Skip to content

Connectivity Policy in vCenter

This section describes the procedures for configuring Connectivity Policy using the vSphere Client.

Connectivity Policy defines cross-VPC communication rules.

vCenter Conn Policy


Overview of Connectivity Policy Types

Different Connectivity Policy types are available:

Type Use Case Routing Logic
[Community] Permits communication between VPCs within the same defined group. Ideal for application-tier connectivity within a specific division. VPCs can communicate with other Community peers in their group and all Promiscuous VPCs.
[Isolated] Strictly blocks communication to all other VPCs. Best for highly sensitive or sta ndalone application workloads. VPCs are restricted to communicating only with Promiscuous VPCs (Shared Services).
[Promiscuous] Provides universal connectivity across the environment. Ideal for shared services (e.g., Backup, DNS, NTP). VPCs have unrestricted communication with all other VPCs in the environment.

vCenter Conn Policy Types


Connectivity Policy

Configuration

Deep Dive: Blogs & Video Demonstrations

Step1. Create Connectivity Policy

vCenter Conn Policy config

  • Visibility:
    Set to External.

  • CIDRs/Ranges:
    Enter the specific CIDR blocks or IP ranges to be managed by this block.

  • Excluded IP Ranges:
    (Optional) Specify any IP Range(s) within the CIDRs above that should be withheld from automatic allocation (e.g. IP Range used by the physical network).

  • Reserved for Specific Subnet:
    Enable for the Subnet-VLAN use case, otherwise disabled.

Monitoring

Show other VPCs within your community

vCenter Conn Policy validation

Show VPCs who don't belog to any Community

vCenter Conn Policy validation

Show all VPCs with connectivity to yours

xxx to do