build 7bbbddf7 | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 267 | 0 skipped | | format
apiVersion: soultec.ch/v1kind: Solutionmetadata: name: vmware/vmware-cloud-foundation/nsx locale: en labels: vendor: VMware VCF Networking capability/network: 2.16 capability/security: 2.16 capability/virtualization: 1.37 vendor/vmware: 0.88 annotations: source: src/content/solutions/en/vmware/vmware-cloud-foundation/nsx.md route: /en/solutions/vmware/vmware-cloud-foundation/nsx/ schema: /nerd/schema/solutions.json markdown: /en/solutions/vmware/vmware-cloud-foundation/nsx.mdspec: title: VCF Networking tags: [network, security, virtualization] vendors: [vmware] summary: >- Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology. photoNeed: >- A vSphere or VCF console on a real screen at soulTec: a cluster view, a running task, an inventory tree, so the reader should recognise the UI stub: false draft: false kind: product formerly: NSX editions: [vcf] addon: false sourceNote: >- Broadcom, VMware Cloud Foundation 9.1 and VMware vSphere Foundation 9.1: Feature Comparison & Upgrade Paths, read 2026-08-28 vendorName: VMware VCF Networking status: current practice: >- Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented. practiceReview: true sections: - heading:

What it is

body: | NSX virtualizes the network: switching, routing and firewalling run as software in the hypervisor rather than on dedicated hardware. The firewall sits at each VM's virtual port rather than at the edge of the network. That is the difference that matters. Traffic between two VMs on the same host is filtered without ever leaving the host. - heading:

What it is for

body: | Segmentation. The classic approach separates with VLANs and physical firewalls, and it scales exactly as long as the number of zones stays manageable. With a distributed firewall, which zone a VM belongs to becomes a property of the VM rather than of where it sits in the rack. The second use case is automation: networks that come up with an application and disappear with it. - heading:

What to watch

body: | NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up. Not because the technology is hard, but because nobody knows a rule set that grew over a decade in full. Segmentation needs an honest answer to which systems talk to each other today, and that answer is rarely written down.status: corpus: 267 services: - {ref: services/network, score: 0.83} - {ref: services/cloud, score: 0.49} - {ref: services/modern-workplace, score: 0.43} - {ref: services/security, score: 0.42} posts: - {ref: posts/distributed-network-security-services, score: 0.83} - {ref: posts/nsx-free-nsx-ebooks-to-download, score: 0.83} - {ref: posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter, score: 0.73} - {ref: posts/how-to-broadcom-download-token, score: 0.73} - {ref: posts/how-to-broadcom-support-portal-quick-links, score: 0.73} - {ref: posts/how-to-install-vcenter-without-dns, score: 0.73} experts: - {ref: experts/marco-betschart, score: 0.61} - {ref: experts/rico-lenherr, score: 0.61} - {ref: experts/aldo-gwerder, score: 0.55} neighbours: - {ref: solutions/vmware/vmware-cloud-foundation/addon/advanced-security, score: 0.83} - {ref: solutions/vmware/vmware-secure-access-service-edge, score: 0.83} - {ref: solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance, score: 0.73}
{ "apiVersion": "soultec.ch/v1", "kind": "Solution", "metadata": { "name": "vmware/vmware-cloud-foundation/nsx", "locale": "en", "labels": { "vendor": "VMware VCF Networking", "capability/network": "2.16", "capability/security": "2.16", "capability/virtualization": "1.37", "vendor/vmware": "0.88" }, "annotations": { "source": "src/content/solutions/en/vmware/vmware-cloud-foundation/nsx.md", "route": "/en/solutions/vmware/vmware-cloud-foundation/nsx/", "schema": "/nerd/schema/solutions.json", "markdown": "/en/solutions/vmware/vmware-cloud-foundation/nsx.md" } }, "spec": { "title": "VCF Networking", "tags": [ "network", "security", "virtualization" ], "vendors": [ "vmware" ], "summary": "Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology.", "photoNeed": "A vSphere or VCF console on a real screen at soulTec: a cluster view, a running task, an inventory tree, so the reader should recognise the UI", "stub": false, "draft": false, "kind": "product", "formerly": "NSX", "editions": [ "vcf" ], "addon": false, "sourceNote": "Broadcom, VMware Cloud Foundation 9.1 and VMware vSphere Foundation 9.1: Feature Comparison & Upgrade Paths, read 2026-08-28", "vendorName": "VMware VCF Networking", "status": "current", "practice": "Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented.\n", "practiceReview": true }, "sections": [ { "heading": "

What it is

",
"body": "NSX virtualizes the network: switching, routing and firewalling run as software in the\nhypervisor rather than on dedicated hardware. The firewall sits at each VM's virtual port\nrather than at the edge of the network.\n\nThat is the difference that matters. Traffic between two VMs on the same host is filtered\nwithout ever leaving the host." }, { "heading": "

What it is for

",
"body": "Segmentation. The classic approach separates with VLANs and physical firewalls, and it\nscales exactly as long as the number of zones stays manageable. With a distributed\nfirewall, which zone a VM belongs to becomes a property of the VM rather than of where it\nsits in the rack.\n\nThe second use case is automation: networks that come up with an application and\ndisappear with it." }, { "heading": "

What to watch

",
"body": "NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up.\nNot because the technology is hard, but because nobody knows a rule set that grew over a\ndecade in full. Segmentation needs an honest answer to which systems talk to each other\ntoday, and that answer is rarely written down." } ], "status": { "corpus": 267, "services": [ { "ref": "services/network", "score": "0.83" }, { "ref": "services/cloud", "score": "0.49" }, { "ref": "services/modern-workplace", "score": "0.43" }, { "ref": "services/security", "score": "0.42" } ], "posts": [ { "ref": "posts/distributed-network-security-services", "score": "0.83" }, { "ref": "posts/nsx-free-nsx-ebooks-to-download", "score": "0.83" }, { "ref": "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter", "score": "0.73" }, { "ref": "posts/how-to-broadcom-download-token", "score": "0.73" }, { "ref": "posts/how-to-broadcom-support-portal-quick-links", "score": "0.73" }, { "ref": "posts/how-to-install-vcenter-without-dns", "score": "0.73" } ], "experts": [ { "ref": "experts/marco-betschart", "score": "0.61" }, { "ref": "experts/rico-lenherr", "score": "0.61" }, { "ref": "experts/aldo-gwerder", "score": "0.55" } ], "neighbours": [ { "ref": "solutions/vmware/vmware-cloud-foundation/addon/advanced-security", "score": "0.83" }, { "ref": "solutions/vmware/vmware-secure-access-service-edge", "score": "0.83" }, { "ref": "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance", "score": "0.73" } ] }}
apiVersion = "soultec.ch/v1"kind = "Solution"[metadata]name = "vmware/vmware-cloud-foundation/nsx"locale = "en"[metadata.labels]vendor = "VMware VCF Networking""capability/network" = "2.16""capability/security" = "2.16""capability/virtualization" = "1.37""vendor/vmware" = "0.88"[metadata.annotations]source = "src/content/solutions/en/vmware/vmware-cloud-foundation/nsx.md"route = "/en/solutions/vmware/vmware-cloud-foundation/nsx/"schema = "/nerd/schema/solutions.json"markdown = "/en/solutions/vmware/vmware-cloud-foundation/nsx.md"[spec]title = "VCF Networking"tags = ["network", "security", "virtualization"]vendors = ["vmware"]summary = "Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology."photoNeed = "A vSphere or VCF console on a real screen at soulTec: a cluster view, a running task, an inventory tree, so the reader should recognise the UI"stub = falsedraft = falsekind = "product"formerly = "NSX"editions = ["vcf"]addon = falsesourceNote = "Broadcom, VMware Cloud Foundation 9.1 and VMware vSphere Foundation 9.1: Feature Comparison & Upgrade Paths, read 2026-08-28"vendorName = "VMware VCF Networking"status = "current"practice = '''Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented.'''practiceReview = true[[sections]]heading = "

What it is

"
body = '''NSX virtualizes the network: switching, routing and firewalling run as software in thehypervisor rather than on dedicated hardware. The firewall sits at each VM's virtual portrather than at the edge of the network.That is the difference that matters. Traffic between two VMs on the same host is filteredwithout ever leaving the host.'''[[sections]]heading = "

What it is for

"
body = '''Segmentation. The classic approach separates with VLANs and physical firewalls, and itscales exactly as long as the number of zones stays manageable. With a distributedfirewall, which zone a VM belongs to becomes a property of the VM rather than of where itsits in the rack.The second use case is automation: networks that come up with an application anddisappear with it.'''[[sections]]heading = "

What to watch

"
body = '''NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up.Not because the technology is hard, but because nobody knows a rule set that grew over adecade in full. Segmentation needs an honest answer to which systems talk to each othertoday, and that answer is rarely written down.'''[status]corpus = 267[[status.services]]ref = "services/network"score = "0.83"[[status.services]]ref = "services/cloud"score = "0.49"[[status.services]]ref = "services/modern-workplace"score = "0.43"[[status.services]]ref = "services/security"score = "0.42"[[status.posts]]ref = "posts/distributed-network-security-services"score = "0.83"[[status.posts]]ref = "posts/nsx-free-nsx-ebooks-to-download"score = "0.83"[[status.posts]]ref = "posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter"score = "0.73"[[status.posts]]ref = "posts/how-to-broadcom-download-token"score = "0.73"[[status.posts]]ref = "posts/how-to-broadcom-support-portal-quick-links"score = "0.73"[[status.posts]]ref = "posts/how-to-install-vcenter-without-dns"score = "0.73"[[status.experts]]ref = "experts/marco-betschart"score = "0.61"[[status.experts]]ref = "experts/rico-lenherr"score = "0.61"[[status.experts]]ref = "experts/aldo-gwerder"score = "0.55"[[status.neighbours]]ref = "solutions/vmware/vmware-cloud-foundation/addon/advanced-security"score = "0.83"[[status.neighbours]]ref = "solutions/vmware/vmware-secure-access-service-edge"score = "0.83"[[status.neighbours]]ref = "solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance"score = "0.73"
<?xml version="1.0" encoding="UTF-8"?><manifest kind="Solution"> <apiVersion>soultec.ch/v1</apiVersion> <metadata> <name>vmware/vmware-cloud-foundation/nsx</name> <locale>en</locale> <labels> <vendor>VMware VCF Networking</vendor> <entry key="capability/network">2.16</entry> <entry key="capability/security">2.16</entry> <entry key="capability/virtualization">1.37</entry> <entry key="vendor/vmware">0.88</entry> </labels> <annotations> <source>src/content/solutions/en/vmware/vmware-cloud-foundation/nsx.md</source> <route>/en/solutions/vmware/vmware-cloud-foundation/nsx/</route> <schema>/nerd/schema/solutions.json</schema> <markdown>/en/solutions/vmware/vmware-cloud-foundation/nsx.md</markdown> </annotations> </metadata> <spec> <title>VCF Networking</title> <tags> <item>network</item> <item>security</item> <item>virtualization</item> </tags> <vendors> <item>vmware</item> </vendors> <summary>Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology.</summary> <photoNeed>A vSphere or VCF console on a real screen at soulTec: a cluster view, a running task, an inventory tree, so the reader should recognise the UI</photoNeed> <stub>false</stub> <draft>false</draft> <kind>product</kind> <formerly>NSX</formerly> <editions> <item>vcf</item> </editions> <addon>false</addon> <sourceNote>Broadcom, VMware Cloud Foundation 9.1 and VMware vSphere Foundation 9.1: Feature Comparison &amp; Upgrade Paths, read 2026-08-28</sourceNote> <vendorName>VMware VCF Networking</vendorName> <status>current</status> <practice>Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented. </practice> <practiceReview>true</practiceReview> </spec> <sections> <section> <heading>

What it is

</heading>
<body>NSX virtualizes the network: switching, routing and firewalling run as software in thehypervisor rather than on dedicated hardware. The firewall sits at each VM's virtual portrather than at the edge of the network.That is the difference that matters. Traffic between two VMs on the same host is filteredwithout ever leaving the host. </body> </section> <section> <heading>

What it is for

</heading>
<body>Segmentation. The classic approach separates with VLANs and physical firewalls, and itscales exactly as long as the number of zones stays manageable. With a distributedfirewall, which zone a VM belongs to becomes a property of the VM rather than of where itsits in the rack.The second use case is automation: networks that come up with an application anddisappear with it. </body> </section> <section> <heading>

What to watch

</heading>
<body>NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up.Not because the technology is hard, but because nobody knows a rule set that grew over adecade in full. Segmentation needs an honest answer to which systems talk to each othertoday, and that answer is rarely written down. </body> </section> </sections> <status> <corpus>267</corpus> <services> <item> <ref>services/network</ref> <score>0.83</score> </item> <item> <ref>services/cloud</ref> <score>0.49</score> </item> <item> <ref>services/modern-workplace</ref> <score>0.43</score> </item> <item> <ref>services/security</ref> <score>0.42</score> </item> </services> <posts> <item> <ref>posts/distributed-network-security-services</ref> <score>0.83</score> </item> <item> <ref>posts/nsx-free-nsx-ebooks-to-download</ref> <score>0.83</score> </item> <item> <ref>posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter</ref> <score>0.73</score> </item> <item> <ref>posts/how-to-broadcom-download-token</ref> <score>0.73</score> </item> <item> <ref>posts/how-to-broadcom-support-portal-quick-links</ref> <score>0.73</score> </item> <item> <ref>posts/how-to-install-vcenter-without-dns</ref> <score>0.73</score> </item> </posts> <experts> <item> <ref>experts/marco-betschart</ref> <score>0.61</score> </item> <item> <ref>experts/rico-lenherr</ref> <score>0.61</score> </item> <item> <ref>experts/aldo-gwerder</ref> <score>0.55</score> </item> </experts> <neighbours> <item> <ref>solutions/vmware/vmware-cloud-foundation/addon/advanced-security</ref> <score>0.83</score> </item> <item> <ref>solutions/vmware/vmware-secure-access-service-edge</ref> <score>0.83</score> </item> <item> <ref>solutions/vmware/vmware-cloud-foundation/addon/advanced-cyber-compliance</ref> <score>0.73</score> </item> </neighbours> </status></manifest>
Solution · VMware

VCF Networking

formerly NSX

VCF

The vendor calls it: VMware VCF Networking

Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology.

VMware Pinnacle Partner

Topics Network 2.16 Security 2.16 Virtualization 1.37
Vendors VMware 0.88
04Services
06Posts
03Capabilities
267Corpus

What it is

NSX virtualizes the network: switching, routing and firewalling run as software in the hypervisor rather than on dedicated hardware. The firewall sits at each VM’s virtual port rather than at the edge of the network.

That is the difference that matters. Traffic between two VMs on the same host is filtered without ever leaving the host.

What it is for

Segmentation. The classic approach separates with VLANs and physical firewalls, and it scales exactly as long as the number of zones stays manageable. With a distributed firewall, which zone a VM belongs to becomes a property of the VM rather than of where it sits in the rack.

The second use case is automation: networks that come up with an application and disappear with it.

What to watch

NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up. Not because the technology is hard, but because nobody knows a rule set that grew over a decade in full. Segmentation needs an honest answer to which systems talk to each other today, and that answer is rarely written down.

What we do with it

Draft, unreviewed

Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented.

This paragraph is a draft and nobody at soulTec has confirmed it yet. Everything above it describes the product and is checkable against the vendor.

Posts about it

Who works with it

Do you work with this? Take a look at our open roles.