Academy/VCAP — VCF Networking (3V0-25.25)
VCF

VCAP — VCF Networking (3V0-25.25)

VCF 9.0vcap-advanced

Master NSX federation, advanced routing with BGP/OSPF, micro-segmentation at scale, ALB integration, and multi-site networking for large enterprise deployments. Deep focus on operational resiliency and automation.

3V0-25.25
VCAP
60
Questions
135m
Duration
300/500
Pass Score
30
Objectives

Exam Blueprint Weights

Section titles, groupings and weights below are VCDX Academy study groupings, NOT the official Broadcom blueprint structure. Broadcom publishes no section weights. Always cross-check the official exam guide. Official exam guide ↗
Section 1 — Architecture
~15%
Section 2 — Routing Design
~25%
High Weight
Section 3 — Security Services
~20%
Section 4 — Load Balancing and Network S
~15%
Section 5 — Troubleshooting
~25%
High Weight

Version Evolution

VCAP Networking covers advanced NSX design and operations. Evolution mirrors NSX itself: NSX-V edge-centric → NSX-T with T0/T1 model → NSX 4.x with federation and advanced security. VCF 9.0 aligns NSX versioning with VCF (NSX 9.0.x). Exam focuses on multi-site federation, edge design, and integration with Avi ALB for load balancing.

Learning Outcomes

  • Understand Advanced VCF 9.0 Networking (NSX & Advanced Routing) concepts and architecture
  • IPv4 Multicast (M-BGP):Standard BGP carries unicast only. For multicast (one-to-many traffic, e.g., video streaming), enable MBGP: separate address family (AFI/SAFI 1/2), advertise multicast routes. N
  • BGP Route Policies to Prevent VRF Leak:In multi-VRF deployments, accidentally leak routes from high-security VRF to low-security VRF = security breach. Apply export policies on Tier-0: per-VRF route m
  • SSL VPN Use Case:Employee on public WiFi needs access to internal file shares. Connects to NSX edge SSL VPN endpoint, authenticates (AD credentials), receives virtual network adapter (tun0). Traffic f

Advanced NSX Design & Multi-Site Federation#

NSX Form Factors & Sizing

NSX deployment sizing depends on workload scale, geographic distribution, and performance SLAs:

Small Form Factor

: 1 NSX Manager, 2 Edge nodes (1GbE VNICs). Max: 64 compute nodes, 1024 logical switches. Suitable for 50-500 VMs.

Medium Form Factor

: 3 NSX Managers (cluster), 4 Edge nodes (10GbE). Max: 512 compute nodes, 8000 logical switches. 500-5000 VMs.

Large Form Factor

: 3 NSX Managers (cluster), 8+ Edge nodes (10/40GbE). Max: 2048 compute nodes, 16000 logical switches. 5000+ VMs.

Edge VM Sizing (identical in NSX 4.2 and NSX 9.0; disk is 200 GB for every size)

: Small 2 vCPU / 4 GB - proof-of-concept ONLY, T1 L7 rules not realized. Medium 4 vCPU / 8 GB - L2-L4, under 2 Gbps. Large 8 vCPU / 32 GB - L2-L4 at 2-10 Gbps, plus L7 LB and TLS inspection. Extra Large 16 vCPU / 64 GB - high-throughput L7 LB, VPN, URL filtering, IDS/IPS. Broadcom does not designate one size 'production-recommended' - size by throughput and feature band. DPDK is a property of the host CPU (AESNI + 1 GB huge pages), not of the Edge form factor.

Manager Node Cluster

: 3 nodes minimum for HA; etcd quorum requires all 3 healthy. Typically deployed on vSAN for storage redundancy.

NSX Federation: Multi-Site Architecture

Federation allows multiple NSX domains (sites) to operate as unified network fabric:

Global Manager

: Single point of management. Active/Active or Active/Standby failover. Runs on dedicated VM or appliance (16vCPU/32GB typical).

Local Managers

: One per site; subordinate to Global Manager. Independent operation if Global Manager unavailable (graceful degradation).

Stretched Segments

: Logical switch synchronized across sites. VM can vMotion between sites while maintaining IP/MAC. ARP/DHCP handled by Global Manager.

Location-Aware Groups

: DFW rules scoped per location. Example: block-malware group can differ per site; Global Manager compiles per-location rules.

Gateway Failover

: Tier-0 gateways at each site peer upstream; stretched VIP failover managed by VRRP (Virtual Router Redundancy Protocol).

┌──────────────────────────────────────────────────────────────┐
│                      Global Manager                          │
│          (Active/Standby or Active/Active failover)         │
└───────────────────────┬──────────────────────────────────────┘
          ┌─────────────┴─────────────┐
          │                           │
    ┌─────▼─────┐             ┌───────▼────┐
    │  Site-A   │             │  Site-B    │
    │  Local Mgr│             │  Local Mgr │
    │  3x ESXi  │             │  3x ESXi   │
    │ Tier-0 GW │             │ Tier-0 GW  │
    └─────┬─────┘             └────┬───────┘
          │ BGP Peer               │ BGP Peer
          │ (to core)              │ (to core)
    ┌─────┴─────────────────────────┴──────┐
    │        IP WAN / L3 Underlay          │
    └───────────────────────────────────────┘

Stretched Segments: Segment-A exists on both sites

DFW Rules: Location-aware rules apply per site

Service VLAN: Unique per site; GSLB load balances across

N-VDS to VDS Migration

Migrating from NSX-V to NSX-T or from older NSX-T builds requires careful planning:

N-VDS (NSX Virtual Distributed Switch)

: NSX-V construct; DVports bound to NSX VLANs. Cannot coexist with NSX-T.

Migration Strategy

: (1) Dual-stack approach—run both N-VDS and VDS during migration, (2) Rolling vMotion of VMs from N-VDS segments to NSX-T segments, (3) Service vMotion (move network interface) as final step.

Cutover Validation

: Test floating traffic across dual stack; validate DFW rules migration; verify GSLB/DNS failover.

Rollback Plan

: Maintain N-VDS configuration until NSX-T fully proven; keep 2-week rollback window.

Transport Node Profiles & NIOC

Transport Node Profiles standardize hypervisor configuration at scale:

Transport Node Profile

: Template defining VMKs (Virtual Machine Kernel adapters), VLAN transport zones, overlay transport zones. Applied to cluster or host level.

Network I/O Control (NIOC)

: QoS for VMK traffic. Example: vSAN traffic guaranteed 20% bandwidth, vMotion 10%, management 5%, VM data best-effort. Enforces fairness across competing workloads.

MTU Sizing

: Geneve overlay minimum MTU is 1600; 1700 is recommended and is the NSX default Global TEP MTU (headroom for future Geneve options). VCF design rule VCF-NET-REQD-OVL-001: overlay segment MTU = TEP MTU minus 200. Where the fabric supports jumbo frames, 9000 is recommended. Validate end-to-end path supports MTU.

Uplink Profiles

: Define active/standby topology, failover strategy (active-active requires LAG or ECMP), LLDP/CDP for underlay discovery.

#!/bin/bash

NSX CLI: Create Transport Node Profile

  • nsx-cli
  • enter admin
  • create transport-node-profile profile-a
  • set uplink-mtu 1700
  • set vlans vlan-transport-zone id 0-4094
  • set overlay overlay-transport-zone
  • apply

Assign to cluster

  • create transport-node cluster-1
  • set transport-node-profile-name profile-a
  • apply

Verify

get transport-nodes
show transport-node cluster-1

Key Takeaways

  • For exam: NSX form factors define max nodes/switches (Small=64/1024, Medium=512/8000, Large=2048/16000). Edge VM sizing: Small 2vCPU/4GB (PoC only), Medium 4/8 (<2 Gbps), Large 8/32 (2-10 Gbps + L7 LB/TLS), XL 16/64 (L7 LB, VPN, IDS/IPS). All 200 GB disk.
  • For exam: Federation architecture: Global Manager (16vCPU/32GB) + Local Managers per site. Stretched segments enable VM vMotion while maintaining IP/MAC. Location-aware DFW rules differ per site.
  • For exam: Transport Node Profile template for VMKs, VLAN/overlay zones. NIOC enforces QoS fairness (vSAN 20%, vMotion 10%, management 5%). MTU: 1600 minimum for Geneve overlay, 1700 recommended (NSX default TEP MTU); 9000 where the fabric supports jumbo frames. Fabric MTU should exceed workload MTU by at least 100 bytes, 200 preferred.

Advanced Routing: BGP, OSPF, and Route Redistribution#

BGP Deep Dive: Route Maps, Prefix Lists, Community Strings

Border Gateway Protocol is critical for multi-site, high-availability networking:

BGP Basics

: Autonomous System Number (ASN) per site. Tier-0 router acts as BGP speaker; advertises pod CIDR, service CIDR, stretched segment CIDR to upstream DC fabric.

Route Maps

: Policy-based routing logic. Example: Tag pod routes with community 65000:1000 (production), pod routes with 65000:1001 (test). Upstream routers use communities to apply different QoS per workload.

Prefix Lists

: Define allowed IP ranges for incoming/outgoing routes. Prevent accidental advertisement of 0.0.0.0/0 or private ranges.

AS Path Prepend

: Artificially inflate AS path to deprioritize certain routes. Example: prepend 65000 3 times to make backup site route less preferred; upstream chooses primary site by shortest AS path.

Local Preference (LocalPref)

: BGP attribute 0-4294967295. Higher value = preferred. Set high LocalPref on primary site, lower on secondary. Overrides AS path length.

Route Redistribution

: Inject connected routes (VM networks), static routes, OSPF routes into BGP. Example: redistribute OSPF routes learned in data center as BGP route 65000:1 (external route).

#!/bin/bash

NSX CLI: Configure advanced BGP

  • nsx-cli
  • enter admin
  • configure tier-0-router tier0-a
  • configure bgp
  • configure address-family ipv4
  • configure prefix-list prod-prefixes
  • 10 permit 10.100.0.0/16 # Pod CIDR
  • 20 permit 10.200.0.0/16 # Service CIDR
  • exit
  • configure route-map prod-tag
  • 10 match ip address prefix-list prod-prefixes
  • 10 set community 65000:1000
  • 20 match ip address prefix-list test-prefixes
  • 20 set community 65000:1001
  • exit
  • configure neighbor 10.0.0.1 (upstream router)
  • remote-as 65001
  • address-family ipv4
  • route-map prod-tag out
  • maximum-prefix 10000 warning-only
  • exit
  • apply

OSPF Areas & Multi-Area Design

Open Shortest Path First suitable for intra-datacenter routing (NSX-T → NSX-T):

Area 0 (Backbone)

: Tier-0 routers connected via OSPF. All other areas must connect through backbone.

Area Types

: Standard (full adjacency), Stub (no external routes, smaller LSA flooding), Totally Stubby (no external, no inter-area routes learned outside area).

Cost Calculation

: Cost = 10^8 / bandwidth. GbE = 100 cost, 10GbE = 10 cost. Manual override for non-standard topologies.

Convergence

: LSP (Link-State Packet) flooded every 30 seconds (configurable); convergence time ~10-30 seconds upon topology change.

ECMP Load Balancing

: Up to 8 equal-cost paths supported. Example: 4 paths to remote site via 4 edge nodes, traffic load-balanced across all.

Route Redistribution at Scale

Combining multiple routing protocols requires careful redistribution design:

BGP ← OSPF
: Inject OSPF intra-area (Type 1/2 LSAs) into BGP as "internal" routes (AS path length = 0). OSPF inter-area routes (Type 3 LSAs) advertised as "external" routes.
OSPF ← Static

: Redistribute static routes (default route from ISP) into OSPF as external routes. Backup static route requires lower metric than advertised route to trigger failover.

Filtering

: Deny redistribution of specific networks. Example: deny OSPF internal 10.255.255.0/24 (admin subnet) from BGP redistribution to avoid exposure to untrusted peers.

Metric Translation

: OSPF cost ≠ BGP AS path. Define conversion: high OSPF cost = low BGP weight (more preferred) for load balancing asymmetry.

ECMP & Multi-Path Load Balancing

Maximizing throughput via parallel paths:

8-Way ECMP

: Tier-0 can load-balance across up to 8 equal-cost paths. Requires 8 edge nodes with active-active uplinks.

Hash Algorithm

: NSX uses 5-tuple hash (source IP, dest IP, source port, dest port, protocol) by default. Configurable to 3-tuple (source/dest IP, protocol) for coarser balancing.

Asymmetric Paths

: Return traffic may take different path than outbound (valid in NSX). Ensure firewall rules symmetric; no hairpinning required.

Link Redundancy

: 8 edge nodes at same site all contribute to ECMP pool. Loss of 1 edge = 12.5% throughput reduction (1/8 paths). Rebalance load automatically.

IPv6 & Dual-Stack Design

VCF 9.0 supports IPv6 at Tier-0/Tier-1 level:

Dual-Stack Segments

: Logical switch with both IPv4 and IPv6 CIDR. DHCPv6 server can auto-assign /64 to pods.

Router Advertisement (RA)

: Tier-1 router issues RA packets; stateless autoconfig for VM networks. Stateful DHCPv6 alternative.

BGP IPv6

: Separate address family (AFI 2, SAFI 1) in BGP config. Tier-0 advertises both IPv4 and IPv6 routes independently.

NAT64

: NSX supports stateless NAT64 for IPv6-only clients reaching IPv4-only servers. Pool of IPv4 addresses mapped to ::/96 prefix.

Key Takeaways

  • For exam: BGP route maps + communities tag production (65000:1000) vs. test routes (65000:1001) for upstream QoS. AS path prepend deprioritizes backup routes. LocalPref 0-4294967295 overrides AS path length.
  • For exam: OSPF cost = 10^8 / bandwidth (GbE=100, 10GbE=10). Area 0 backbone required. Convergence ~10-30 seconds on LSP flooding (30 sec default interval). Type 1/2=intra-area, Type 3=inter-area.
  • For exam: ECMP up to 8 equal-cost paths. Hash algorithm: 5-tuple (IP src/dst, port src/dst, proto) default, configurable to 3-tuple. Loss of 1 edge = 12.5% throughput reduction. Asymmetric paths valid; ensure firewall rule symmetry.

Advanced BGP Engineering#

BGP Session Types and Scalability

BGP session design determines convergence time, route scalability, and failover behavior. NSX edges support three primary architectures: iBGP full-mesh (N squared sessions, complex), route-reflector (star topology, simpler), and confederation (hierarchical for multi-region).

Flow-Specific Routes and BGP Routing Policies

Advanced scenarios require route filtering and re-distribution:

Key Takeaways

  • IPv4 Multicast (M-BGP):Standard BGP carries unicast only. For multicast (one-to-many traffic, e.g., video streaming), enable MBGP: separate address family (AFI/SAFI 1/2), advertise multicast routes. NSX 4.1+ supports MBGP. Requires upstream ISP MBGP support.
  • BGP Route Policies to Prevent VRF Leak:In multi-VRF deployments, accidentally leak routes from high-security VRF to low-security VRF = security breach. Apply export policies on Tier-0: per-VRF route maps denying routes from forbidden VRFs. Monitor route advertisements: show bgp ipv4 unicast neighbor

Multi-VRF on Tier-0#

VRF-Lite and VRF Attachment Strategy

VRF-Lite enables multiple independent routing tables on a single Tier-0. Each VRF has separate BGP session, route table, and interface namespace. Use case: multi-tenant deployments (each tenant = VRF), PCI zone isolation (payment processing VRF separate from general VRF), OT/IT isolation (operational tech on VRF-OT, IT on VRF-IT).

Key Takeaways

  • For exam: VRF-Lite = separate routing tables + BGP sessions on single Tier-0. Each VRF independent route table and interface namespace. Use for multi-tenant, PCI isolation, OT/IT segregation.
  • For exam: Route leak vulnerability: high-security VRF → low-security VRF = breach. Mitigate with export route maps per VRF, deny forbidden VRF routes. Monitor: show bgp ipv4 unicast neighbor.
  • For exam: VRF-Lite more efficient than multi-site federation for single-site isolation. Federation for stretched segments and GSLB across geographic locations.

Advanced NSX Federation#

Global Manager Cluster Architecture: RAFT-based Consensus

NSX Federation enables multi-site deployments with global object management. Global Manager (GM) cluster (3 nodes in RAFT consensus) centralizes policy, stretched segments, and global groups. Local Managers (one per site) register with GM, enforce global policies locally.

Key Takeaways

  • For exam: Global Manager cluster: 3 nodes RAFT consensus. Local Managers per site register with GM and enforce global policies locally. Graceful degradation if GM unavailable.
  • For exam: Stretched segments synchronized across sites. VM vMotion maintains IP/MAC. ARP/DHCP handled by Global Manager. Location-aware DFW rules compiled per-site by GM.
  • For exam: Gateway failover VRRP (Virtual Router Redundancy Protocol). Tier-0 gateways peer upstream per site. GSLB load balances service VIPs across sites.

Dataplane Performance and DPDK Tuning#

Edge VM CPU Pinning and Hugepages

NSX edge performance depends on dataplane (DP) core allocation and pinning. Edges run control plane (CP) on one core (management, BGP, SSH), dataplane on N cores (packet forwarding).

Key Takeaways

  • For exam: NSX edge architecture: 1 CP core (management, BGP, SSH) + N DP cores (packet forwarding). CPU pinning mandatory for predictable performance. Hugepages reduce TLB misses.
  • For exam: DPDK (Data Plane Development Kit) enables high-throughput packet processing. CPU isolation avoids context switches. Monitor: NSX Manager → System → Performance → Edge.
  • For exam: DP core saturation = packet drops. Scale horizontally: add more edge nodes. Verify uplink capacity matches DP throughput (no bottleneck upstream).

Enterprise Integrations with Third-Party Infrastructure#

Cisco ACI Border Leaf Peering

NSX Tier-0 can establish eBGP sessions with Cisco ACI border leafs, enabling multi-vendor fabric. NSX advertises its routes (workload subnets), ACI advertises fabric routes.

Key Takeaways

  • For exam: Cisco ACI integration: eBGP session NSX Tier-0 ↔ ACI border leaf. NSX advertises workload subnets; ACI advertises fabric routes. ASN differs (NSX vs. ACI), enables eBGP dynamic peering.
  • For exam: Multi-vendor fabric: validate BGP convergence, route leak prevention (route maps, prefix lists). Test failover: disable one border leaf, verify alternative path.
  • For exam: Integration complexity trade-off: ACI + NSX = advanced segmentation but operational overhead. Single vendor (NSX-only) simpler to manage but less flexibility if ACI already deployed.

IPv6 in NSX: Dual-Stack and Transition Mechanisms#

Dual-Stack Segment Support and IPv6 Routing

NSX supports dual-stack segments: both IPv4 and IPv6 subnets on same logical switch. Tier-1 routers support IPv6 static routes and dynamic routing (BGP, OSPFv3 in NSX 4.1+).

Key Takeaways

  • For exam: Dual-stack segment = IPv4 + IPv6 CIDR on same logical switch. DHCPv6 auto-assign /64 to pods. Router Advertisement (RA) enables stateless autoconfig vs. stateful DHCPv6.
  • For exam: BGP IPv6: separate AFI 2 / SAFI 1. Tier-0 advertises IPv4 and IPv6 routes independently. OSPFv3 supported in NSX 4.1+ (intra-DC IPv6 routing).
  • For exam: NAT64 stateless: IPv6-only clients → IPv4-only servers. Pool of IPv4 addresses mapped to ::/96 prefix. Translation transparent at NSX Tier-1.

VPN Deep Dive: IPSec, SSL, and Layer-2 Stretch#

IPSec VPN: IKEv2, Crypto Profiles, PFS, Rekey

NSX supports route-based IPSec (IPSec encapsulation) and policy-based IPSec (packet classification first, then encapsulation). IKEv2 (Internet Key Exchange version 2) is standard for key negotiation (IKEv1 deprecated).

SSL VPN: Layer-7 Remote Access

SSL VPN (client-to-gateway, not site-to-site) provides remote-access to corporate network. NSX edge runs SSL VPN server, users connect via web browser or native client, tunnel created over HTTPS (port 443).

Layer-2 VPN (Deprecated, Rarely Used)

L2VPN extends Ethernet segment across WAN (pre-VXLAN overlay era, now mostly replaced by NSX Federation stretched segments). Still used in legacy migrations. Performance: layer 2 forwarding (slower than layer 3 routing), broadcast flooding across WAN (network storms possible). Avoid new designs; use stretched segments with NSX Federation instead.

Key Takeaways

  • SSL VPN Use Case:Employee on public WiFi needs access to internal file shares. Connects to NSX edge SSL VPN endpoint, authenticates (AD credentials), receives virtual network adapter (tun0). Traffic from employee encrypted and tunneled to NSX edge. Useful for BYOD (Bring Your Own Device) scenarios,

Network Security Engineering at Scale#

DFW Rule Management: 10k+ Rules Operational Excellence

Mature NSX deployments grow to tens of thousands of DFW rules. Managing that scale requires discipline, automation, and performance tuning.

Lab Exercise: Design and Deploy Multi-Tier Segmentation

Key Takeaways

  • For exam: DFW rule hierarchy: section → rules. Sections ordered by priority. Implicit deny at end. Rules evaluated top-to-bottom; first match wins.
  • For exam: 10k+ rules optimization: break into sections per tier (management, app, db, edge). Use groups instead of individual IPs (membership updates push to all rules). Monitor rule hit rate.
  • For exam: Performance tuning: enable stateful firewall (track connections), prefer L3 + L4 rules over L7 inspection (lower CPU). Test failover: verify rule sync across edges.

Exam Mapping: 3V0-25.25 — Advanced VCF 9.0 Networking (NSX & Advanced Routing)

  • See Advanced VCF 9.0 Networking (NSX & Advanced Routing) exam blueprint for detailed objectives

Labs in This Section

BGP Route Maps & Community-Based QoS

VCF 9.0Intermediate⏱ 120 min

OSPF Multi-Area & Route Redistribution

VCF 9.0Intermediate⏱ 150 min

Stretched Segment Failover & vMotion across Sites

VCF 9.0Intermediate⏱ 150 min

DFW Multi-Tier Micro-Segmentation

VCF 9.0Intermediate⏱ 75 min

Lab NN1: BGP Convergence & Graceful Restart on NSX Edges

VCF 9.0Intermediate⏱ 75 min

Lab NN2: VRF-Lite & Route Leaking for Multi-Tenant Isolation

VCF 9.0Intermediate⏱ 75 min

Lab NN3: Geneve Encapsulation Deep-Dive & MTU Validation

VCF 9.0Intermediate⏱ 75 min

Lab NN4: Edge Node Failover Scenarios Matrix

VCF 9.0Intermediate⏱ 75 min
📝 Quiz (50)
🃏 Flashcards (52)

📝 Quiz — VCAP Advanced Networking

0/50 correct

Architecture

Q1
NSX overlay uses Geneve encapsulation which requires the physical underlay to support what minimum MTU to avoid fragmentation?
  • 1500
  • 1600
  • 9000 required
  • 1280
NSX overlay uses Geneve encapsulation which adds ~50 bytes of header overhead to each frame. The physical underlay must support minimum 1600 MTU to avoid fragmentation. 1500 is standard (too small). 9000 is jumbo (recommended but not required). 1280 is IPv6 minimum.
Q2
BFD in NSX overlay is used to:
  • Encrypt tunnels
  • Quickly detect TEP-to-TEP tunnel failures
  • Replace BGP
  • Perform IDS inspection
BFD (Bidirectional Forwarding Detection) quickly detects TEP-to-TEP tunnel failures at sub-second intervals, enabling fast failover. It doesn't encrypt tunnels, replace BGP, or perform IDS inspection.
Q3
The NSX Management Plane in a cluster provides which functions?
  • Manager and Policy APIs with integrated controller services
  • Only firewall enforcement
  • Only BGP routing
  • Edge data plane forwarding
The NSX Management Plane cluster provides Manager and Policy APIs with integrated controller services. Controller functionality was merged into the Manager starting in NSX-T 3.x. It doesn't only enforce firewalls, handle BGP routing, or do Edge forwarding.
Q4
DPU-based acceleration offloads:
  • vCenter transactions
  • NSX data-plane functions (e.g., overlay/DFW) to a SmartNIC
  • Storage I/O to vSAN
  • BGP policy calculation
DPU-based acceleration offloads NSX data-plane functions (overlay encap/decap, DFW enforcement) to SmartNICs, freeing host CPU. It doesn't offload vCenter transactions, vSAN I/O, or BGP calculations.
Q5
Which transport zone type carries Geneve overlay traffic?
  • VLAN transport zone
  • Overlay transport zone
  • Global transport zone
  • Edge-only zone
Overlay transport zones carry Geneve-encapsulated overlay traffic. VLAN transport zones carry VLAN-tagged traffic. Global and Edge-only zones are not standard NSX transport zone types.

Routing Design

Security Services

Load Balancing and Network Services

Troubleshooting

🃏 Flashcards — VCAP Advanced Networking

52 cards
Card 1 of 52
Central Control Plane (CCP)
The NSX control plane function inside the NSX Manager cluster responsible for computing runtime state (segment tables, TEP lists) from policy and distributing it to transport nodes. It is distinct from the management plane that stores intent. CCP health is critical to fast convergence.

Labs in this section

Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.