Why VCF Networking NSX Is Essential Even in a VXLAN World with VMware by Broadcom
Physical fabrics may provide VXLAN, but modern private clouds demand far more than basic overlay connectivity. This video explores how VCF Networking (NSX) decouples networking from the physical fabric, enabling automated, policy-driven network services that integrate natively with vCenter and VCF Automation. We also examine Virtual Private Clouds (VPCs), which empower developers to instantly provision secure, multi-tenant environments without deep networking expertise. Discover why VCF Networking is not simply an overlay but the foundational layer that unlocks agility, operational simplicity, and true cloud operating models inside the modern data center. Dimitri Desmidt shows why network virtualization within VMware Cloud Foundation (VCF) is essential, even if the underlying physical network already supports VXLAN. He highlights that while physical networks provide basic overlay connectivity, they fall short in delivering the comprehensive network services – such as switching, routing, load balancing, and firewalling – that modern applications require. Managing these services manually on physical infrastructure for each new application often entails a cumbersome, ticket-driven process spanning multiple teams and interfaces, delaying application deployment by weeks or even months.
VCF Networking, powered by NSX, addresses this by bringing these crucial network services directly into the cloud platform, enabling a self-service, automated consumption model. This shift eliminates the need for manual configuration and inter-team coordination, drastically reducing network provisioning time from weeks to mere seconds. A key innovation in VCF 9.0 is the introduction of Virtual Private Clouds (VPCs), which adopt the familiar industry-standard concept. A VPC is a self-contained “network bubble” that developers or vCenter administrators can instantly provision with subnets and automated IP address management. VCF is pre-configured with an IP block designated for future application networks, ensuring that newly provisioned subnets do not conflict with or overlap existing physical network infrastructure, thereby preventing IP conflicts and maintaining network stability.
VPCs offer granular control over network access, allowing for “public” subnets exposed to the external world, “private transit gateway” subnets for communication within a tenant, and “private VPC” subnets for isolation within a single VPC bubble. While VCF Networking handles basic access control and Network Address Translation (NAT), more advanced security needs, such as protocol-level firewalling, IDS/IPS, and malware inspection, are addressed by vDefense. The VPC gateway is fully distributed, running as a process within each ESX host, making the creation of new subnets completely transparent to the underlying physical fabric. This design means the physical network only sees encapsulated traffic between ESX host IPs, so no changes are required to the physical switches. This approach not only provides exceptional flexibility for dynamically connecting virtual machines but also allows for overlapping private IP address spaces across different VPCs, as all outbound traffic is automatically NAT’d, preventing conflicts. Additionally, VCF enables administrators to set quotas for network resources, ensuring fair usage and resource governance across various tenants or business units.
Presented by Dimitri Desmidt, NSX Senior Technical Product Manager, VCF Division, Broadcom. Recorded live at Cloud Field Day in Santa Clara on March 12th, 2026. Watch the entire presentation at https://techfieldday.com/appearance/vmware-by-broadcom-presents-at-cloud-field-day-25/ or visit https://techfieldday.com/event/cfd25/ or https://www.vmware.com/ for more information.
Transcript
I'm Dimitri. Uh, you can guess I'm French with the accent. And you can guess I'm a little bit older than 25.
And we'll talk about networking, and especially VPC in the networking capabilities of our private cloud VCF. So I don't know if all of you are more compute, storage, or network, but that's fine even if you don't have your network tattoo. Any cloud has compute needs, virtualization compute needs, storage needs, and network needs.
You need those three pillars. And my background is mainly on the networking, but because I've been working in cloud for a while, I have some knowledge also on compute and storage, and that's, that's cool and that's what everybody in the cloud administration management should have. Not expertise on everything, but at least some knowledge.
And, and yes, the three pillars again are compute, storage, and networking. On top of that, within VCF, you have your workloads, whatever they are, VMs, containers, private AI. And on top of that, you have advanced services, and if we stick to networking, load balancing, network observability, but other things like, database that was presented just before me.
But anyway, enough about VCF and let's talk about networking. Uh, for many years, less and less, but for many years, people ask why do I need in my VCF network virtualization offered by VCF? Because I have already my network.
My network is the Cisco I love, the Arista I love, whatever, and I love them all, so congratulations, you made the good choice. Whatever it is, it's a good choice. Uh, and that network offers also overlay VXLAN.
I'm sure you, or I guess you have heard about this, which is the ability to create virtual networks on your physical infrastructure overlay. Uh, so why adding another network virtualization within VCF when, when my physical fabric can do it? And before talking about VPC, I'll talk about that quickly.
So when you have an application compute... No, an application, VMs, containers, I mean, at the end of the day, you need to plug that somewhere so people can access your application, and that application needs switching, routing, maybe load balancing, maybe security with some, some firewalling, maybe a VPN access to some remote data center. So you need a lot of services, especially network services.
And if you do that in the fabric, so your cloud does not offer network services built in, what do you do? Then you go on your physical fabric. When you have your new application, let's say this beautiful two-tier app, web tier, app tier, you go to your physical fabric, Cisco, Arista, whatever, and you create your network for those two networks for this new application, and because you have overlay, you'll most likely not do VLAN, but you'll do VXLAN on your physical fabric.
That's great. Uh, but then you'll go on vCenter and do click, click on vCenter to create your port group VLAN that are mapped to those VXLAN VNI. So you click, clicked on Cisco, Arista, whatever.
You click, clicked on vCenter, and then yeah, great, you can plug your applications into the network. But you need a default gateway, so you do some click, click more on your physical fabric you like. Then you may need some load balancing, so you do click, click on the F5, on the whatever load balancer you have, or maybe VMware AV.
But anyway, on the vendor you like, and maybe some firewalling and so on and so forth. So you've done a bunch of click, click, click. If you're not the only one managing your cloud, most likely you open tickets to do that, involving the different teams managing the load balancer, managing the security, managing the, the physical fabric, and so on and so forth.
And, I mean, alboquick. So when you do it within your cloud, then you don't need to open ticket. All those services are available to you, and that's what VCF with the private cloud, offers.
And now you're autonomous to configure all the things you need, compute, storage, network included, consuming those services from the platform for the cloud you have. Like on AWS, you don't open a ticket when you want to deploy an application. On VCF, it's not the same.
Your developer doesn't open a ticket to deploy his application, compute, storage, network. And that's what makes the, the usage of network virtualization in a cloud, a, a real cloud, where before, okay, it's weeks, it could be, it's just a number, it could be weeks, it could be months, depending on how... Or days, depending on how fast you write people to process your tickets, or it can be seconds if you click, click super fast in VCF or use some orchestration, VCF orchestration to deploy your whole application.
Okay. That's it. So I hope that's clear why network virtualization is key and one of the three pillars of any cloud, VCF included.
Sounds good? Okay. 0.
So network virtualization within VCF has been there for, for years and years and years. But we have this new model, which is pretty cool. Uh, so what is it?
It's a network bubble, if you ask me. It's a network bubble where you will plug your applications in it and... Oh, VPC, by the way, if you know AWS, it's, it's exactly this.
Private... Virtual private cloud. So for once, VMware, we did not invent a new word.
We use, the industry standard. I don't know if AWS is an industry standard, but, uh... Am, am I recording?
Shoot. Anyway. Um, so we use VPC for virtual private cloud, and it's a network bubble, and you can create that network bubble fro- within...
from, VCF, from different components of VCF. If you're a vCenter admin, beautiful. You can create network directly from the vCenter UI you have been using for years and years and years and you love.
Or if you want to use something else like VCF automation, or if you want to use NSX. Anyway, from diff- from, from different VCF components, you can create those network bubbles, or you can also do API automation, Python, Terraform, whatever you love, and you create those network bubbles with the subnets. Something pretty cool is when you...
0 with the VPC concept, and that's what I really enjoy, is if you're the vCenter admin and you want to be autonomous so you don't open tickets to ask for a new VLAN, a new subnet, a new default gateway, a new NAT, a new load balancer. When you're the vCenter admin, you don't know what subnet is available to you. If I give you the ability to create a new subnet for your application, you don't know whether network team is using or can make available to you for this new application.
And so within VPC... Uh, I mean, within VCF, sorry. Within VCF, so the VMware, private cloud, you ha- when you deploy VCF, there is one question which is, "Okay, give me your, physical servers where I will install ESX.
" And so when you deployed VCF, you had to talk to the network guy, so at some point, to ask them, "Hey, you're using so many IP blocks, so many subnets in your own physical infrastructure. Give me one for VC... I mean, actually, give me one for VCF, for vSAN.
Give me one for V- vCenter, vSAN, for vCenter, vMotion. " Okay? So that's done at the VCF installation.
And then you have this concept of, of external IP blocks. And when somebody, the vCenter admin, the VCFA admin or tenant, or the NSX admin, because you can create those network bubbles from the different VCF components, you don't say what subnet, you just take one of those blocks. A, a slice of one of those blocks.
Okay, enough of that. Uh, and then, okay, you created your network bubbles. Here I have two VPC subnets in my VPC bubble.
And technically, how it works, the, those workloads, VM containers, here I'm showing VMs, they are plugged to those VPC subnets, and they are physically a little bit on ESX1, a little bit on ESX2, but those networks and VPC bubbles are everywhere. And they have a default gateway. It's a VPC gateway.
It's fully distributed. I'm showing it only on ESX1, but it's actually everywhere, on ESX1, ESX2, ESX3. And so when web one wants to talk to app one on two different subnets, it goes to its default gateway, which is always within its own ESX.
And then that... It's not a VM, this VPC router. It's a process running inside ESX, but it's not a VM.
And so, yeah, the router, distributed router VPC of that VPC blue, takes the traffic and route to app one VM, and will send it to app one VM. And here it's the same technology we used for fifteen years within NSX, which is the component of VCF for network virtualization. We encapsulate.
So the ESX one will encapsulate that traffic. VM one, ten ten ten ten talking to app one, eleven eleven eleven eleven. It will be encapsulated by ESX one and sent to ESX two.
So the physical fabric, what does it see? It sees the IP of ESX one talking to the IP of ESX two. And so any new VPC subnets you create, it's completely transparent to the physical fabric.
You don't need to touch the physical fabric 'cause the traffic is encapsulated. Mm-hmm. And that physical fabric is using VLAN, it's using VXLAN.
Don't care. The only requirement is ESX one IP needs to be able to talk to ESX two IP. Nothing to do with web and, and app VMs.
Okay. So summary. Um, virtual private clouds are the core building block for publi- for private cloud experience.
So a true cloud experience, yes, you need compute virtualization, you need, storage virtualization, and you need network virtualization, as I talked about before. And VPC, yeah, it relies behind at the end. It's running on NSX.
Even if you create your VPC bubbles and you network things from vCenter, VCFA, whatever, or NSX, at the end, it's implemented in NSX. 0. That's great.
Now, if you have been using VP- VCF for a long time, and vCenter NSX for a long time- Mm ... and you use... I don't know if you're familiar with NSX, logical routers tier zero, logical routers tier one.
0. You don't need to trash and redo. Tier zero, tier one segment.
Any new application in nine dot oh deployed with this old, I mean, old, let's call it, what... how do you say in English? Um- Legacy.
Legacy. Thank you. Legacy way, tier zero, tier one segment, nine dot one, it will still work.
But you need to do click, click NSX or API NSX. Or for the new applications, you can use this new model, and now you can give the, your different users, personas, the vCenter admin, the VCF tenant, Pepsi, Coke, finance, marketing, this way so it's autonomous. Okay, a few words, and then I have a live demo, that will clarify all of that, hopefully.
Uh, just a few words on, on VPC. It does a lot of things, but there is one thing that is important to, to, to grasp. So you create your different VPC bubbles, the VC, the vCenter admin or whoever.
Create those VPC bubbles with networks inside. Now, how do s- networks communicate between those bubbles? And you can decide, and we'll, we'll talk about that in the next, on the next slide.
You can decide how a VPC bubble talks to another VPC bubble or the outside world will reach my VPC bubble or stuff in that VPC bubble. Uh, now, if you want more granularity than that, then we have vDefend, which is our firewalling, or security add-on, where it's not about who can access yes or no my VPC bubble or subnet in my VPC bubble. " I mean, you go protocol level or even deeper than that, IDS, IPS, malware inspection.
That's vDefend. What I'll talk about here is only networking, so who can access it or not access it. Now, if you can access it, you can do whatever you want.
SSH, HTTP, Telnet. If you want to protect more, it's vDefend. So for the access.
So you have multiple bubbles, VPC bubbles, with networks inside. I'm showing tenant one, tenant two with a bunch of bubbles in it. Uh, tenant one, tenant two can be Pepsi and Coke, can be finance, marketing, whatever.
You have the ability to group applications or, or business units or customers within a, a tenant. And so if you want everybody, everybody, everybody to talk to you, then you create a VPC subnet public. Now, if you want, only the VP...
the, the workloads, the applications in your tenant, Pepsi or finance, to talk to that, to those workloads plugged on that subnet, you make it private transit gateway. So anybody within that tenant will be able to talk to it, not other tenants, not the outside world. And if you want only the s- the com- the compute, the workload in that bubble to talk to VMs on that subnet private, then you make it private, VPC private, and nobody else will be able to talk to it.
Okay? Can you change those? Are they dynamic to be changed along the way, or once you define that that's- No.
But, but you, you decide where you plug your workload. So you can create a public, a private, and you decide to plug that VM here. Yes.
And six months later, "Oh, shoot, actually, I'd like everybody to talk to it," you can plug it here. Or, or the, that VM is in a private subnet, so nobody can talk to it. Like, AWS, you know you can create an external IP.
Mm-hmm. So you can create an external IP. And now this VM still has a private IP that nobody can talk to outside of the VPC bubble.
But people can reach that VM through its NAT IP, external IP address. Yes. Okay.
Both are, are possible. Okay. So that's it, for the slides.
Now I have a lab, so let's see this in action. Okay. Still showing.
Okay. So it's, my nine dot o lab. Uh, you can see...
I mean, it's, I'm on, I'm on my vCenter, part of this beautiful VCF. I mean, I c- I can log in. Part of this beautiful VCF.
And I have a bunch of applications. Beautiful. And under networking, so the same UI you've been using for years and years and years, there is something new in nine dot o, which is VPC.
And here you can see I already have a VPC finance created with a public subnet, which is 30... whatever, which is whatever, with its default gateway, with its, with its DHCP server, because I wanted a DHCP server. I have a private subnet with whatever.
How did I create that? Very simply. I mean, if I want to create a new subnet, I can just do new subnet.
And I'm the vCenter admin. I'm not the network guy at all. And I say, "Hey, I want it public," and, I don't know, public two, because I want a new DMZ for my new application, or I can call it DMZ, whatever.
I don't know what subnet I could use. I don't know what is available, within my company to be advertised to the real world. Do I want DHCP?
Yeah, I'm lazy, or no, or I use DHCP relay because I want to use my info blocks to, to manage, to manage, the IPAM. Okay. That's it.
Next, next, next. Here we go. And I don't have a tattoo.
I don't really under- a network tattoo. I don't really understand how DHCP works and, and how I should configure it. I just do click DHCP and that's it.
And here we go. I have this new public tool. It's live.
Um, but so this new beautiful subnet, where does that come from? I'm, I'm the vCenter admin, so I'm not the big boss of networking, but if I want to, I could have guessed because we have this new thing also here under vCenter, Network Connectivity, and the big block is this guy. So any future IP subnet...
Uh, VPC subnet, sorry, VPC subnet public I will create, it will come from this big giant block, the... Or giant, whatever the, the, the network team gave to the VCF, to the guy who deployed VCF. So where my mind first goes to, is this helping to basically help, like, prevent, CIDR overlaps?
Yeah, exactly. So if, somebody used for its own VPC, this CIDR, this subnet, this CIDR, and somebody else from vCenter, click, click, click. From NSX, click, click, click.
From VC- VCF automation, click, click, click. Create... I'm showing VCF automation.
I wanted to do it later, but whatever. Uh, on VCF automation, I'm the tenant, Pepsi, whatever. Mm-hmm.
And I want to create a new subnet. Same thing. And I had no clue.
I mean, I'm the... I'm Pepsi. I don't know what the cloud admin has for public network.
I just say, "Hey, I want it public, with so many IPs," and boom, it will take... Or I can do it. Let's g- Yeah, okay.
Who cares about the name? That's a beautiful name. And, it will not take, it will not take, something that is already taken.
Mm-hmm. Okay? Uh, why, where is the refresh?
Like, regardless of which, like, DHCP option you pick, like, it's still going to make it- Yeah, here we go ... to overlap. Here we go.
Um, yeah. So you cannot make mistake. So that's great for the network admin.
He's not scared somebody will pick something that, oh, shoot, it's the, the subnet I use for my common services where I have my DNS server, IP, IP conflict. Ni- no mess can happen. And then if for whatever reason it started to...
I mean, I digress a lot. This is too small because at the beginning they told me, I mean the network guy gave me a small subnet, and, and VP- VCF is becoming more and more popular. People started to deploy stuff.
Um, you can add... I mean, not me, 'cause I'm the vCenter guy. Um, I'm in charge of more compute and storage, but not network.
I consume it, and I create my own network now, but I'm not allowed to... Yeah, the, the big network guy can add more blocks for future VPCs, subnets. Cool.
Uh, okay. And yeah, I created a subnet, but I can create a VPC. It's as easy as click.
Okay. And I create my VPC marketing, whatever. So I can do click, click, all day long or because, you know, I'm, I'm a, I'm a vCenter admin, so I love PowerCLI, and I made a, a...
Where did I put that? I made a beautiful, a beautiful PowerCLI script. Oops.
And of course, it's too small, you cannot read, but, I'm telling you it's beautiful. And, um- So I, the, I connect to... Sorry.
It's, it's not recorded, correct? Yeah. The...
I'm, I have my vCenter. I c- I connect to my vCenter. I create, a VPC I call VPC Marketing.
I create two subnets. I don't say what IP addresses. I just take it from the block.
I want two subnet, a public, a private, and I want to plug my beautiful VMs on it. Anyway. And here we go.
It's called VPC Marketing, and I con- I mean, it's an overloaded lab, so it takes a few mi- it's live. Yeah, it takes few seconds to connect. It...
Oh, shoot. And let's go quick here. Yeah.
Here we go. My VPC Marketing is here. Uh, ah, here we go.
Uh, two subnets, only one is displayed in... Here we go. Two are displayed in the...
And I plug my VM. I mean, it's not rocket science. And we had the question on external IP.
Actually, in this beautiful script, I also create an external IP, and I'll finish with... Oh, no, I have five minutes? Oh, plenty of time.
Um, you have also this beautiful thing I, I love. Uh, again, I don't know much networking. I'm a vCenter guy, a- and doesn't...
I mean, this doesn't speak to me, but I love pictures. I love diagrams. And here for the VPC Marketing, I can see that my VPC Marketing has this beautiful logical router, VPC router, this beautiful, web subnet, this beautiful, private subnet.
Um, it's maybe not powered on. Oh, it's running. I don't know if it's right off.
Yeah, it's already ready. Uh, yeah, no, it's not already up and running. But the date will be up and running, the VM- the, the VM, because I just powered it on.
It will have an IP address via DHCP private, so nobody can access to it. But if they want to access to it, I created, this, external IP for it. Okay?
If I refresh... Oh, here we go. Here we go.
And, and, yeah, that's it. I mean, then you can even see should have the same IP address. Here we go.
I access my, my web... My marketing I just powered on in front of you. Where is it?
Here. Here. Here.
The IP address 67. The IP address 67. And I can talk to my...
I mean, the web tier can talk to the DB tier, which is private. But of course, me, myself, from my external client, um... Yeah, let's go.
Sorry. Let's go to a new one. Ping.
Of course, from the outside world, I cannot talk to it because it's private. But if I go to... Sorry, it's this guy.
You follow me or I go too fast? Good. I can ask another question, though.
Sure. What about, um... So let's say I'm the network person.
Can I create a CIDR overlap? Uh, no. Even if you want to, you cannot.
Uh, hold your... Because I'm a network guy, I love to do ping. It's not- It's not super sexy, but I had to.
Uh, anyway, so now you can see I can ping my database, behind through its external IP. Mm-hmm. Uh, okay, can I do overlapping?
If I create, a new subnet and I make it public, it will never overlap with another public subnet. However, let's do that. You're, you're saying the external IP- Right ...
address range that, that it gets assigned- Yeah ... will never overlap. No, I cannot.
But the internal address space it uses- That's where- ... that can overlap ... I'm using...
Yeah, that's what... So when I created a VPC here- Mm-hmm ... you can see here, if I want to, there is no red, star, so it's optional.
If I want to, I can manually enter a private s- it's not a subnet, it's a block, a private block. Okay. And that private block will be used for future VPC subnets private.
Mm-hmm. Mm-hmm. And that block, for this VPC 3, can overlap.
Oh, let's overlap. Let's see this VPC Finance, what I used. I forgot.
VPC Finance. So you can see it's live. Here we go.
This guy- Mm-hmm ... it's for any future private subnet on that specific VPC, and I'll do VPC 3. And the network admin is not involved for that subnet because who cares?
Nobody from the outs- this subnet will never go to the real world. Mm-hmm. Uh, so I can do that.
And now I have overlapping if I create a VPC subnet private, but who cares? Because it's private to my bubble. Mm-hmm.
Mm-hmm. Does that make sense? Yeah.
Yeah. Are you able to set up any kind of alerts when that happens? No.
And you don't... Why an alert? Alert means bad.
There is no IP overlapping, it's just it happens to be that two network bubbles have private subnets that have the same IP and, and so what? Because they'll never talk to the out- outside of the bubble with that IP. Unless you're connecting them.
Yeah. No, no, no. If I connect them, what?
To the bubble? If you, if you want to do transit between the two- Yeah ... VPCs.
That's NATed. Okay. It's NATed.
The... If we go back to this beautiful thing. Here we go.
Oops. Here. When the VM here wants to initiate traffic to the outside world, it will be NATed.
Mm-hmm. And so the out... When I exit that bubble to go here or to go to the physical world or to go here, what IP address do you see when you exit the bubble?
Up the logical router VPC. You don't see this IP. You see the NATed IP- Correct ...
which is public. Yeah. And so there is no conflict, never.
It's not possible. Hey, hey, can I jump in with a quick question? Sure.
If you guys can hear me. Yeah. Yeah.
So, you know, there are other cloud providers where, you know, you pay, like, quite a lot. It's caught me on my cloud bill- Yeah ... for that NATing.
Yeah. Uh, so would you... I love this.
I just gotta say, it brings, a smile to my face. So you pay... I mean, so, I mean, VCF is not free as far as I...
I'm not on the sales side, but I, I don't think it's free. But, once you pay for VCF- Understatement ... then you can use that feature.
It's included. The, the NAT, the NAT thing or the, the, the private, or the, the, the number of public subnets, you, you, you allow the vCenter guy click, click, click, or the VCFa- the VCFA guy click, click, click. And then you, you're the VCF big admin, you own it, you gave us money to, to use it.
You can charge your customer, if your customers are Pepsi and Coke, or if your customers are finance, marketing within your company, you can charge them by utilization. And I'll finish with this because I'm late now. Um, in VCFA, not in vCenter, but in VCFA, you can associate...
I'll, I won't show it because I'm, I'm... Yeah, I'm late. Okay, I cannot show it.
You'll, you'll trust me. In VCFA, you can decide, you can give quota. You're the big VCFA provider, the big VCFA admin, and you create an org for Pepsi, an org for Coke or finance, and you give quota.
You can give quota in term of CPU, memory. Don't care much, I'm the network guy. But also quota on network.
You say Pepsi cannot use more than so many public IP addresses, so it won't take all the IP addresses from f- from Coke and from the other guy. Make sense? So you have the ability to do quota.
And if you want to charge Pepsi and Coke on the number of IP addresses they use, feel free.