WAN
Internet
NSX Edge:
• Connects isolated
networks to shared
uplink and provides
network services like
FW, LB, …
• Supports Multi-
VM VM Tenancy in Cloud
environment
VM VM
VM VM
Firewall Rule configuration with IP, Port ranges, Grouping Objects, VC Containers
Routing Static as well as Dynamic Routing protocols support (OSPF, BGP, ISIS)
Load Balancing Configure Virtual Servers and backend pools using IP addresses or VC Objects
Site-to-Site VPN IPSec site to site VPN between two Edges or other vendor VPN terminators.
SSL VPN Allow remote users to access the private networks behind Edge GSW.
High Availability Active-Standby HA capability which works well with vSphere HA.
Perimeter FW
N-S
(Physical)
protection
Quad-Large
4 vCPU Suitable for high
1024 MB vRAM performance Firewall
Large
2 vCPU
1024 MB vRAM
Compact
1 vCPU
512MB vRAM
Tenant A
Features
• Dynamic Routing:
Tenant B OSPF/eBGP/iBGP/IS-IS
L2
L2
Tenant C • North-South Routing
L2 L2
• Virtualization context firewall
L2
L2 L2
Scale & Performance
L2
Use Cases
Use Cases
Features
• SSL-based
• Web-proxy Support
• L2 Extension to Cloud
VM VM VM • Broadcast support
• Cloud On-boarding
• Cloud Bursting
Internal PG
• Modes of configuration
– Advanced/Manual mode: Internal vNic designated by the user
– Auto configure mode: NSX Manager uses first available internal vNic
• Other Redundancy
– Physical redundancy with host monitoring and vSphere HA
– Process restart redundancy with process monitoring
DHCP When Standby becomes active the HA link synchronization should preserve DHCP
allocation table state.
Load Balancer For L7, Sticky tables are synced. Health of backend pool servers is synced.
Will perform a back-end status health check before becoming available.
IPSec VPN When Standby becomes active the tunnels should reconnect automatically
SSL VPN When Standby becomes active the client should reconnect automatically
L2 VPN High Availability is not supported for this feature. Will be supported in future release.
External Network
VM VM VM VM
VM VM VM VM
VXLAN 5022
VM VM VM VM
Redistribute Redistribute
connected connected
NAT 20,000
IPSec Sites / Tunnels 128,000 This is a number published across a max of 2,000 Edge Appliances
which can be supported in NSX
Large-Edge X-Large-Edge
Max Limit Compact-Edge