GettingStartedWithNSX
GettingStartedWithNSX
Steve Baca
BRANCH
BRANCH
BRANCH
BRANCH
TELCO/NFV
BRANCH
BRANCH EDGE/IOT
BRANCH
EDGE/IOT
Virtual Cloud
Networking Built-in
Automated
Programmable
Application Centric
Branch
Users Offices
NSX Data Center NSX Cloud AppDefense NSX SD-WAN NSX Hybrid Connect
Networking and security for Networking and security for Modern application security by VeloCloud Data center and cloud
data Public Cloud workloads WAN connectivity workload migration
center workloads services
Multi-Cloud and
Expand the network Multi-Hypervisor
NSX-T
•North-south routing
•East-west routing
•Multitenant support
•High-availability support
•IPv6 support
•Multicast support
•Firewall operations
Logical Routing: Multitier Topology
In multitier distributed routing:
• Tier-0 and Tier-1 routers are also instantiated on the hypervisors to prevent hairpinning.
• Fully distributed architecture: As much routing as possible is performed upfront at the source.
ESXi-1 ESXi-2
Tier-0 DR Tier-0 DR
Distinct Routing
Peer
VPN
Tenant 1 Tenant 2
Two-Tier Routing with Connectivity Options for Workload (2)
Stateful services runs in a centralized mode:
• FW, NAT, LB DHCP, and VPN
• Bridging services
Tier-0 services:
• DPDK-based forwarding: Routing and bridging
Tier-1 services:
• Tenant routing
Internet
Network Perimeter
PCI
Every Workload can have:
Scope
Individual firewalls
Individual security policies
Policies can be defined based on
any context
VM attributes
Network attributes
Application attributes
Internet
Perimeter
• Zero Trust / Least Privilege model. Firewall
DMZ
App
• Policies align with logical
groups.
• Network topology-agnostic.
Services
ESXi
We’ve helped thousands of
organizations succeed with
You don’t need to go it alone. NSX through: