Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Info

Information

...

Info

Information:

  • [1] HCP VM deployment translates to one vApp in vCloud Director. It therefore creates vApp networks when one VM is deployed via HCP.

  • [2] HCP will assign and configure NAT on Edge Gateway using IPs from provider Network, if configured in HCP IP Pool.

  • [3] HCP deploys one vApp per VM and hence creates vApp networks for each VM.

  • [4] Multi-Tier vApp templates are not supported. This feature is available using HCP Blueprints.

  • Refer Appendix-A and Appendix-B for VM Template preparation guidelines.

Firewall Requirements

...

A firewall is a network security device that monitors incoming and outgoing network traffic, and permits or blocks data packets based on a set of security rules. Its purpose is to establish a barrier between your internal network and the incoming traffic from external sources such as the internet in order to block malicious traffic like viruses and hackers.

All applicable firewalls must be configured with the following ports:

Note

Caution

HyperGrid will provide the Kubernetes Load Balancer IP address mentioned below.

Service

Source

Destination

Protocol/Ports

Authentication

HyperCloud AMPQ IP

AD/LDAP Services

TCP: 389,636



SAML IDP

TCP: 443

Service Orchestration

HyperCloud AMPQ IP

Microsoft Failover Cluster 1

TCP: 4434 1



VMware vCenter Server 1

TCP: 443 1



Ovirt Manager (KVM) 1

TCP: 443 1



VMware vCloud Director 1

TCP: 443 1





Service Orchestration

HyperCloud AMPQ IP

Linux/Windows VMs

TCP: 22 2

Notification

HyperCloud AMPQ IP

SMTP Relay Mail Server

TCP: 25,465, 587

Agent

Linux/Windows VMs

HyperCloudâ„¢ URL & AMPQ IP

TCP: 443, 5671


Linux/Windows VMs

https://repo.skygrid.cloud/*

TCP: 443

Notes:

  • (1)Ensure Private Cloud Providers have a public NAT only to SaaS HyperCloudTM Portal IP Addresses provided by HyperGrid.

  • (2)Only needed if HyperCloudTM will install the HyperCloudTM Agent via SSH.

    • Ignore if Agent is pre-installed or installed on demand via cloud-init (Recommended) for VMware/Hyper-V/KVM Templates