Prerequisites for deploying the virtual appliances in AWS
Following are the prerequisites for deploying the Resiliency Platform virtual appliances in AWS:
Follow the documentation of AWS to create the required security groups. make sure that the security groups meet the network and port requirements mentioned in the Resiliency Platform documentation are open for communication.
See Ports required for recovery of assets to AWS or VMware in Cloud (VMC).
If you deploy Resiliency Platform components through AWS Marketplace, the required security groups are automatically created.
Following are the prerequisites you can refer to perform operations:
Create a role named vmimport and grant the permissions required to import an image to the role. Follow the documentation of AWS to know about the permissions required to import an image.
The vmimport role should have the following KMS service permissions (along with the permissions mentioned in the AWS documentation):
"kms:ReEncrypt*"
"kms:GenerateDataKeyWithoutPlaintext"
"kms:DescribeKey"
"kms:CreateGrant"
"kms:Decrypt"
Create Individual roles for Resiliency Manager, IMS, and Replication Gateway with certain permissions. These roles are used for authenticating the operations performed by the Resiliency Platform components in AWS.
See Permissions required for IAM roles for Resiliency Manager, IMS, and Replication Gateway.
If you deploy Resiliency Platform through AWS Marketplace, then the required role are automatically created through AWS CloudFormation template that the marketplace deployment uses.
Ensure that there is direct communication between the premise network and the AWS network. It is recommended to use VPN or Direct Connect for AWS environment.
Ensure that Resiliency Manager and Infrastructure Management Server (IMS) have outgoing internet access enabled. You may choose to restrict incoming internet access on these virtual appliances.
Ensure the Replication Gateway has outgoing internet access while deploying from AWS Marketplace.
Ensure to deploy the IMS in the region to which you plan to associate the cloud data center.
For significant cost benefits, it is recommended to buy Amazon EC2 reserved instances for the Resiliency Platform virtual appliances as the virtual appliances will be running continuously. While buying the reserved instances, it is also recommended to select the availability zones where the virtual appliances are to be deployed; this will ensure reserved capacity. It is important to choose the reserved instance types that matches the virtual appliances' instance types.
See Deploying the virtual appliances in AWS through AWS Marketplace.