build 980262fe | content blog-content@c8490fa · 338 posts | profiles 20 · corpus 208 | 0 skipped |
Solution · VMware

NSX

The vendor calls it: VMware NSX vendorName: VMware NSX

Networking and firewalling in software, at the virtual port. The route to segmentation that does not depend on rack topology.

VMware Pinnacle Partner · soultec.ch/partner, verbatim

Topics capabilities · idf weight Network network 2.83 Security security 2.23 Virtualization virtualization 1.59
Vendors vendors · idf weight VMware vmware 0.91
04Services
06Posts
03Capabilities
208Corpus

What it is

NSX virtualizes the network: switching, routing and firewalling run as software in the hypervisor rather than on dedicated hardware. The firewall sits at each VM’s virtual port rather than at the edge of the network.

That is the difference that matters. Traffic between two VMs on the same host is filtered without ever leaving the host.

What it is for

Segmentation. The classic approach separates with VLANs and physical firewalls, and it scales exactly as long as the number of zones stays manageable. With a distributed firewall, which zone a VM belongs to becomes a property of the VM rather than of where it sits in the rack.

The second use case is automation: networks that come up with an application and disappear with it.

What to watch

NSX is part of VMware Cloud Foundation, and it is the component that holds migrations up. Not because the technology is hard, but because nobody knows a rule set that grew over a decade in full. Segmentation needs an honest answer to which systems talk to each other today, and that answer is rarely written down.

What we do with it

Draft, unreviewed practiceReview: true

Draft, not yet reviewed. Turning the distributed firewall on takes an afternoon. Writing a rule set someone can still understand in three years takes months. We start in monitor mode and only enforce once the flows are documented.

This paragraph is a draft and nobody at soulTec has confirmed it yet. Everything above it describes the product and is checkable against the vendor.

Posts about it

Distributed Network & Security Services

Virtualised networks have been running on hypervisor platforms in data centres for more than 20 years. What has changed is what they now have to cover: automation and security together.

2024-05-07 · posts/distributed-network-security-services.md · 822 words · 4 min · matthias-grasmueck

Network network 2.83 Security security 2.23

9 Free NSX eBooks to download

Last year I was fortunate enough to go to VMworld in Barcelona. One of the coolest “goodies” that I brought back was a small NSX book about automating NSX using PowerNSX.

2018-08-06 · posts/nsx-free-nsx-ebooks-to-download.md · 303 words · 2 min · dario-doerflinger

Network network 2.83 Security security 2.23

Install vCenter without DNS

A lot of people believe you cannot install vCenter without a DNS server in the environment. Not quite. It is not ideal, but it works.

2023-06-19 · posts/how-to-install-vcenter-without-dns.md · 314 words · 2 min · marco-mattei

Virtualization virtualization 1.59 Network network 2.83

Renew the STS Signing Root Certificate in vCenter

I recently had a call from a customer that received multiple alerts about their ESXi Hosts certificate was about to expire.

2025-05-23 · posts/how-to-renew-the-sts-signing-root-certificate-in-vcenter.md · 357 words · 2 min · dario-doerflinger

Virtualization virtualization 1.59 Security security 2.23

Broadcom Download Token

From now on your vCenter or SDDC Manager needs a unique token. Without it, from the end of April 2025, no patches for VMware software will download any more.

2025-04-14 · posts/how-to-broadcom-download-token.md · 176 words · 1 min · daniel-stadelmann

Virtualization virtualization 1.59 Security security 2.23

Broadcom Support Portal – Quick Links

A collection of links into the Broadcom Support Portal, so you get to the right product download or the right portal quickly.

2024-06-19 · posts/how-to-broadcom-support-portal-quick-links.md · 132 words · 1 min · yannick-gerber

Virtualization virtualization 1.59 Security security 2.23

Who works with it