DR & Ransomware Recovery: Isolated Recovery, Protection and Recovery, and VPC Isolation

DR & Ransomware Recovery: Isolated Recovery, Protection and Recovery, and VPC Isolation

Introduction Disaster recovery and ransomware recovery get planned in the same conversation more often than not, same team, same budget line, sometimes the same runbook with a different label on it. Broadcom’s own architecture disagrees with that framing. Operational DR assumes your primary environment is healthy but unreachable or impaired, the priority is RTO, automation, and minimal data loss. Cyber recovery assumes your primary environment is compromised, every action requires forensic isolation, immutability, and an air-gap mentality. Same team can run both. Structurally, they’re not the same discipline, and VCF 9.1’s tooling treats them as genuinely separate. ...

October 3, 2026 · Mohamed Rabiee
VCF 9 Security and Compliance: DFW, VPC Isolation, and Hardened Operations

VCF 9 Security and Compliance: DFW, VPC Isolation, and Hardened Operations

Introduction Security is a foundational concern in any private cloud deployment. VMware Cloud Foundation 9 delivers a layered security architecture that spans from the physical network underlay through the workload networking and compute layers, with VCF Operations providing centralized visibility into the security posture of all domains. In this post, we explore the VCF 9 security architecture, focusing on the Distributed Firewall design, VPC-level isolation, the Gateway Firewall default behavior change, and how VCF Operations handles security compliance monitoring. ...

August 23, 2026 · Mohamed Rabiee
NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

NSX Edge Cluster Deep Dive: Tier-0/Tier-1 Gateways, VPN, and North-South Firewall Design

Introduction Every workload domain eventually needs to talk to the outside world, and in NSX that conversation happens at the edge. The NSX Edge cluster is where policy meets physical: it hosts the Tier-0 gateway that peers with your physical network, terminates VPN tunnels, and enforces the firewall rules that decide what’s allowed to cross the north-south boundary. Get the Edge cluster’s HA design wrong and you inherit asymmetric routing, dropped stateful sessions, or a firewall that silently fails open on a node switchover. This post breaks down the Tier-0/Tier-1 split, the HA modes that govern them, and how VPN and firewall services layer on top. ...

August 9, 2026 · Mohamed Rabiee
VI Workload Domains: Shared vs Dedicated NSX

VI Workload Domains: Shared vs Dedicated NSX

Introduction Every VI workload domain you stand up in VCF asks the same networking question: does it join an existing NSX Manager, or get its own? The Networking page of the workload domain creation wizard boils this down to two buttons – “Join Existing NSX Manager Instance” and “Create New NSX Manager Instance” – but the operational consequences run much deeper than a single click. This is a per-domain decision, not a fleet-wide one, and a VCF instance scaling toward its 25-domain ceiling will likely end up with a mix of both. ...

August 2, 2026 · Mohamed Rabiee
Workload Domain Creation: Greenfield vs Import Existing vCenter

Workload Domain Creation: Greenfield vs Import Existing vCenter

Introduction Every VI workload domain in a VCF instance got there one of two ways: it was built from scratch through the workload domain wizard, or it was an existing vCenter environment that VCF Operations absorbed as-is. These aren’t just two UI paths to the same result – they carry different prerequisites, different day-one side effects, and different long-term upgrade constraints. Picking the wrong one for your situation doesn’t just cost time in the wizard; it can lock a workload domain out of upgrade paths for its entire lifecycle. ...

July 25, 2026 · Mohamed Rabiee
VCF 9 Management Domain Anatomy: What Actually Runs Inside

VCF 9 Management Domain Anatomy: What Actually Runs Inside

Introduction Every VCF Instance starts with a management domain – it’s the first workload domain deployed, and it never stops being special. This post breaks down exactly what components live inside a management domain per Broadcom’s official documentation, why the very first one in a fleet carries extra weight, and the shared-vs-dedicated NSX tradeoff that shows up in almost every design conversation. What Every VCF Domain Contains Per the VCF Taxonomy documentation, any VCF domain – management or workload – is built from the same base components: one vCenter instance, one or more vSphere clusters with vSphere HA and DRS enabled, at least one vSphere Distributed Switch per cluster plus NSX segments for workload traffic, a dedicated or shared NSX Manager instance, optional NSX Edge or Virtual Network Appliance clusters added after domain creation, and one or more shared storage allocations. ...

July 20, 2026 · Mohamed Rabiee
VCF 9 NSX VPC Deep Dive: Cloud-Native Networking for Your Private Cloud

VCF 9 NSX VPC Deep Dive: Cloud-Native Networking for Your Private Cloud

Introduction One of the most impactful networking changes in VCF 9 is the introduction of Virtual Private Cloud (VPC) networking as the primary multi-tenancy model in NSX 9.0. VPCs replace the manual overlay segment and Tier-1 gateway model of previous VCF releases with a cloud-native, self-service networking abstraction that aligns with industry standards. In this post, we dive deep into the VCF 9 VPC architecture, Transit Gateway design patterns, and how application teams can consume VPC-based networking from vCenter, VCF Automation, and vSphere Supervisor. ...

July 8, 2026 · Mohamed Rabiee
VCF 9 Workload Domain Planning and Deployment

VCF 9 Workload Domain Planning and Deployment

Introduction With the VCF 9 management domain up and running, the next step in your private cloud journey is creating workload domains. A workload domain groups ESX hosts under a dedicated vCenter instance, along with NSX networking and storage, so it can host tenant or departmental workloads. Depending on how you configure NSX connectivity during creation, a workload domain can become VPC-ready either immediately or after a short follow-up step: more on that below. ...

July 6, 2026 · Mohamed Rabiee