NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

Introduction Every workload domain eventually needs to talk to the outside world, and in NSX that conversation happens at the edge. The NSX Edge cluster is where policy meets physical: it hosts the Tier-0 gateway that peers with your physical network, terminates VPN tunnels, and enforces the firewall rules that decide what’s allowed to cross the north-south boundary. Get the Edge cluster’s HA design wrong and you inherit asymmetric routing, dropped stateful sessions, or a firewall that silently fails open on a node switchover. This post breaks down the Tier-0/Tier-1 split, the HA modes that govern them, and how VPN and firewall services layer on top. ...

August 9, 2026 · Mohamed Rabiee
Physical Network Design: VDS Separation, ToR Switches, and BGP Uplinks

Physical Network Design: VDS Separation, ToR Switches, and BGP Uplinks

Introduction Every workload domain you’ll ever stand up in VCF inherits whatever the physical network underneath it can actually deliver. By the time you’re in the workload domain creation wizard picking a VDS profile, the rack layout, the ToR trunk configuration, and the MTU on every switch port in between have already decided how much of that wizard’s promise you can keep. This post works bottom-up: what the physical fabric needs to provide, how vSphere Distributed Switches carve that fabric into traffic types, and how NSX Edge nodes hand off to it over BGP. ...

July 24, 2026 · Mohamed Rabiee
VCF 9 NSX VPC Deep Dive: Cloud-Native Networking for Your Private Cloud

VCF 9 NSX VPC Deep Dive: Cloud-Native Networking for Your Private Cloud

Introduction One of the most impactful networking changes in VCF 9 is the introduction of Virtual Private Cloud (VPC) networking as the primary multi-tenancy model in NSX 9.0. VPCs replace the manual overlay segment and Tier-1 gateway model of previous VCF releases with a cloud-native, self-service networking abstraction that aligns with industry standards. In this post, we dive deep into the VCF 9 VPC architecture, Transit Gateway design patterns, and how application teams can consume VPC-based networking from vCenter, VCF Automation, and vSphere Supervisor. ...

July 8, 2026 · Mohamed Rabiee