port Display,Protocol,Optional/Mandatory,Use
    ,,,,,
    Client,Service Installer VM,22,TCP,,SSH
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access
    Client,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    Client,Workload Cluster IP Range,22,TCP,(Optional),Troubleshooting
    Client,Workload Cluster IP Range,30000-32767,TCP ,(Optional),If Nodeport Support is required
    Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload
    ,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,NTP
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity
    ,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,
    ,,,,,
    Service Installer VM,DNS Server,53,UDP,,DNS
    Service Installer VM,NTP Server,123,UDP,,NTP
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Configuration
    Service Installer VM,vCenter Server,443,TCP,,WCP Configuration
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,,HTTP Workload
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,Cluster Access
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional - configure content library from VC UI
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    ,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,DNS
    Supervisor Management IP Range,NTP Server,123,UDP,,NTP
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,Content Library
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,AKO connectivity
    Supervisor Management IP Range,vCenter Server,443,TCP,,Critical !!!
    Supervisor Management IP Range,NSX ALB VIP Network IP Range,6443,TCP,,Supervisor cluster -> Workload cluster config
    Supervisor Management IP Range,Workload Cluster IP Range,6443,TCP,,VM Operator and TKC VM communication
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,Private registry,443,TCP,(Optional),In a internet restricted env
    Supervisor Management IP Range,TSM and TO (to be expanded later),443,TCP,(Optional),SaaS connectivity
    ,,,,,
    Supervisor Workload IP Range*,DNS Server,53,UDP,,DNS
    Supervisor Workload IP Range*,Supervisor Management IP Range,6443,TCP,,
    Supervisor Workload IP Range*,Workload Cluster IP Range,6443,TCP,,
    ,,,,,
    Workload Cluster IP Range,DNS Server,53,UDP,,DNS
    Workload Cluster IP Range,NTP Server,123,UDP,,NTP
    Workload Cluster IP Range,NSX ALB VIP Network IP Range,6443,TCP,,
    Workload Cluster IP Range,NSX ALB Controller(s),443,TCP,(Optional),While using AKOO on guest cluster
    Workload Cluster IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,Private registry,443,TCP,(Optional),
    Workload Cluster IP Range,TSM and TO (to be expanded later) ,443,TCP,(Optional),SaaS connectivity
    ,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,443,TCP,,Supervisor Cluster
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,6443,TCP,,Supervisor Cluster
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,443,TCP,,HTTPS Workload
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,6443,TCP,,Workload Cluster
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,80,TCP,(Optional),HTTP Workload
    ,,,,,
    vCenter Server,Supervisor Management IP Range,443,TCP,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    ,,,,,
    Notes,,,,,
    ,,,,,
    "1. For TMC, if firewalls do not allow wildcard ",,,,,
    open ports to ALL IPs corresponding to - ,,,,,
    [account_name].tmc.cloud.vmware.com and ,,,,,
    extensions.aws-usw2.tmc.cloud.vmware.com,,,,,
    ,,,,,
    2. This doc assumes there is no firewall WITHIN a subnet/VLAN,,,,,
    ,,,,,
    3. Supervisor Workload IP Range* and Workload Cluster IP Range ,,,,,
    are the same subnet/VLAN for the Primary Supervisor Namespace,,,,,
  4. @papivot papivot revised this gist Feb 28, 2022. 1 changed file with 73 additions and 66 deletions.
    139 changes: 73 additions & 66 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -1,66 +1,73 @@
    Source IP Address,Destination IP Address,Port Display,Protocol,Optional/Manditory,Use
    Client,Workload Cluster IP Range,22,TCP,(Optional),Troubleshooting
    Client,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    Client,Service Installer VM,22,TCP,,SSH
    Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access
    ,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP
    NSX ALB Controller(s),NSX ALB Service Engines (Management),123,UDP,,NTP
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity
    ,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,
    ,,,,,
    Service Installer VM,DNS Server,53,UDP,,DNS
    Service Installer VM,NTP Server,123,UDP,,NTP
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional - configure a subscribed content lib directly on vCenter
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Config
    Service Installer VM,vCenter Server,443,TCP,,WCP Config
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP workload
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,HTTPS workload
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,Cluster Access
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    ,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,DNS
    Supervisor Management IP Range,NTP Server,123,UDP,,NTP
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,Content Library
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,
    Supervisor Management IP Range,vCenter Server,443,TCP,,
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,Private registry,443,TCP,(Optional),
    Supervisor Management IP Range,TSM and TO (to be expanded later),443,TCP,(Optional),SaaS connecitivity
    ,,,,,
    Supervisor Workload IP Range*,DNS Server,53,UDP,,
    Supervisor Workload IP Range*,Supervisor Management IP Range,6443,TCP,,
    Supervisor Workload IP Range*,Workload Cluster IP Range,6443,TCP,,
    ,,,,,
    Workload Cluster IP Range,DNS Server,53,UDP,,
    Workload Cluster IP Range,NTP Server,123,UDP,,
    Workload Cluster IP Range,NSX ALB VIP Network IP Range,6443,TCP,,
    Workload Cluster IP Range,NSX ALB Controller(s),443,TCP,(Optional),While using AKOO on guest cluster
    Workload Cluster IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,Private registry,443,TCP,(Optional),
    Workload Cluster IP Range,TSM and TO (to be expanded later) ,443,TCP,(Optional),SaaS connecitivity
    ,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,443,TCP,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,6443,TCP,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,80,TCP,(Optional),HTTP Workload
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,443,TCP,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,6443,TCP,,
    ,,,,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    vCenter Server,Supervisor Management IP Range,443,TCP,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,
    ,,,,,
    [account_name].tmc.cloud.vmware.com,,,,,
    extensions.aws-usw2.tmc.cloud.vmware.com,,,,,
    ,,,,,
    ,,,,,
    Assuming no firewall within a subnet/VLAN,,,,,
    Source IP Address,Destination IP Address,Port Display,Protocol,Optional/Manditory,Use,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Client,Service Installer VM,22,TCP,,SSH,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access,,,,,,,,,,,,,
    Client,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    Client,Workload Cluster IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    Client,Workload Cluster IP Range,30000-32767,TCP ,(Optional),IF Nodeport Support is requried,,,,,,,,,,,,,
    Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,NTP ,,,,,,,,,,,,,
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity,,,,,,,,,,,,,
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,,,,,,,,,,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Service Installer VM,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Service Installer VM,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Configuration,,,,,,,,,,,,,
    Service Installer VM,vCenter Server,443,TCP,,WCP Configuration ,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,,HTTP Workload,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,Cluster Access,,,,,,,,,,,,,
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional - configure content library from VC UI,,,,,,,,,,,,,
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Supervisor Management IP Range,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,Content Library,,,,,,,,,,,,,
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,AKO connecivity,,,,,,,,,,,,,
    Supervisor Management IP Range,vCenter Server,443,TCP,,Critical !!!,,,,,,,,,,,,,
    Supervisor Management IP Range,NSX ALB VIP Network IP Range,6443,TCP,,Supervisor cluster -> Workload cluster config,,,,,,,,,,,,,
    Supervisor Management IP Range,Workload Cluster IP Range,6443,TCP,,VM Operator and TKC VM communication,,,,,,,,,,,,,
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Supervisor Management IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Supervisor Management IP Range,Private registry,443,TCP,(Optional),,,,,,,,,,,,,,
    Supervisor Management IP Range,TSM and TO (to be expanded later),443,TCP,(Optional),SaaS connecitivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Workload IP Range*,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Supervisor Workload IP Range*,Supervisor Management IP Range,6443,TCP,,,,,,,,,,,,,,,
    Supervisor Workload IP Range*,Workload Cluster IP Range,6443,TCP,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Workload Cluster IP Range,DNS Server,53,UDP,,DNS,,,,,,,,,,,,,
    Workload Cluster IP Range,NTP Server,123,UDP,,NTP,,,,,,,,,,,,,
    Workload Cluster IP Range,NSX ALB VIP Network IP Range,6443,TCP,,,,,,,,,,,,,,,
    Workload Cluster IP Range,NSX ALB Controller(s),443,TCP,(Optional),While using AKOO on guest cluster,,,,,,,,,,,,,
    Workload Cluster IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Workload Cluster IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity,,,,,,,,,,,,,
    Workload Cluster IP Range,Private registry,443,TCP,(Optional),,,,,,,,,,,,,,
    Workload Cluster IP Range,TSM and TO (to be expanded later) ,443,TCP,(Optional),SaaS connecitivity,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,443,TCP,,Superisor Cluster,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,6443,TCP,,Superisor Cluster,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,443,TCP,,HTTPS Workload,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,6443,TCP,,Workload Cluster ,,,,,,,,,,,,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,80,TCP,(Optional),HTTP Workload,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,443,TCP,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,,,,,,,,,,,,,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Notes,,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    "For TMC, if firewalls does not allow wildcard then ",all IPs of - ,,,,,,,,,,,,,,,,,
    [account].tmc.cloud.vmware.com and ,extensions.aws-usw2.tmc.cloud.vmware.com,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Assuming no firewall within a subnet/VLAN,,,,,,,,,,,,,,,,,,
    ,,,,,,,,,,,,,,,,,,
    Supervisor Workload IP Range* and Workload Cluster IP Range are the same for the Primary Supervisor Namespace,,,,,,,,,,,,,,,,,,
  5. @papivot papivot revised this gist Feb 27, 2022. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -17,7 +17,7 @@ NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,
    ,,,,,
    Service Installer VM,DNS Server,53,UDP,,DNS
    Service Installer VM,NTP Server,123,UDP,,NTP
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional, configure a subscribed content lib directly on vCenter
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional - configure a subscribed content lib directly on vCenter
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Config
    Service Installer VM,vCenter Server,443,TCP,,WCP Config
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP workload
  6. @papivot papivot revised this gist Feb 27, 2022. 1 changed file with 1 addition and 1 deletion.
    2 changes: 1 addition & 1 deletion vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -8,7 +8,7 @@ Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access
    ,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,NTP
    NSX ALB Controller(s),NSX ALB Service Engines (Management),123,UDP,,NTP
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity
    ,,,,,
  7. @papivot papivot revised this gist Feb 27, 2022. 1 changed file with 16 additions and 15 deletions.
    31 changes: 16 additions & 15 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -6,28 +6,29 @@ Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access
    ,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,
    NSX ALB Controller(s),NTP Server,123,UDP,,
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,
    NSX ALB Controller(s),vCenter Server,443,TCP,,
    NSX ALB Controller(s),DNS Server,53,UDP,,DNS
    NSX ALB Controller(s),NTP Server,123,UDP,,NTP
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,NTP
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,Infra connectivity
    NSX ALB Controller(s),vCenter Server,443,TCP,,Infra connectivity
    ,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,
    ,,,,,
    Service Installer VM,DNS Server,53,UDP,,
    Service Installer VM,NTP Server,123,UDP,,
    Service Installer VM,wp-content.vmware.com,443,TCP,,
    Service Installer VM,NSX ALB Controller(s),443,TCP,,
    Service Installer VM,vCenter Server,443,TCP,,
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,
    Service Installer VM,DNS Server,53,UDP,,DNS
    Service Installer VM,NTP Server,123,UDP,,NTP
    Service Installer VM,wp-content.vmware.com,443,TCP,(Optional),If Optional, configure a subscribed content lib directly on vCenter
    Service Installer VM,NSX ALB Controller(s),443,TCP,,NSX ALB Config
    Service Installer VM,vCenter Server,443,TCP,,WCP Config
    Service Installer VM,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP workload
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,HTTPS workload
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,Cluster Access
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    ,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,
    Supervisor Management IP Range,NTP Server,123,UDP,,
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,
    Supervisor Management IP Range,DNS Server,53,UDP,,DNS
    Supervisor Management IP Range,NTP Server,123,UDP,,NTP
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,Content Library
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,
    Supervisor Management IP Range,vCenter Server,443,TCP,,
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
  8. @papivot papivot created this gist Feb 27, 2022.
    65 changes: 65 additions & 0 deletions vsphere-with-tanzu-tko-ports.csv
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,65 @@
    Source IP Address,Destination IP Address,Port Display,Protocol,Optional/Manditory,Use
    Client,Workload Cluster IP Range,22,TCP,(Optional),Troubleshooting
    Client,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    Client,Service Installer VM,22,TCP,,SSH
    Client,NSX ALB VIP Network IP Range,80,TCP,(Optional),HTTP Workload
    Client,NSX ALB VIP Network IP Range,443,TCP,,HTTPS Workload
    Client,NSX ALB VIP Network IP Range,6443,TCP,,Cluster access
    ,,,,,
    NSX ALB Controller(s),DNS Server,53,UDP,,
    NSX ALB Controller(s),NTP Server,123,UDP,,
    NSX ALB Controller(s),NSX ALB Service Engines (Management) ,123,UDP,,
    NSX ALB Controller(s),ESXi Server(s),443,TCP,,
    NSX ALB Controller(s),vCenter Server,443,TCP,,
    ,,,,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),22,TCP,,
    NSX ALB Service Engines (Management) ,NSX ALB Controller(s),8443,TCP,,
    ,,,,,
    Service Installer VM,DNS Server,53,UDP,,
    Service Installer VM,NTP Server,123,UDP,,
    Service Installer VM,wp-content.vmware.com,443,TCP,,
    Service Installer VM,NSX ALB Controller(s),443,TCP,,
    Service Installer VM,vCenter Server,443,TCP,,
    Service Installer VM,NSX ALB VIP Network IP Range,443,TCP,,
    Service Installer VM,NSX ALB VIP Network IP Range,6443,TCP,,
    Service Installer VM,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Service Installer VM,console.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    ,,,,,
    Supervisor Management IP Range,DNS Server,53,UDP,,
    Supervisor Management IP Range,NTP Server,123,UDP,,
    Supervisor Management IP Range,wp-content.vmware.com,443,TCP,,
    Supervisor Management IP Range,NSX ALB Controller(s),443,TCP,,
    Supervisor Management IP Range,vCenter Server,443,TCP,,
    Supervisor Management IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Supervisor Management IP Range,Private registry,443,TCP,(Optional),
    Supervisor Management IP Range,TSM and TO (to be expanded later),443,TCP,(Optional),SaaS connecitivity
    ,,,,,
    Supervisor Workload IP Range*,DNS Server,53,UDP,,
    Supervisor Workload IP Range*,Supervisor Management IP Range,6443,TCP,,
    Supervisor Workload IP Range*,Workload Cluster IP Range,6443,TCP,,
    ,,,,,
    Workload Cluster IP Range,DNS Server,53,UDP,,
    Workload Cluster IP Range,NTP Server,123,UDP,,
    Workload Cluster IP Range,NSX ALB VIP Network IP Range,6443,TCP,,
    Workload Cluster IP Range,NSX ALB Controller(s),443,TCP,(Optional),While using AKOO on guest cluster
    Workload Cluster IP Range,*.tmc.cloud.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,projects.registry.vmware.com,443,TCP,(Optional),TMC Connectivity
    Workload Cluster IP Range,Private registry,443,TCP,(Optional),
    Workload Cluster IP Range,TSM and TO (to be expanded later) ,443,TCP,(Optional),SaaS connecitivity
    ,,,,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,443,TCP,,
    NSX ALB VIP Network IP Range,Supervisor Workload IP Range,6443,TCP,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,80,TCP,(Optional),HTTP Workload
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,443,TCP,,
    NSX ALB VIP Network IP Range,Workload Cluster IP Range,6443,TCP,,
    ,,,,,
    vCenter Server,Supervisor Management IP Range,22,TCP,(Optional),Troubleshooting
    vCenter Server,Supervisor Management IP Range,443,TCP,,
    vCenter Server,Supervisor Management IP Range,6443,TCP,,
    ,,,,,
    [account_name].tmc.cloud.vmware.com,,,,,
    extensions.aws-usw2.tmc.cloud.vmware.com,,,,,
    ,,,,,
    ,,,,,
    Assuming no firewall within a subnet/VLAN,,,,,