Release Notes v5.0

Release and Configuration Notes

First Published: 9/1/2022, Revised 10/1/2022
This document contains system requirements, supported features and bugs for ReSTNSX CloudControl v5.0
Important Notes:
The ReSTNSX appliance no longer ships with a 45 day Evaluation License. Users must email info@restnsx.com to receive a limited, temporary license. In evaluations mode, the following limitations are enforced:
▪ A limit of two data sources (NSX Managers) can be configured
▪ Tenants count limited to 2
▪ No additional users or external auth may be provisioned
▪ vRNI flows are limited to 15 ▪ ASA import to dFW publish is disabled
▪ Maximum of 10 workflow items can be published to NSX Manager
▪ For Operations -> dFW, a limit of 20 rule changes / 4 section changes total is enforced when importing NSX rules from CSV or published to NSX Manager. dFW Mover is limited to 1 Section / 15 rules per instantiation.
▪ For Operations -> N&S, Mover is limited to 15 objects per instantiation.
In evaluation mode, the default login information is as follows:
Username: admin Password: default
System Requirements:

Table Master

Role Version CPU Memory Storage
ReSTNSX (Small) 5.x 8 vCPU 16GB 50GB
ReSTNSX (Med-Large) 5.x 10 vCPU 32GB 100GB
vCenter 6.5, 6.7, 7.0
NSX Manager (-v) 6.3, 6.4
NSX Manager (-T) 3.x, 4.x
VMCoAWS M10-M20
VMC - Other NSX-T 3.x, 4.x
vRNI 3.8+
vRNI Cloud
Palo Alto 9.x+
Cisco ASA 8.x+
Fortnet All
Checkpoint R40+

For REST API access, HTTPS (TCP Port 443) must be allowed through any transient firewalls for the ReSTNSX Appliance to access vCenter and NSX Manager. For NSX-T Central CLI and edge node troubleshooting tools, ReSTNSX requires SSH connectivity to the primary NSX Manager / vCenter hosts. VMCoAWS is supported for direct connect connections and running as an OVA within the compute cluster within a given SDDC. CGW and MGW rules must be added for HTTP for ReSTNSX to connect to NSX Manager and vCenter

Browser Support

▪ Chrome 84+ for the best user experience ▪ Firefox 52+ (Limited Interop Testing)

New Features

General

▪ Query: Added Security Tags with the effective members (VMs). (NSX-T). ▪ Query: VM details added to show Guest information and networking (Segment, Tier 1) details. (NSX-T) ▪ Work Authorizations: Custom email template support for the Request, Approval and Implementation stages of work authorizations. This feature allows the system admin to define custom emails when notifications are sent ▪ Work Authorizations: Initiate ReSTFUL API calls to 3rd party systems for Request, Approval and Implementation events

Tools

Policy Engine (formerly Policy Sync)

▪ A new audit file export where the updates made in the latest Policy Engine run for NSX-v dFW rules, IP Sets, Security Groups and Services are reported. The data includes the object definition before and after the policy was run. ▪ NSX-v to NSX-T Global Manager dFW Sync added ▪ NSX-T to NSX-T synchronization when a segment is contained in a rule or applied-to. This feature will query the destination NSX-T manager for a segment matching by name to be placed in the NS Group.

If no matching entry is found: ▪ Then If source segment = VLAN, collect VM IPs on source segment ▪ Else If source segment = Routed, collect Segment IP Subnet ▪ Place IP(s)/Subnet(s) in destination NS Group

Supported versions for Firewall and Security Group synchronization:

Firewall Rules:

Table Master

NSX-v NSX-T 3.x AWS
NSX-v Y Y N
NSX-T 3.x Y Y Y
AWS N Y Y

Clone (New)

▪ Users can now clone entire NSX-T Security Configurations to another NSX-T manager. ▪ This is in addition to Bulk Provisioning (CSV files); NSX Mover (One object type at a time) and Policy Engine (dFW Sections and objects) Object Analyzer

Reporting

  • Difference Reports introduces the capability to compare, ondemand, up to three NSX-T Managers. This feature allows users to compare security configurations and detect variations as slight as differences in object descriptions.

Administration

▪ Data sources can now be enabled to send notifications to 3rd party systems via ReSTFUL API calls.

▪ System report notification maximum email destinations increased to 25 from 3

Multi-Tenant New Features

(NSX-T) ▪ VM page showing more column options to display additional Virtual Machine details (CPU, Memory, Tags, etc...). ▪ Logging dashboard now limited to user events and system level events filtered out

ReSTNSX - Features Overview Administration:

Enterprise license support. Beginning with ReSTNSX 2.2, customers will have the option of a Standard or Enterprise license. Standard licenses enable all the core features of the platform whereas Enterprise provides advanced functionality such as NSX Mover and Multi-Tenant Administration without requiring separate feature licenses for each capability.

Usage Notes:

▪ VM queries against NSX 6.4 Managers will show the corresponding IP address(es) for any given VM

Central CLI (NSX-v, NSX-T)

ReSTNSX's Central CLI provides web-based (HTTPS) API-driven access to the NSX Manager CLI without the need for SSH or leaving the web UI for troubleshooting NSX. Highlights include:

  • Easy buttons allowing users to click an icon to run pre-defined CLI commands
  • Enhanced command output with Intelligent Hyperlinks
  • Users can save commands for future use
  • Color picker for saving text, hyperlink and background color

API Scout (NSX-v, NSX-T)

API Scout provides in-application access to the NSX Manager and vCenter APIs without having to use an external client.

Security Planner:

ReSTNSX's Security Planner integrates into VMware's vRealize Network Insight (vRNI) platform for easy firewall rule creation in NSX Manager.

Operations:

ReSTNSX Operations provides real-time, instant creation, modification and deletion of NSX objects.

Networking and Security Objects - N&S - (NSX-v, NSX-T)

Real-time operations for N&S objectsCreate, Edit and Delete N&S objects instantly through ReSTNSX.

Load Balancing

Real-time operations for NSX Load Balancers Within ReSTNSX, users can now create, edit and operate their NSX load balancers easier than ever before.

NSX Mover

Real-time replication of Networking and Security N&S Objects With NSX Mover, Administrators can easily copy N&S objects and dFW rules between NSX Managers of the same or different type instantly.

Administrators, Auditors and IT Managers

Access to a unified reporting fabric to gain visibility into all of the ReSTNSX managed domains.

Upgrading ReSTNSX

Upgrades to ReST NSX leverage configuration export for easy migrations.