Master NSX federation, advanced routing with BGP/OSPF, micro-segmentation at scale, ALB integration, and multi-site networking for large enterprise deployments. Deep focus on operational resiliency and automation.
3V0-25.25
VCAP
60
Questions
135m
Duration
300/500
Pass Score
30
Objectives
Exam Blueprint Weights
Section titles, groupings and weights below are VCDX Academy study groupings, NOT the official Broadcom blueprint structure. Broadcom publishes no section weights. Always cross-check the official exam guide. Official exam guide ↗
Section 1 — Architecture
~15%
Section 2 — Routing Design
~25%
High Weight
Section 3 — Security Services
~20%
Section 4 — Load Balancing and Network S
~15%
Section 5 — Troubleshooting
~25%
High Weight
Version Evolution
VCAP Networking covers advanced NSX design and operations. Evolution mirrors NSX itself: NSX-V edge-centric → NSX-T with T0/T1 model → NSX 4.x with federation and advanced security. VCF 9.0 aligns NSX versioning with VCF (NSX 9.0.x). Exam focuses on multi-site federation, edge design, and integration with Avi ALB for load balancing.
IPv4 Multicast (M-BGP):Standard BGP carries unicast only. For multicast (one-to-many traffic, e.g., video streaming), enable MBGP: separate address family (AFI/SAFI 1/2), advertise multicast routes. N
BGP Route Policies to Prevent VRF Leak:In multi-VRF deployments, accidentally leak routes from high-security VRF to low-security VRF = security breach. Apply export policies on Tier-0: per-VRF route m
SSL VPN Use Case:Employee on public WiFi needs access to internal file shares. Connects to NSX edge SSL VPN endpoint, authenticates (AD credentials), receives virtual network adapter (tun0). Traffic f
Edge VM Sizing (identical in NSX 4.2 and NSX 9.0; disk is 200 GB for every size)
: Small 2 vCPU / 4 GB - proof-of-concept ONLY, T1 L7 rules not realized. Medium 4 vCPU / 8 GB - L2-L4, under 2 Gbps. Large 8 vCPU / 32 GB - L2-L4 at 2-10 Gbps, plus L7 LB and TLS inspection. Extra Large 16 vCPU / 64 GB - high-throughput L7 LB, VPN, URL filtering, IDS/IPS. Broadcom does not designate one size 'production-recommended' - size by throughput and feature band. DPDK is a property of the host CPU (AESNI + 1 GB huge pages), not of the Edge form factor.
Manager Node Cluster
: 3 nodes minimum for HA; etcd quorum requires all 3 healthy. Typically deployed on vSAN for storage redundancy.
NSX Federation: Multi-Site Architecture
Federation allows multiple NSX domains (sites) to operate as unified network fabric:
Global Manager
: Single point of management. Active/Active or Active/Standby failover. Runs on dedicated VM or appliance (16vCPU/32GB typical).
Local Managers
: One per site; subordinate to Global Manager. Independent operation if Global Manager unavailable (graceful degradation).
Stretched Segments
: Logical switch synchronized across sites. VM can vMotion between sites while maintaining IP/MAC. ARP/DHCP handled by Global Manager.
Location-Aware Groups
: DFW rules scoped per location. Example: block-malware group can differ per site; Global Manager compiles per-location rules.
Gateway Failover
: Tier-0 gateways at each site peer upstream; stretched VIP failover managed by VRRP (Virtual Router Redundancy Protocol).
Stretched Segments: Segment-A exists on both sites
DFW Rules: Location-aware rules apply per site
Service VLAN: Unique per site; GSLB load balances across
N-VDS to VDS Migration
Migrating from NSX-V to NSX-T or from older NSX-T builds requires careful planning:
N-VDS (NSX Virtual Distributed Switch)
: NSX-V construct; DVports bound to NSX VLANs. Cannot coexist with NSX-T.
Migration Strategy
: (1) Dual-stack approach—run both N-VDS and VDS during migration, (2) Rolling vMotion of VMs from N-VDS segments to NSX-T segments, (3) Service vMotion (move network interface) as final step.
Cutover Validation
: Test floating traffic across dual stack; validate DFW rules migration; verify GSLB/DNS failover.
Transport Node Profiles standardize hypervisor configuration at scale:
Transport Node Profile
: Template defining VMKs (Virtual Machine Kernel adapters), VLAN transport zones, overlay transport zones. Applied to cluster or host level.
Network I/O Control (NIOC)
: QoS for VMK traffic. Example: vSAN traffic guaranteed 20% bandwidth, vMotion 10%, management 5%, VM data best-effort. Enforces fairness across competing workloads.
MTU Sizing
: Geneve overlay minimum MTU is 1600; 1700 is recommended and is the NSX default Global TEP MTU (headroom for future Geneve options). VCF design rule VCF-NET-REQD-OVL-001: overlay segment MTU = TEP MTU minus 200. Where the fabric supports jumbo frames, 9000 is recommended. Validate end-to-end path supports MTU.
Uplink Profiles
: Define active/standby topology, failover strategy (active-active requires LAG or ECMP), LLDP/CDP for underlay discovery.
#!/bin/bash
NSX CLI: Create Transport Node Profile
nsx-cli
enter admin
create transport-node-profile profile-a
set uplink-mtu 1700
set vlans vlan-transport-zone id 0-4094
set overlay overlay-transport-zone
apply
Assign to cluster
create transport-node cluster-1
set transport-node-profile-name profile-a
apply
Verify
get transport-nodes show transport-node cluster-1
Key Takeaways
For exam: NSX form factors define max nodes/switches (Small=64/1024, Medium=512/8000, Large=2048/16000). Edge VM sizing: Small 2vCPU/4GB (PoC only), Medium 4/8 (<2 Gbps), Large 8/32 (2-10 Gbps + L7 LB/TLS), XL 16/64 (L7 LB, VPN, IDS/IPS). All 200 GB disk.
For exam: Federation architecture: Global Manager (16vCPU/32GB) + Local Managers per site. Stretched segments enable VM vMotion while maintaining IP/MAC. Location-aware DFW rules differ per site.
For exam: Transport Node Profile template for VMKs, VLAN/overlay zones. NIOC enforces QoS fairness (vSAN 20%, vMotion 10%, management 5%). MTU: 1600 minimum for Geneve overlay, 1700 recommended (NSX default TEP MTU); 9000 where the fabric supports jumbo frames. Fabric MTU should exceed workload MTU by at least 100 bytes, 200 preferred.
Advanced Routing: BGP, OSPF, and Route Redistribution#
BGP Deep Dive: Route Maps, Prefix Lists, Community Strings
Border Gateway Protocol is critical for multi-site, high-availability networking:
BGP Basics
: Autonomous System Number (ASN) per site. Tier-0 router acts as BGP speaker; advertises pod CIDR, service CIDR, stretched segment CIDR to upstream DC fabric.
Route Maps
: Policy-based routing logic. Example: Tag pod routes with community 65000:1000 (production), pod routes with 65000:1001 (test). Upstream routers use communities to apply different QoS per workload.
Prefix Lists
: Define allowed IP ranges for incoming/outgoing routes. Prevent accidental advertisement of 0.0.0.0/0 or private ranges.
AS Path Prepend
: Artificially inflate AS path to deprioritize certain routes. Example: prepend 65000 3 times to make backup site route less preferred; upstream chooses primary site by shortest AS path.
Local Preference (LocalPref)
: BGP attribute 0-4294967295. Higher value = preferred. Set high LocalPref on primary site, lower on secondary. Overrides AS path length.
Route Redistribution
: Inject connected routes (VM networks), static routes, OSPF routes into BGP. Example: redistribute OSPF routes learned in data center as BGP route 65000:1 (external route).
#!/bin/bash
NSX CLI: Configure advanced BGP
nsx-cli
enter admin
configure tier-0-router tier0-a
configure bgp
configure address-family ipv4
configure prefix-list prod-prefixes
10 permit 10.100.0.0/16 # Pod CIDR
20 permit 10.200.0.0/16 # Service CIDR
exit
configure route-map prod-tag
10 match ip address prefix-list prod-prefixes
10 set community 65000:1000
20 match ip address prefix-list test-prefixes
20 set community 65000:1001
exit
configure neighbor 10.0.0.1 (upstream router)
remote-as 65001
address-family ipv4
route-map prod-tag out
maximum-prefix 10000 warning-only
exit
apply
OSPF Areas & Multi-Area Design
Open Shortest Path First suitable for intra-datacenter routing (NSX-T → NSX-T):
Area 0 (Backbone)
: Tier-0 routers connected via OSPF. All other areas must connect through backbone.
Area Types
: Standard (full adjacency), Stub (no external routes, smaller LSA flooding), Totally Stubby (no external, no inter-area routes learned outside area).
: Redistribute static routes (default route from ISP) into OSPF as external routes. Backup static route requires lower metric than advertised route to trigger failover.
Filtering
: Deny redistribution of specific networks. Example: deny OSPF internal 10.255.255.0/24 (admin subnet) from BGP redistribution to avoid exposure to untrusted peers.
Metric Translation
: OSPF cost ≠ BGP AS path. Define conversion: high OSPF cost = low BGP weight (more preferred) for load balancing asymmetry.
ECMP & Multi-Path Load Balancing
Maximizing throughput via parallel paths:
8-Way ECMP
: Tier-0 can load-balance across up to 8 equal-cost paths. Requires 8 edge nodes with active-active uplinks.
Hash Algorithm
: NSX uses 5-tuple hash (source IP, dest IP, source port, dest port, protocol) by default. Configurable to 3-tuple (source/dest IP, protocol) for coarser balancing.
Asymmetric Paths
: Return traffic may take different path than outbound (valid in NSX). Ensure firewall rules symmetric; no hairpinning required.
Link Redundancy
: 8 edge nodes at same site all contribute to ECMP pool. Loss of 1 edge = 12.5% throughput reduction (1/8 paths). Rebalance load automatically.
IPv6 & Dual-Stack Design
VCF 9.0 supports IPv6 at Tier-0/Tier-1 level:
Dual-Stack Segments
: Logical switch with both IPv4 and IPv6 CIDR. DHCPv6 server can auto-assign /64 to pods.
Router Advertisement (RA)
: Tier-1 router issues RA packets; stateless autoconfig for VM networks. Stateful DHCPv6 alternative.
BGP IPv6
: Separate address family (AFI 2, SAFI 1) in BGP config. Tier-0 advertises both IPv4 and IPv6 routes independently.
NAT64
: NSX supports stateless NAT64 for IPv6-only clients reaching IPv4-only servers. Pool of IPv4 addresses mapped to ::/96 prefix.
Key Takeaways
For exam: BGP route maps + communities tag production (65000:1000) vs. test routes (65000:1001) for upstream QoS. AS path prepend deprioritizes backup routes. LocalPref 0-4294967295 overrides AS path length.
For exam: OSPF cost = 10^8 / bandwidth (GbE=100, 10GbE=10). Area 0 backbone required. Convergence ~10-30 seconds on LSP flooding (30 sec default interval). Type 1/2=intra-area, Type 3=inter-area.
For exam: ECMP up to 8 equal-cost paths. Hash algorithm: 5-tuple (IP src/dst, port src/dst, proto) default, configurable to 3-tuple. Loss of 1 edge = 12.5% throughput reduction. Asymmetric paths valid; ensure firewall rule symmetry.
VRF-Lite enables multiple independent routing tables on a single Tier-0. Each VRF has separate BGP session, route table, and interface namespace. Use case: multi-tenant deployments (each tenant = VRF), PCI zone isolation (payment processing VRF separate from general VRF), OT/IT isolation (operational tech on VRF-OT, IT on VRF-IT).
Key Takeaways
For exam: VRF-Lite = separate routing tables + BGP sessions on single Tier-0. Each VRF independent route table and interface namespace. Use for multi-tenant, PCI isolation, OT/IT segregation.
For exam: Route leak vulnerability: high-security VRF → low-security VRF = breach. Mitigate with export route maps per VRF, deny forbidden VRF routes. Monitor: show bgp ipv4 unicast neighbor.
For exam: VRF-Lite more efficient than multi-site federation for single-site isolation. Federation for stretched segments and GSLB across geographic locations.
Global Manager Cluster Architecture: RAFT-based Consensus
NSX Federation enables multi-site deployments with global object management. Global Manager (GM) cluster (3 nodes in RAFT consensus) centralizes policy, stretched segments, and global groups. Local Managers (one per site) register with GM, enforce global policies locally.
Key Takeaways
For exam: Global Manager cluster: 3 nodes RAFT consensus. Local Managers per site register with GM and enforce global policies locally. Graceful degradation if GM unavailable.
For exam: Stretched segments synchronized across sites. VM vMotion maintains IP/MAC. ARP/DHCP handled by Global Manager. Location-aware DFW rules compiled per-site by GM.
For exam: Gateway failover VRRP (Virtual Router Redundancy Protocol). Tier-0 gateways peer upstream per site. GSLB load balances service VIPs across sites.
NSX edge performance depends on dataplane (DP) core allocation and pinning. Edges run control plane (CP) on one core (management, BGP, SSH), dataplane on N cores (packet forwarding).
Key Takeaways
For exam: NSX edge architecture: 1 CP core (management, BGP, SSH) + N DP cores (packet forwarding). CPU pinning mandatory for predictable performance. Hugepages reduce TLB misses.
For exam: DPDK (Data Plane Development Kit) enables high-throughput packet processing. CPU isolation avoids context switches. Monitor: NSX Manager → System → Performance → Edge.
For exam: DP core saturation = packet drops. Scale horizontally: add more edge nodes. Verify uplink capacity matches DP throughput (no bottleneck upstream).
Enterprise Integrations with Third-Party Infrastructure#
Cisco ACI Border Leaf Peering
NSX Tier-0 can establish eBGP sessions with Cisco ACI border leafs, enabling multi-vendor fabric. NSX advertises its routes (workload subnets), ACI advertises fabric routes.
For exam: Multi-vendor fabric: validate BGP convergence, route leak prevention (route maps, prefix lists). Test failover: disable one border leaf, verify alternative path.
For exam: Integration complexity trade-off: ACI + NSX = advanced segmentation but operational overhead. Single vendor (NSX-only) simpler to manage but less flexibility if ACI already deployed.
IPv6 in NSX: Dual-Stack and Transition Mechanisms#
Dual-Stack Segment Support and IPv6 Routing
NSX supports dual-stack segments: both IPv4 and IPv6 subnets on same logical switch. Tier-1 routers support IPv6 static routes and dynamic routing (BGP, OSPFv3 in NSX 4.1+).
Key Takeaways
For exam: Dual-stack segment = IPv4 + IPv6 CIDR on same logical switch. DHCPv6 auto-assign /64 to pods. Router Advertisement (RA) enables stateless autoconfig vs. stateful DHCPv6.
For exam: BGP IPv6: separate AFI 2 / SAFI 1. Tier-0 advertises IPv4 and IPv6 routes independently. OSPFv3 supported in NSX 4.1+ (intra-DC IPv6 routing).
For exam: NAT64 stateless: IPv6-only clients → IPv4-only servers. Pool of IPv4 addresses mapped to ::/96 prefix. Translation transparent at NSX Tier-1.
NSX supports route-based IPSec (IPSec encapsulation) and policy-based IPSec (packet classification first, then encapsulation). IKEv2 (Internet Key Exchange version 2) is standard for key negotiation (IKEv1 deprecated).
SSL VPN: Layer-7 Remote Access
SSL VPN (client-to-gateway, not site-to-site) provides remote-access to corporate network. NSX edge runs SSL VPN server, users connect via web browser or native client, tunnel created over HTTPS (port 443).
Layer-2 VPN (Deprecated, Rarely Used)
L2VPN extends Ethernet segment across WAN (pre-VXLAN overlay era, now mostly replaced by NSX Federation stretched segments). Still used in legacy migrations. Performance: layer 2 forwarding (slower than layer 3 routing), broadcast flooding across WAN (network storms possible). Avoid new designs; use stretched segments with NSX Federation instead.
Key Takeaways
SSL VPN Use Case:Employee on public WiFi needs access to internal file shares. Connects to NSX edge SSL VPN endpoint, authenticates (AD credentials), receives virtual network adapter (tun0). Traffic from employee encrypted and tunneled to NSX edge. Useful for BYOD (Bring Your Own Device) scenarios,
Mature NSX deployments grow to tens of thousands of DFW rules. Managing that scale requires discipline, automation, and performance tuning.
Lab Exercise: Design and Deploy Multi-Tier Segmentation
Key Takeaways
For exam: DFW rule hierarchy: section → rules. Sections ordered by priority. Implicit deny at end. Rules evaluated top-to-bottom; first match wins.
For exam: 10k+ rules optimization: break into sections per tier (management, app, db, edge). Use groups instead of individual IPs (membership updates push to all rules). Monitor rule hit rate.
For exam: Performance tuning: enable stateful firewall (track connections), prefer L3 + L4 rules over L7 inspection (lower CPU). Test failover: verify rule sync across edges.
NSX overlay uses Geneve encapsulation which adds ~50 bytes of header overhead to each frame. The physical underlay must support minimum 1600 MTU to avoid fragmentation. 1500 is standard (too small). 9000 is jumbo (recommended but not required). 1280 is IPv6 minimum.
The NSX Management Plane cluster provides Manager and Policy APIs with integrated controller services. Controller functionality was merged into the Manager starting in NSX-T 3.x. It doesn't only enforce firewalls, handle BGP routing, or do Edge forwarding.
Overlay transport zones carry Geneve-encapsulated overlay traffic. VLAN transport zones carry VLAN-tagged traffic. Global and Edge-only zones are not standard NSX transport zone types.
TEP IPs are assigned to hypervisor VMkernel interfaces on transport nodes and Edge uplink interfaces. They're not on NSX Manager interfaces, individual VMs, or physical routers.
An administrator notices that overlay traffic between two ESXi transport nodes fails while underlay ping succeeds. Payload pings of 1572 bytes (DF set) fail. What is the root cause?
TEP IP address mismatch
MTU on the physical underlay is below 1600 bytes, causing Geneve-encapsulated frames to be dropped/fragmented
MTU below 1600 on the physical underlay drops or fragments Geneve-encapsulated frames (standard 1500 + ~50 byte Geneve header = 1550+ needed). 1572-byte payload pings with DF set confirm this. TEP mismatch, Geneve disabling, and BFD VLAN issues are incorrect.
Active-Active with ECMP distributes north-south traffic across multiple Edge nodes for maximum throughput and scale-out. Active-Standby limits throughput to one Edge. Stateful A/S is for services requiring session state. Single-node has no redundancy.
A prefix list applied via route map filters inbound prefixes by exact match or longest-prefix criteria. AS-path filters match AS paths. Community strings tag routes. BFD sessions detect path failures.
OSPF on Tier-0 peers with legacy enterprise networks that run OSPF internally, providing IGP route exchange. It doesn't replace the management plane, encrypt traffic, or provide micro-segmentation.
NSX Federation introduces the Global Manager which coordinates Local Managers across multiple sites for consistent networking and security. It's not a single controller, shared Edge cluster, or shared vCenter.
VRF gateways on a shared Tier-0 provide per-tenant routing isolation with separate RIBs (routing tables) while sharing Edge uplinks. They're not just L2 bridging, Edge replacements, or IPv6-only.
Sub-second BFD timers are appropriate when fast convergence is needed AND the network path can support it without false positives. Slower detection, dropped ICMP, and disabled BGP are not valid reasons for aggressive BFD.
A Tier-0 gateway is configured Active-Active with 4 Edge nodes, each peering over two uplinks to separate ToR switches via eBGP. A single ToR fails. Which statement is accurate?
All traffic must fail over to standby Tier-0 before recovery
ECMP paths via the surviving ToR continue forwarding; BFD detects the peer loss in sub-second and affected next-hops are removed from the FIB
Traffic is black-holed until BGP holdtime (default 180s) expires
With ECMP across 4 Edges and 2 ToRs, a single ToR failure only removes paths via that ToR. ECMP paths through the surviving ToR continue. BFD detects loss in sub-second. Traffic isn't black-holed or requiring standby failover.
Which BGP attribute, when manipulated via a route-map on T0 egress, provides the most effective control for influencing INBOUND path selection from upstream peers?
AS_PATH prepending is the most effective way to influence INBOUND path selection from upstream peers — longer AS paths are less preferred. LOCAL_PREF affects outbound decisions locally. MED works only within the same AS. Weight is Cisco-specific and local-only.
In NSX Federation, a stretched Tier-0 gateway spans two locations. Which statement is correct about egress routing?
Egress is always performed at the primary location only
With 'Primary/Secondary' locations, egress is centralized at Primary; with 'All Primary', each location egresses locally using its own BGP peers, and MAC addresses are managed per-location to avoid loops
In Federation with 'All Primary' locations, each location egresses locally using its own BGP peers. With 'Primary/Secondary', egress centralizes at Primary. Federation does support BGP, and VMs egress via local Edges, not the Global Manager.
A VRF gateway is attached to a parent Tier-0. Which statement about VRF constraints is correct?
Each VRF can have a different BGP ASN than the parent
VRFs inherit the parent T0's Edge cluster, HA mode, and BGP ASN; per-VRF you can configure separate VLAN uplinks, BGP neighbors, and route redistribution
VRFs inherit the parent T0's Edge cluster, HA mode, and BGP ASN. Per-VRF, you configure separate VLAN uplinks, BGP neighbors, and route redistribution. VRFs can't have different ASNs from the parent. VRFs support BGP. VRFs don't need separate Edge nodes.
Which is the correct use case for OSPF on a Tier-0 gateway?
Peering to the Internet via multiple ISPs
Interoperating with an enterprise campus that already runs OSPF as IGP, allowing NSX to exchange routes in a single area (commonly Area 0 or a totally stubby area)
OSPF on Tier-0 interoperates with enterprise campus networks running OSPF as IGP, allowing route exchange in a single area. It's not for multi-ISP peering (use BGP), EVPN routes, or Federation signaling.
To aggressively detect BGP peer failures for an Active-Active T0 while avoiding false positives during vMotion of the peer, which BFD settings are typical?
Interval 50ms, multiplier 3
Interval 500ms-1s with multiplier 3, aligned with physical network capabilities; 50ms is only advisable when both sides are hardware-forwarded and stable
BFD interval 500ms-1s with multiplier 3 balances fast detection with stability. 50ms is only safe with hardware-forwarded, stable paths. 10s x 10 is too slow. BFD should not be disabled on production Edges.
A design requires multi-tenant routing isolation with each tenant having its own Tier-1 gateways, segments, and firewall policies, managed by the tenant admin. Which NSX construct is most appropriate?
NSX Federation
NSX Projects (optionally combined with VPCs) which provide tenant-scoped management and RBAC on a shared T0
NSX Projects (optionally with VPCs) provide tenant-scoped management and RBAC on a shared T0 with per-tenant Tier-1s, segments, and firewall policies. Federation connects sites. VRFs provide routing isolation. Separate vCenters are heavy-handed.
Distributed Firewall at the vNIC provides east-west micro-segmentation between workloads on the same host without traffic leaving the host. Gateway Firewall handles north-south. Edge service insertion and ToR ACLs don't handle intra-host traffic.
Gateway Firewall on Tier-0 inspects north-south traffic passing through the gateway. Intra-host traffic is handled by DFW. IPv6 link-local and control plane traffic are special cases, not the primary design.
Global IDS/IPS policies in Federation ensure consistent signature-based enforcement uniformly across all sites managed by the Global Manager. They're not site-local only, without logging, or with disabled DFW.
Dynamic criteria with AND/OR expressions enable group membership based on multiple attributes like VM tag AND OS type simultaneously. Static IP sets, MAC lists, and vSAN policies don't provide dynamic multi-criteria grouping.
URL filtering on Tier-1 categorizes and controls outbound web access by FQDN and URL category. It doesn't improve BGP convergence, optimize vMotion, or replace DFW.
IDS/IPS 'Detect and Prevent' drops or resets matching flows in addition to logging. Detect-only just logs. It doesn't replace gateways or disable DFW rules.
A DFW rule uses a dynamic security group with criteria 'VM Tag equals scope=PCI AND OS Name contains Windows'. A new Windows VM is deployed and tagged. When does the rule apply?
Only after a manual rule publish
As soon as the tag is applied and membership recalculates on the management plane, the rule is pushed to the vNIC slot (filter) of the VM by the control plane in near real-time
When a VM is tagged, dynamic security group membership recalculates on the management plane and the rule is pushed to the vNIC vfilter in near real-time. No manual publish is needed for membership updates. It doesn't wait for host reboot or never apply to dynamic members.
Distributed IDS/IPS is enabled in 'Detect only' mode. During an incident, the SOC wants selective blocking for one critical segment without globally enabling Block. Which is the correct approach?
Switch the global mode to Block, then revert after
Create an IDS profile set to Block for the specific signatures and apply it via a policy rule scoped (Applied To) to that segment's security group
Create an IDS profile set to Block for specific signatures and apply via a policy rule scoped (Applied To) to that segment's security group. This provides surgical blocking without global impact. Switching global mode or disabling DFW is heavy-handed.
NSX Malware Prevention (part of vDefend NDR) inspects files on Gateway Firewall and optionally on hosts using local analysis plus cloud sandboxing. DFW alone doesn't inspect file content. IPFIX exports flow data. Service Insertion via partner SVM is a different approach.
Global DFW rules authored on the Global Manager are pushed to each Local Manager and instantiated on transport nodes, ensuring consistent east-west rules across all sites. They're not manually replicated, Edge-only, or NSX Intelligence.
Projects and VPCs with per-tenant Tier-1s/segments provide isolated routing, segmentation, and self-service for multi-tenant designs. A single shared Tier-1 offers no isolation. VLAN-only lacks overlay benefits. Disabled firewall is a security risk.
Public VPC subnet type is reachable from the public/external network. Private-VPC and Private-Transit Gateway subnets are internal only. Hidden is not a standard VPC subnet type.
SNAT on Tier-1 translates private source IPs to a public IP for outbound access. It's not IPv6-specific, for internal-only traffic, or related to Active-Standby mode.
L2 VPN extends a VLAN/segment to a remote site over an IP network, maintaining L2 adjacency. It doesn't encrypt DFW rules, provide DNS, or route BGP only.
NSX-backed Supervisor uses VPC + CTGW and per-namespace Tier-1/segments for VKS networking integration. Classic VLANs, kube-proxy only, and VLAN trunks per pod don't provide the NSX integration model.
CTGW provides shared services and transit connectivity across multiple VPCs. It doesn't replace NSX Manager, perform DFW inspection, or act solely as a load balancer.
A tenant requires both stateful SNAT for outbound Internet traffic and an IPSec policy-based VPN to a partner site. Where in the NSX topology should these services be placed?
On the Tier-0 only, never on Tier-1
On a Tier-1 gateway with a Service Router on an Edge cluster (required for stateful services); the Tier-0 handles ECMP northbound
Stateful services (SNAT, IPSec VPN) require a Tier-1 Service Router on an Edge cluster. The Tier-0 handles ECMP northbound routing. These services can't run on segments directly or on the host DFW.
NSX Traceflow with DFW rule matching is the first step — it shows exactly which rule blocks TCP 443 while ICMP passes. Replacing Edge, restarting NSX Manager, and re-IPing VMs are drastic and premature.
Underlay MTU < 1600 or TEP connectivity failure is the most common cause of overlay tunnel failures. Guest OS firewalls don't affect TEP tunnels. DFW Application category rules don't affect overlay encapsulation. Brief controller VIP offline doesn't permanently down tunnels.
BGP 'Active' state means the Edge is trying to establish TCP/179 but can't connect. Check ASN configuration, neighbor IP, and intermediate firewall rules for TCP 179. ECMP settings, DFW on Edge, and certificate rotation don't address TCP session establishment.
'get logical-router <uuid> bgp neighbor summary' shows BGP peer state on the Edge. esxcli doesn't have BGP commands. 'show running-config route' and 'nsxcli-show-bgp' are not valid NSX Edge CLI commands.
IPFIX with a flow exporter configured on segments/DFW captures per-flow statistics for traffic visibility and exports to a collector. Port mirroring captures all traffic. vMotion logging and vSAN Observer serve different purposes.
Check DNAT rule match criteria (source, destination, port) and route advertisement/uplink reachability. If the VIP isn't advertised upstream or the match criteria are wrong, DNAT won't translate. Replacing Edge, disabling overlay TZ, and reinstalling NSX Manager are overkill.
Traceflow from VM-A to VM-B (different hosts, same overlay segment) shows 'Delivered' to the destination, but the guest OS never receives the packet. What is the next troubleshooting step?
Restart NSX Manager
Check the guest OS firewall, vNIC status, and ARP table inside the guest; Traceflow confirms hypervisor delivery but not guest processing
Traceflow confirms hypervisor-level delivery but not guest OS processing. Next: check guest OS firewall, vNIC status, and ARP table. Restarting NSX Manager, rebuilding TEPs, and redeploying Edges won't fix guest OS issues.
On an Edge node, 'get bgp neighbor' shows the peer in Active state. What does this indicate?
BGP is functioning normally
The local Edge is actively trying to establish the TCP session but has not succeeded; common causes are ACL/firewall blocking TCP/179, wrong neighbor IP, or BGP not enabled on the peer
'Active' state means the Edge is trying to establish TCP/179 but the session never completes — common causes are ACL/firewall blocking TCP/179, wrong neighbor IP, or BGP not enabled on the peer. Active does NOT mean functioning normally.
Check uplink CRC errors with 'esxcli network nic stats get' and validate underlay MTU with vmkping using 1572-byte payloads and DF flag across TEPs. Rebooting hosts, disabling overlay TZ, and increasing vCPU are not diagnostic steps.
IPFIX sampling rate of 0 (disabled) or collector unreachable from the hypervisor management interface are the most common causes. DFW status, Geneve encapsulation, and VRF configuration don't affect IPFIX flow export.
A DNAT rule translates 198.51.100.10:443 to 10.0.0.5:8443, but external clients cannot connect. Traceflow from an external source shows the packet dropped at the Gateway Firewall. Root cause?
NAT executes before the Gateway Firewall for destination NAT; the GFW rule must permit the translated destination (10.0.0.5:8443), not the original (198.51.100.10:443)
DNAT executes before the Gateway Firewall for destination NAT. The GFW rule must permit the translated destination (10.0.0.5:8443), not the original VIP. NAT can be combined with firewall rules. A dedicated Tier-0 isn't required. The segment state is irrelevant if NAT and GFW are the issue.
Check LB Monitor (health check) configuration: type, port, URI, expected response. Also verify SNAT so backend replies return via the LB. Changing form factor, disabling SSL, and switching algorithms don't address health check failures.
Port mirroring is configured from a VM vNIC to a remote analyzer using ERSPAN, but no traffic arrives. Which is most likely?
ERSPAN traffic (GRE) is blocked by a physical firewall or the mirror destination IP is unreachable from the hypervisor TEP/vmk source; also verify TCP/IP stack and routing
ERSPAN uses GRE encapsulation — if a physical firewall blocks GRE or the destination IP is unreachable from the hypervisor, no traffic arrives. Port mirroring doesn't require DFW disabled. Both DVS and NSX support ERSPAN. EVPN is not required.
The NSX control plane function inside the NSX Manager cluster responsible for computing runtime state (segment tables, TEP lists) from policy and distributing it to transport nodes. It is distinct from the management plane that stores intent. CCP health is critical to fast convergence.
Policy Role (NSX)
The declarative API surface of NSX where users author intent (segments, rules, gateways) in a desired-state style. Policy is rendered down to Manager and Central Control Plane internal objects. Modern NSX operations interact almost exclusively through Policy.
Manager Role (NSX)
The imperative, object-oriented NSX API surface that predates Policy and still exists for legacy integrations. New designs avoid Manager API direct calls in favor of Policy. Mixing both on the same objects leads to drift and is unsupported.
Underlay MTU Requirement
No change needed — this definition is consistent with NSX documentation (1600 minimum, 1700 default/recommended).
BFD Tunnel Monitoring
A sub-second liveness protocol running between TEPs and Edge uplinks, detecting tunnel failure and driving fast reconvergence. NSX uses BFD for overlay, BGP, and HA. Healthy BFD sessions are the backbone of robust NSX forwarding.
DPU Data Plane Offload
An NSX architecture option where packet processing (overlay, DFW, IDS) runs on a SmartNIC/DPU instead of host CPU, freeing cores for workloads. It requires compatible hardware and NSX DPU mode. It is increasingly common in high-throughput VCAP designs.
Transport Node
An ESXi host or Edge node prepared with NSX VIBs, a TEP IP, and an N-VDS/VDS switch profile. Transport Zones bind it to the overlay and VLAN networks it can participate in.
Transport Zone (Overlay vs VLAN)
Overlay TZ carries Geneve-encapsulated segments; VLAN TZ carries tagged VLAN segments used for uplinks, service networks, and backed-by-VLAN segments. A segment belongs to exactly one TZ.
Edge Cluster Failover Modes
Preemptive (failback to preferred node when it returns) vs Non-Preemptive (stay on backup until manual/failure). Choice affects how stateful services like Gateway Firewall behave during Edge flaps.
Active-Active ECMP Tier-0
A Tier-0 gateway HA mode where all Edge nodes actively forward and BGP-peer simultaneously, sharing north-south load. It maximizes throughput but cannot host stateful services. It is the preferred mode for pure routing workloads.
Active-Standby Tier-0
A Tier-0 HA mode with one active Edge and one or more standby Edges ready to take over on failure. It is required for stateful services (NAT, LB, VPN) that need a single owner. Failover is sub-second but traffic has a brief gap.
Route Map
A BGP policy object that filters and rewrites prefixes on ingress or egress, changing community, local preference, MED, and AS path. Route maps are the expressive policy layer in NSX BGP. They are the primary tool for traffic-engineering complex topologies.
Prefix List
A BGP helper object that matches a set of IP prefixes, often referenced by route maps to scope actions to specific networks. Prefix lists are more efficient than large regex match-all route maps. They are standard in any production BGP design.
BGP Community
A 32-bit tag attached to routes that downstream peers use to make forwarding or filtering decisions. Communities are the contract between tenants and the core routing fabric. They enable scalable, attribute-driven traffic policy.
NSX Federation
An NSX feature that introduces a Global Manager coordinating multiple Local Managers across sites for stretched networking and security. It synchronizes global objects (Tier-0s, segments, DFW rules) while preserving site autonomy. It is the recommended multi-site NSX architecture in VCF.
VRF Gateway
A virtual routing and forwarding instance hosted on a Tier-0, giving each tenant its own routing table and BGP peering on shared infrastructure. It is distinct from a full dedicated Tier-0 per tenant. It is the cost-effective multi-tenant routing primitive.
BGP AS Path Prepending
Adding one's own ASN multiple times to the AS_PATH to make a route less preferred for inbound traffic engineering. Common on NSX Tier-0 to steer ingress to the preferred site/peer.
BGP Local Preference
Iinternal BGP attribute (higher wins) used on Tier-0 SR to prefer one uplink/edge for egress. Set via route map on the BGP neighbor.
ECMP Max Paths
NSX Tier-0 supports up to 8 ECMP paths per prefix (release-dependent). Flows are hashed (5-tuple) across active paths; BGP must learn equal-cost routes for ECMP to engage.
BFD Timers
Bidirectional Forwarding Detection default 1000 ms tx/rx with multiplier 3 (failover ~3 s). Aggressive timers (300/300 ms with mult 3) give sub-second convergence on supported Edge form factors.
Inter-SR Routing
Internal routing between Active-Active Tier-0 SR instances over a hidden transit segment. Lets traffic entering one Edge reach services hosted on another, though symmetric routing is still the design goal.
East-West Micro-Segmentation Design
A Tier-1-scoped NSX policy design that applies DFW rules between workload tiers on the same or connected segments, independent of north-south perimeter. It delivers zero-trust for lateral movement. It is the flagship use case of NSX security.
Gateway Firewall Perimeter Policy
A Tier-0 or Tier-1 rule set applied to north-south traffic entering or leaving the NSX domain, with stateful filtering and logging. It complements, rather than replaces, DFW. It is the NSX equivalent of a traditional edge firewall.
Distributed IDS/IPS Signature Management
The NSX Manager workflow for downloading, updating, and profiling IDS/IPS signature sets, including per-profile enable/disable. It applies to distributed IDS/IPS at the vNIC. It is the day-to-day maintenance task for the ATP service.
URL Filtering Policy
A Gateway Firewall rule that allows or blocks outbound HTTP/HTTPS by category, list, or FQDN, enforced on Tier-0 Edges. It provides web egress control without a third-party proxy. It is the NSX-native alternative to dedicated secure web gateways.
Dynamic Tag-Based Group
An NSX security group whose membership is computed from VM tags rather than static lists, so policy follows workloads as they are tagged. Tags come from vCenter, NSX, or automation. Tag-based groups are the cleanest model for large, dynamic estates.
Global IDS/IPS Policy (Federation)
An IDS/IPS rule set authored on the Global Manager and pushed to Local Managers for consistent cross-site threat detection. It guarantees identical posture across federated sites. It complements site-local operational tuning.
Service Insertion Chain
An ordered list of partner services (Inspection, Decryption, AV) that traffic traverses via redirect rules. North-South chains live on Gateway Firewall; East-West chains apply at DFW via NetX.
Partner Service Manager
NSX object registering a 3rd-party vendor (e.g., Palo Alto Panorama, Check Point). Provides service profiles used by redirect rules and drives health/deployment of service VMs.
NSX Intelligence (historical)
Former standalone appliance producing recommendation-based DFW policies. Functionality merged into Security Intelligence on NAPP/SSP with the vDefend rebrand.
Time-Based / Schedule-Based Rule
Gateway or DFW rule attribute that confines rule activity to defined windows; useful for change-control exceptions and 'allow patching' windows.
NSX VPC Subnet Model
The NSX VPC construct that bundles subnets, a default Tier-1, DFW, and NAT into a self-serve unit consumed via API or VCF Automation. It is the modern multi-tenant networking primitive in NSX. It is a prerequisite for All-Apps-Org tenant isolation.
Centralized Transit Gateway (CTGW)
An NSX construct that aggregates traffic between many VPCs and the external Tier-0, with centralized services and statefulness. It simplifies hub-and-spoke topologies. It is the typical choice for shared-services access from VPCs.
Distributed Transit Gateway (DTGW)
An NSX construct providing distributed forwarding between VPCs without hairpinning through an Edge, optimized for east-west tenant traffic. It complements CTGW for high-bandwidth inter-VPC communication. It is selected at VPC design time.
VPC Subnet Type
The classification of a VPC subnet as Public (internet-facing), Private-VPC (reachable across the VPC only), or Private-Transit Gateway (routed via TGW). The type determines reachability and services. It is fundamental to VPC network design.
NSX Project
An NSX multi-tenant management construct providing isolated Tier-1 gateways, segments, DFW, and RBAC within a shared Tier-0. Projects predate VPCs and target in-platform tenancy. They can contain VPCs for nested tenancy models.
NSX-Backed Supervisor Networking
A VKS Supervisor networking mode that uses NSX VPC and CTGW to provide per-namespace Tier-1 gateways, segments, and LBs automatically. It is the recommended mode in full VCF deployments. It differs sharply from VDS-backed Supervisor in isolation and capability.
Segment Types (Overlay vs VLAN)
Overlay segments are L2 across transport zone via Geneve; VLAN segments bridge to physical VLANs via Edge or host uplink. Service interfaces and uplink interfaces use VLAN segments.
Bridged Segment
L2 bridge between an overlay segment and a VLAN on Edge nodes. Used to migrate workloads from physical VLANs into overlay without changing IPs.
NAT on Tier-1
SNAT, DNAT, Reflexive NAT, and NO-NAT rules configured on Tier-1 gateway. Common pattern for tenant-isolated projects to reach shared services via SNAT to a pool.
DHCP Profiles
NSX supports DHCP Server (in SR) and DHCP Relay profiles attached to segments or Tier-1 gateways. Relay forwards requests to external DHCP, server profile sets ranges/options inline.
North-South Packet Walk
The end-to-end traversal a VM-to-Internet packet takes through DFW, Tier-1 DR, Tier-0 DR, Edge SR, Gateway Firewall, and finally to the physical uplink. Mapping the walk is the core skill for NSX egress troubleshooting. Traceflow is the primary tool for confirming it.
TEP Connectivity Check
A validation step using vmkping -I vmkN -s <size> -d to confirm MTU-correct reachability between TEPs across the underlay. Use -s 1572 to validate a 1600-byte MTU (Geneve minimum) or -s 1672 for 1700-byte MTU (NSX default). The fastest way to isolate overlay issues from physical-network issues; the first test after any NSX fabric change.
BGP ASN Mismatch
A neighbor-down root cause where the NSX Tier-0 is configured with one Autonomous System Number while the physical peer expects another. The session oscillates through Active/Idle. Fixing it requires coordinating the ASN with the network team.
get bgp neighbor CLI
An Edge-node command that lists BGP peers, states, counters, and last error. It is the authoritative view of routing-protocol health on NSX Edges. It is typically the second command run after tunnel checks.
NAT Flow Troubleshooting
The process of verifying SNAT/DNAT rule order, applied scope, and session state, often using get firewall connections on the Edge. Common issues include overlapping rules and asymmetric paths. It is a frequent VCAP-level exam topic.
IPFIX Flow Export
A standard (RFC 7011) NSX uses to export per-flow records with tuple, timing, and byte counters to collectors like VCF Operations for Networks. Enabling IPFIX provides deep east-west visibility without packet capture. It is essential for traffic-based troubleshooting.
Traceflow
Injects a synthetic packet from a source logical port to a destination and reports every hop (DFW, segment, router, Edge) and drop cause. Key tool for segmentation and routing validation.
Port Mirroring (NSX)
Logical SPAN from a source port/segment to a destination (local ERSPAN or remote analyzer). Used for deep-packet analysis when Traceflow/PCAP is insufficient.
Geneve Encapsulation Overhead
Geneve adds ~50–76 bytes (outer IP+UDP+Geneve header). Underlay MTU must be ≥1600 (1700 recommended) to carry a 1500-byte inner frame without fragmentation.
Edge Troubleshooting CLI
Key commands: 'get logical-router', 'get logical-router <UUID> route', 'get bgp neighbor summary', 'get interfaces', 'get forwarding'. Run in NSX Edge admin CLI to inspect SR state.
Central CLI
From NSX Manager 'nsxcli' you can run 'on <node> exec <cmd>' to target a specific transport node without SSHing in. Useful for multi-host checks in automation.