, ,

How to Deploy VCF Operations for Networks in VCF 9.1 (VCF 9.1 Deployment Step by Step Guide, Part 9)

How to deploy VCF Operations for Networks in VCF 9.1, the optional network visibility component: platform and collector nodes, the add-component wizard, and adapter registration.

VCF 9.1 Deployment · Part 9 of 22
Optional
VCF Operations for Networks, also called VON, gives network visibility and diagnostics across the fleet. It is an optional Day-N component, deployed as its own appliances and then registered in VCF Operations. It depends on VCF Operations and NSX being reachable.
Before you deploy. Work through the VCF 9.x pre-installation checklist and confirm your fleet is healthy first.

TL;DR · Key Takeaways

  • Optional Day-N component for network visibility, flow analysis and diagnostics across the fleet.
  • Deployed as its own appliances, a platform node plus one or more collector nodes.
  • Small size suits a small three node environment, add collectors for larger fleets.
  • Deploy from VCF Operations, Lifecycle, Add Component, VCF Operations for Networks.
  • Give a platform node IP and a collector node IP, or a non-management portgroup with netmask, gateway, DNS and NTP.
  • After deployment, register it as a Networks adapter under Operate, Administration, Integrations.

In this part you add VCF Operations for Networks, the fleet component that maps flows, shows topology, and helps you diagnose network problems. It is optional. Unlike log management, which runs on the Management Services cluster, VON deploys as its own platform and collector appliances, then plugs into VCF Operations as a Networks adapter.

Confirm the fleet is healthy, reserve two addresses for the nodes, run the add-component wizard, then register the adapter so VCF Operations pulls network data from NSX. The registration step is easy to forget, so it has its own step below.

Prerequisites

ItemRequirement
VCF OperationsHealthy and reachable, Part 7 complete
NSXReachable, so VON can read topology and flows
IP addresses1 for the platform node and 1 for the collector node
NetworkManagement network, or a non-management portgroup with netmask, gateway, DNS and NTP
LicenseVCF subscription that covers Operations for Networks
For address counts by scenario see the IP address requirements.

Step 1 confirm the fleet is healthy

Start from a healthy, reachable fleet with NSX up.

  1. Log in to the VCF Operations UI as an administrator.
  2. Open Fleet Management and confirm no critical alerts.
  3. Confirm the NSX Managers for the domains you want to see are reachable.

Step 2 reserve node addresses

Reserve one address for each node before you start.

  1. Reserve 1 IP for the platform node.
  2. Reserve 1 IP for the collector node.
  3. Decide whether they sit on the management network or a non-management portgroup, and record the netmask, gateway, DNS and NTP.

Step 3 add the component

Launch the wizard from the lifecycle area.

  1. In VCF Operations, open Lifecycle and click Add Component.
  2. Choose VCF Operations for Networks.
  3. Select New deployment.
  4. Choose version 9.1.0.0 and the Small size.
  5. Click Next.

Step 4 set addresses and network

Enter the node identities and where they live.

  1. Enter the admin password.
  2. Enter the platform node IP.
  3. Enter the collector node IP.
  4. For a non-management network, enter the vSphere portgroup name with netmask, gateway, DNS and NTP.
  5. Click Next.

Step 5 start the deployment

Review and launch, then let the appliances build.

  1. Review the summary of nodes and addresses.
  2. Click Finish.
  3. Watch the task until the component shows Active.

Step 6 register the Networks adapter

Connect VON to VCF Operations so it pulls network data.

  1. In VCF Operations, open Operate, then Administration, then Integrations.
  2. Expand VMware Cloud Foundation and edit your VCF Instance.
  3. Confirm System Managed Credentials is checked.
  4. Select your workload domain collector and enable Operational Actions.
  5. Open the NSX tab and enable Operations for Networks.
  6. Click Save.

Step 7 verify network visibility

Confirm data is flowing before you rely on it.

  1. Open VCF Operations for Networks.
  2. Confirm topology and flow data appear for your domains.
  3. Confirm NSX objects and metrics are populating.
NodeRoleAddresses
Platform nodeFleet level analytics and UI1 IP
Collector nodeGathers flows and metrics from NSX and vCenter1 IP, add collectors to scale
Deployment sizeSmall suits a three node environmentScale up for larger fleets
VON node roles and address needs in VCF 9.1.
NSX and vCenterflows and topologyCollector nodePlatform nodeVCFOperations
Figure 1. The collector gathers network data, the platform node analyzes it, and VCF Operations presents it.
flowchart TD
A[Confirm fleet and NSX health] --> B[Reserve platform and collector IPs]
B --> C[Add VCF Operations for Networks]
C --> D[Enter node IPs and network]
D --> E[Finish and wait for Active]
E --> F[Register the Networks adapter]
F --> G[Verify topology and flows]

Verify network visibility

Confirm the component is Active in Lifecycle and that the Networks adapter is enabled under Integrations. Open VCF Operations for Networks and check that topology, flows and NSX objects populate for your domains. If flows are missing, the adapter registration in Step 6 is the first thing to recheck.

Size collectors for your fleet

A single Small deployment, one platform node and one collector, suits a small three node environment. Collectors do the gathering, so a large estate needs more of them. Add collector nodes as you add workload domains, and step up the deployment size when flow volume climbs. Each collector takes an address, so include them in your management plan. Place collectors close to the NSX and vCenter they read, and avoid pointing one collector at every domain in a large fleet, because that is where flow data starts to show gaps.

Fleet sizeLayoutNotes
Small1 platform, 1 collectorSmall size is enough
Medium1 platform, 2 or more collectorsSplit collectors by domain
LargeScaled size, collectors per siteKeep collectors near their sources

What VCF Operations for Networks shows you

VON maps the network the way it actually runs. It shows flows between workloads, the path a packet takes across segments and gateways, and the topology of your NSX objects. That makes it the tool you open when a connection fails and the firewall rules look correct, because it shows whether traffic is even reaching the segment. It also underpins planning for micro segmentation, since it reveals the real east to west traffic before you write vDefend rules.

Notes and best practices

Register the Networks adapter the moment the appliances go Active, because until you do the platform shows no flows and it looks like the deployment failed when it did not. In a large fleet, run more than one collector and keep each one close to the NSX and vCenter it reads, since a single distant collector is where flow gaps appear. Use VON to baseline real east to west traffic before you design micro segmentation, so your firewall groups match how the applications actually talk rather than how you think they do. Scale the deployment size up before flow volume saturates a Small footprint, not after, because a saturated collector drops data silently. Keep the platform and collector on networks that reach both the NSX managers and the workloads, and confirm name resolution both ways so the adapter stays connected.

Common errors and fixes

No flow or topology data.
The Networks adapter is not registered. Open Operate, Administration, Integrations, edit the VCF Instance and enable Operations for Networks on the NSX tab.

Deployment fails on the address.
The platform or collector IP is in use or on the wrong network. Confirm both addresses are free and reachable on the portgroup you chose.

Wrong portgroup on a non-management deployment.
The vSphere portgroup name must match exactly and carry the netmask, gateway, DNS and NTP you entered. Correct the value and redeploy.

Collector overloaded on a large fleet.
A single small collector cannot cover a big estate. Add collector nodes and scale the deployment size.

Common questions

Is VCF Operations for Networks mandatory
No. It is an optional Day-N component for teams that want flow analysis, topology and network diagnostics.

Where does it run
As its own platform and collector appliances, unlike log management which runs on the Management Services cluster.

How many addresses does it need
One for the platform node and one for the collector node, with more collectors for larger fleets.

Can it sit on a non-management network
Yes. Provide a vSphere portgroup with its netmask, gateway, DNS and NTP during the wizard.

VCF 9.1 Deployment · Part 9 of 22
« Previous: Part 8  |  Complete Guide  |  Next: Part 10 »

References

About The Author


Discover more from Journal of Intelligent Infrastructure

Subscribe to get the latest posts sent to your email.

Leave a Reply

Your email address will not be published. Required fields are marked *

Architect’s Toolkit

About the Author

Dr. Pranay Jha is a Cloud and AI Consultant with 18+ years of experience in hybrid cloud, virtualization, and enterprise infrastructure transformation. He specializes in VMware technologies, multi-cloud strategy, and Generative AI solutions. He holds a PhD in Computer Applications with research focused on Cloud and AI, has published multiple research papers, and has been a VMware vExpert since 2016 and a VMUG Community Leader.

Discover more from Journal of Intelligent Infrastructure

Subscribe now to keep reading and get access to the full archive.

Continue reading