Release Notes v5.0
Release and Configuration Notes
First Published: 9/1/2022, Revised 10/1/2022
This document contains system requirements, supported features and bugs for ReSTNSX CloudControl v5.0
Important Notes:
The ReSTNSX appliance no longer ships with a 45 day Evaluation License. Users must email info@restnsx.com to receive a limited, temporary license. In evaluations mode, the following limitations are enforced:
▪ A limit of two data sources (NSX Managers) can be configured
▪ Tenants count limited to 2
▪ No additional users or external auth may be provisioned
▪ vRNI flows are limited to 15 ▪ ASA import to dFW publish is disabled
▪ Maximum of 10 workflow items can be published to NSX Manager
▪ For Operations -> dFW, a limit of 20 rule changes / 4 section changes total is enforced when importing NSX rules from CSV or published to NSX Manager. dFW Mover is limited to 1 Section / 15 rules per instantiation.
▪ For Operations -> N&S, Mover is limited to 15 objects per instantiation.
In evaluation mode, the default login information is as follows:
Username: admin Password: default
System Requirements:
Table Master
| Role | Version | CPU | Memory | Storage |
|---|---|---|---|---|
| ReSTNSX (Small) | 5.x | 8 vCPU | 16GB | 50GB |
| ReSTNSX (Med-Large) | 5.x | 10 vCPU | 32GB | 100GB |
| vCenter | 6.5, 6.7, 7.0 | |||
| NSX Manager (-v) | 6.3, 6.4 | |||
| NSX Manager (-T) | 3.x, 4.x | |||
| VMCoAWS | M10-M20 | |||
| VMC - Other | NSX-T 3.x, 4.x | |||
| vRNI | 3.8+ | |||
| vRNI Cloud | ||||
| Palo Alto | 9.x+ | |||
| Cisco ASA | 8.x+ | |||
| Fortnet | All | |||
| Checkpoint | R40+ |
For REST API access, HTTPS (TCP Port 443) must be allowed through any transient firewalls for the ReSTNSX Appliance to access vCenter and NSX Manager. For NSX-T Central CLI and edge node troubleshooting tools, ReSTNSX requires SSH connectivity to the primary NSX Manager / vCenter hosts. VMCoAWS is supported for direct connect connections and running as an OVA within the compute cluster within a given SDDC. CGW and MGW rules must be added for HTTP for ReSTNSX to connect to NSX Manager and vCenter
Browser Support
▪ Chrome 84+ for the best user experience ▪ Firefox 52+ (Limited Interop Testing)
New Features
General
▪ Query: Added Security Tags with the effective members (VMs). (NSX-T). ▪ Query: VM details added to show Guest information and networking (Segment, Tier 1) details. (NSX-T) ▪ Work Authorizations: Custom email template support for the Request, Approval and Implementation stages of work authorizations. This feature allows the system admin to define custom emails when notifications are sent ▪ Work Authorizations: Initiate ReSTFUL API calls to 3rd party systems for Request, Approval and Implementation events
Tools
Policy Engine (formerly Policy Sync)
▪ A new audit file export where the updates made in the latest Policy Engine run for NSX-v dFW rules, IP Sets, Security Groups and Services are reported. The data includes the object definition before and after the policy was run. ▪ NSX-v to NSX-T Global Manager dFW Sync added ▪ NSX-T to NSX-T synchronization when a segment is contained in a rule or applied-to. This feature will query the destination NSX-T manager for a segment matching by name to be placed in the NS Group.
If no matching entry is found: ▪ Then If source segment = VLAN, collect VM IPs on source segment ▪ Else If source segment = Routed, collect Segment IP Subnet ▪ Place IP(s)/Subnet(s) in destination NS Group
Supported versions for Firewall and Security Group synchronization:
Firewall Rules:
Table Master
| NSX-v | NSX-T 3.x | AWS | |
|---|---|---|---|
| NSX-v | Y | Y | N |
| NSX-T 3.x | Y | Y | Y |
| AWS | N | Y | Y |
Clone (New)
▪ Users can now clone entire NSX-T Security Configurations to another NSX-T manager. ▪ This is in addition to Bulk Provisioning (CSV files); NSX Mover (One object type at a time) and Policy Engine (dFW Sections and objects) Object Analyzer
Reporting
- Difference Reports introduces the capability to compare, ondemand, up to three NSX-T Managers. This feature allows users to compare security configurations and detect variations as slight as differences in object descriptions.
Administration
▪ Data sources can now be enabled to send notifications to 3rd party systems via ReSTFUL API calls.
▪ System report notification maximum email destinations increased to 25 from 3
Multi-Tenant New Features
(NSX-T) ▪ VM page showing more column options to display additional Virtual Machine details (CPU, Memory, Tags, etc...). ▪ Logging dashboard now limited to user events and system level events filtered out
ReSTNSX - Features Overview Administration:
Enterprise license support. Beginning with ReSTNSX 2.2, customers will have the option of a Standard or Enterprise license. Standard licenses enable all the core features of the platform whereas Enterprise provides advanced functionality such as NSX Mover and Multi-Tenant Administration without requiring separate feature licenses for each capability.
Usage Notes:
▪ VM queries against NSX 6.4 Managers will show the corresponding IP address(es) for any given VM
Central CLI (NSX-v, NSX-T)
ReSTNSX's Central CLI provides web-based (HTTPS) API-driven access to the NSX Manager CLI without the need for SSH or leaving the web UI for troubleshooting NSX. Highlights include:
- Easy buttons allowing users to click an icon to run pre-defined CLI commands
- Enhanced command output with Intelligent Hyperlinks
- Users can save commands for future use
- Color picker for saving text, hyperlink and background color
API Scout (NSX-v, NSX-T)
API Scout provides in-application access to the NSX Manager and vCenter APIs without having to use an external client.
Security Planner:
ReSTNSX's Security Planner integrates into VMware's vRealize Network Insight (vRNI) platform for easy firewall rule creation in NSX Manager.
Operations:
ReSTNSX Operations provides real-time, instant creation, modification and deletion of NSX objects.
Networking and Security Objects - N&S - (NSX-v, NSX-T)
Real-time operations for N&S objectsCreate, Edit and Delete N&S objects instantly through ReSTNSX.
Load Balancing
Real-time operations for NSX Load Balancers Within ReSTNSX, users can now create, edit and operate their NSX load balancers easier than ever before.
NSX Mover
Real-time replication of Networking and Security N&S Objects With NSX Mover, Administrators can easily copy N&S objects and dFW rules between NSX Managers of the same or different type instantly.
Administrators, Auditors and IT Managers
Access to a unified reporting fabric to gain visibility into all of the ReSTNSX managed domains.
Upgrading ReSTNSX
Upgrades to ReST NSX leverage configuration export for easy migrations.