Networking Core Concepts — NSX Architecture
Objectives
- Describe NSX three-plane architecture (management, control, data)
- Explain overlay networking concepts (TEPs, GENEVE, transport zones, segments)
- Describe VPC constructs in NSX for multi-tenancy
- Differentiate Tier-0 (north-south) from Tier-1 (east-west) gateways
- List NSX networking services (NAT, DHCP, DNS, LB, L2 VPN)
Prerequisites
Active Holodeck VCF 9.0 lab or access to VCF documentation
Required skills:
- Basic VMware terminology
Tasks
Task 1 NSX Architecture & Overlay Networking
Understand NSX three-plane architecture and overlay networking
Management Plane: NSX Manager cluster (3 nodes for HA), built-in policy/manager/controller roles. Policy role: centralized config for networking and security. Manager role: prepares data plane components. Controller role: maintains realized state, configures data plane. Data Plane: ESX hosts (transport nodes) + NSX Edge nodes. Architectural separation enables scalability without affecting workloads.
Transport nodes: ESX hosts and Edge nodes prepared for NSX. TEP (Tunnel End Points): encapsulate/decapsulate overlay traffic using GENEVE protocol. Transport zones: overlay (GENEVE tunnels) or VLAN-backed. Segments: L2 broadcast domains in the overlay network. N-VDS: NSX-managed virtual distributed switch.
[HOLODECK NOTE] In Holodeck, GENEVE overlay tunnels run over virtual NICs between nested ESXi hosts. TEP (Tunnel Endpoint) traffic traverses the physical host's virtual switch — there is no physical network underlay separation. MTU 1700+ requirement for GENEVE is handled at the virtual switch level. Overlay performance in nested environments is significantly lower than bare-metal due to double encapsulation overhead.
NSX Projects segment a single NSX deployment into multiple tenants. Each project contains one or more VPCs. VPC constructs: subnets (public/private), gateways, security policies. Native VPCs in vCenter and VCF Automation — VI admins create/manage VPCs via vCenter UI or automate with VCF Automation.
Validation Gate
Check: Explain the difference between overlay and VLAN-backed transport zones and when to use each in VCF
Expected: Overlay: GENEVE-encapsulated, supports micro-segmentation, spans hosts without VLAN provisioning on physical switches. Use for workload segments. VLAN-backed: no encapsulation, maps to physical VLANs, used for uplinks, management, vMotion. Use for infrastructure traffic.
Common Errors
Task 2 NSX Routing & Services
Understand Tier-0/Tier-1 routing and NSX networking services
Tier-0: north-south routing, connects overlay to physical network via BGP/OSPF/static routes, runs on Edge cluster. Tier-1: east-west routing, connected to Tier-0, provides gateway services to segments. Edge cluster: active-standby or active-active deployment modes.
[HOLODECK NOTE] Tier-0 gateway BGP peering in Holodeck connects to a simulated physical router (often VyOS or similar VM). North-south traffic performance is limited by nested virtualization. In production, Tier-0 runs on dedicated Edge nodes with SR-IOV or DPDK for line-rate forwarding — Holodeck cannot replicate this performance.
NAT: source/destination NAT on gateways. DHCP: server or relay on segments. DNS: forwarder on gateways. Load Balancing: must be attached to Tier-1 gateway, includes virtual servers, profiles, server pools, health monitors. Tier-1 must run on Edge cluster in active-standby mode for LB. L2 VPN: extends overlay/VLAN segments across sites on same broadcast domain — requires Tier-0 in active-standby mode, configured from NSX UI.
Validation Gate
Check: Where does DFW enforce rules — on the ESXi host kernel or on Edge VMs?
Expected: DFW enforces on the ESXi host kernel via dvfilter — at the vNIC level of each VM. This is east-west (VM-to-VM) traffic. Gateway Firewall enforces on Edge VMs — this is north-south (VM-to-physical) traffic. They are complementary, not redundant.
Common Errors
Design Reflection (VCDX)
NSX architecture questions in VCDX defense focus on overlay justification (why not VLANs?), Edge sizing methodology, and DFW data-plane/control-plane separation. Be prepared to defend your overlay choice with customer-specific reasoning.
Requirements
- Understand NSX overlay and VLAN-backed transport zones
- Know T0/T1 gateway architecture and placement
- Explain DFW enforcement location and control plane separation
Constraints
- Physical switches must support MTU 9000 for overlay
- NSX Manager cluster requires 3 nodes for HA
- Edge VM sizing must account for services, not just throughput
Assumptions
- Physical underlay supports GENEVE encapsulation
- BGP peering available for T0 north-south connectivity
Risks
- MTU mismatch causing overlay fragmentation and performance degradation
- Single NSX Manager node creating control plane SPOF
⚠ Known Pitfalls (from Community KB)
References
- NSX 4.2 Administration GuideTier 1 — Official
- NSX Reference Design GuideTier 1 — Official