Software that handles networking and security across VCF, covering firewalling, load balancing, NAT, VPCs, overlay segments and Tier-0/1 gateways.
Also called VMware NSX.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains NSX in context, with comparison tables and the common traps.
Terms in this definition
- VMware Cloud Foundation
Broadcom's platform for private cloud. It unifies management of NSX, vSAN, vSphere, VCF Automation and VCF Operations as one fleet; VVF, by contrast, lacks automation and cloud management.
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- Azure NAT Gateway
Gives every resource in a subnet a managed way out to the internet through one or more fixed public IP addresses, while accepting no unsolicited inbound connections. Azure Container Apps can use it only when the environment is a workload profiles one.
Related terms
- Active Standby
An NSX gateway HA mode where one Edge node handles traffic while a second waits to take over. Stateful services such as NAT, VPN, load balancing and the stateful firewall depend on it, and VCF Automation 9.0 expects its Tier-0 to be set up this way.
- Cloud account
An endpoint plus credentials, for example for vCenter, NSX, VCF, AWS, Azure or Google Cloud, that VCF Operations and VCF Automation (VM Apps) use to gather data or provision resources.
- Cloud proxy
Also named the VCF Operations collector in the 9.0 installer and design guides. This appliance pulls metrics from vCenter, NSX and similar endpoints and pushes them, one way only, up to VCF Operations.
- Default project
Lets VPCs be used in NSX without setting up any tenant projects. From the vSphere Client, vCenter admins can make VPCs, subnets and external IPs inside it.
- DFW
Distributed firewall. Stateful rules from NSX (vDefend) are enforced right at each virtual NIC inside the hypervisor, giving micro-segmentation between workloads. Gateway firewalls on Tier-0/1 are a separate thing.
- Distributed switch profile
Decides how many vSphere Distributed Switches a new cluster or domain gets: one shared by all traffic (Default, recommended), two that split off storage or NSX, three that split off both, or a custom layout.
- DNAT
Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.
- External connection
Tells NSX how a transit gateway gets out to non-NSX networks and which services it gets: centralised through Edge-hosted Tier-0, or distributed straight onto host VLANs.