NSX-v to NSX-T Migration: The Playbook Nobody Gives You
Having led this migration at enterprise scale, here’s the real playbook — including the gotchas that aren’t in VMware’s documentation.
Having led this migration at enterprise scale, here’s the real playbook — including the gotchas that aren’t in VMware’s documentation.
If the Distributed Firewall is NSX-V’s most-used feature, the Edge Services Gateway (ESG) is its most confusing. ESGs are software-defined appliances that provide routing, NAT, load balancing, VPN, and perimeter firewall functions. They’re powerful, but the design decisions around ESG sizing and topology have long-term consequences that aren’t obvious when you’re setting one up for … Read more
Organizations deploying NSX-V often already have physical perimeter firewalls — Palo Alto, Fortinet, Cisco ASA, or Check Point. A common design question: what does NSX do, and what does the physical firewall continue to do? Getting this boundary wrong creates operational complexity without commensurate security benefit. The Principle: NSX for East-West, Physical for North-South The … Read more
NSX-V (for vSphere) is VMware’s software-defined networking platform for vSphere environments. It decouples network functions — switching, routing, firewalling, load balancing — from physical infrastructure and manages them in software. The pitch is compelling: micro-segmentation, zero-trust networking, rapid deployment of complex network topologies without touching physical switches. The reality of deploying it for the first … Read more
VMware’s virtual networking model is one of the most powerful things about the platform and one of the most common sources of misconfiguration in smaller deployments. The concepts are learnable in an afternoon, but the consequences of getting them wrong can be subtle and persistent. Standard vSwitch vs. Distributed vSwitch ESXi standalone hosts use Standard … Read more