SlideShare a Scribd company logo
1 of 13
Download to read offline
The VMware NSX Network
Virtualization Platform
VMware Solutions: Designed for Early and Ongoing Success
T E C H N I C A L W H I T E P A P E R
The VMware NSX Network
Virtualization Platform
T E C H N I C A L W H I T E P A P E R / 2
Table of Contents
Executive Summary.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
Networking is Stuck in the Past.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
The Glass is only Half Full. .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
Network provisioning is slow.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 3
Workload placement and mobility is limited.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
It’s Time to Virtualize the Network.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 4
Introducting VMware NSX –The Platform for Network Virtualization.  .  .  .  .  .  .  .  .  .  .  .  .  .  . 5
How VMware NSX Works.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 6
Compelling Technical Features and Characteristics.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 8
NSX fits right in.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 8
NSX network virtualization is not an all-or-nothing proposition.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
NSX simplifies networking .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
NSX provides essential isolation, security, and network segmentation .  .  .  .  .  .  .  .  .  .  .  .  . 9
NSX delivers proven performance and scale.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
NSX enables unparalleled visibility.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 9
NSX is extremely flexible, highly extensible, and widely supported .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
A Proven Solution with Many Powerful Use Cases.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
Data Center Automation.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
Data Center Simplification .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
Data Center Enhancement.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
Multi-tenant Clouds. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
Compelling Capabilities and Business Value. .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
NSX accelerates network provisioning and streamlines operations. .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 10
NSX provides flexible, highly adaptable networking.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 11
NSX enables unrestricted workload mobility and placement.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 11
NSX dramatically enhances network security.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 11
NSX enables push-button, zero-compromise disaster recovery .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 11
NSX reduces network TCO.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 12
Unleashing the Software defined Data Center.  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  .  . 12
T E C H N I C A L W H I T E P A P E R / 3
The VMware NSX Network
Virtualization Platform
Executive Summary
VMware’s Software Defined Data Center (SDDC) vision leverages core data center virtualization technologies to
transform data center economics and business agility through automation and non-disruptive deployment that
embraces and extends existing compute, network and storage infrastructure investments. Enterprise data centers
are already realizing the tremendous benefits of server and storage virtualization solutions to consolidate and
repurpose infrastructure resources, reduce operational complexity and dynamically align and scale their application
infrastructure in response to business priorities. However, the data center network has not kept pace and remains
rigid, complex, proprietary and closed to innovation – a barrier to realizing the full potential of the virtualization and
the SDDCs.
The VMware NSX network virtualization platform provides the critical third pillar of VMware’s Software Defined
Data Center (SDDC) architecture. NSX network virtualization delivers for networking what VMware has already
delivered for compute and storage. In much the same way that server virtualization allows operators to
programmatically create, snapshot, delete and restore software-based virtual machines (VMs) on demand, NSX
enables virtual networks to be created, saved and deleted and restored on demand without requiring any
reconfiguration of the physical network. The result fundamentally transforms the data center network
operational model, reduces network provisioning time from days or weeks to minutes and dramatically simplifies
network operations.
NSX is a non-disruptive solution that is deployed on any IP network, including existing data center network
designs or next generation fabric architectures from any networking vendor. With NSX, you already have the
physical network infrastructure you need to deliver a software defined data center.
Networking is Stuck in the Past
Traditional approaches to networking not only prevent today’s organizations from realizing the full promise of
the software defined data center, but also subject them to limited flexibility and operational challenges.
The Glass is only Half Full
Server and storage virtualization solutions have dramatically transformed the data center by delivering
significant operational savings through automation, capital savings through consolidation and hardware
independence, and greater agility through on-demand and self-service approaches to provisioning. As
significant as these gains have been, however, much of the potential for these solutions remains untapped. More
to the point, these businesses are being held back, by an antiquated network operationaL.
Networking and network services have been stuck in the status quo and are out-of-step with server and storage
solutions that can be quickly provisioned but are constrained by networking services that still require manual
provisioning and are anchored to vendor specific hardware and topology. This directly impacts application
deployment time because applications need both compute and networking resources.
Network provisioning is slow. The current operational model has resulted in slow, manual, error-prone
provisioning of network services to support application deployment.. Network operators are dependent on
terminal, keyboard, scripting and CLIs to manipulate a multitude of VLANs, firewall rules, load balancers and
ACL, QoS, VRF and MAC/IP tables. Complexity and risk are further compounded by the need to ensure that
changes to the network for one application do not adversely impact other applications . Given the complexity of
this situation, it’s no surprise that several recent studies point to manual configuration errors as the cause for
T E C H N I C A L W H I T E P A P E R / 4
The VMware NSX Network
Virtualization Platform
more than 60% of network downtime and/or security breaches. The result is that in addition to the frequent,
inevitable configuration mis-steps, IT response time to new business requirements is too slow, as rapidly
re-purposed compute and storage infrastructure must still wait for the network to catch up.
Workload placement and mobility is limited. The current device-centric approach to networking confines
workload mobility to individual physical subnets and availability zones. In order to reach available compute
resources in the data center, network operators are forced to perform manual box-by-box configuration of
VLANs, ACLs, firewall rules, and so forth. This process is not only slow and complex, but also one that will
eventually reach configuration limits (e.g., 4096 for total VLANs). Organizations often resort to expensive over-
provisioning of server capacity for each application/networking pod, resulting in stranded resources and sub-
optimal resource utilization.
Additional Data Center Networking Challenges
Related challenges data center networking teams face with traditional networking approaches include:
•	VLAN sprawl caused by constantly having to overcome IP addressing and physical topology limitations
required to logically group sets of resources
•	Firewall rule sprawl resulting from centralized firewalls deployed in increasingly dynamic environments coupled
with the common practice of adding new rules but rarely removing any for fear of disrupting service
availability;
•	Performance choke points and increased network capacity costs due to the need for hair-pinning and multiple
hops to route traffic through essential network services that are not pervasively available. The increase of East-
West traffic in a data center exacerbates this problem
•	Security and network service blind spots that result in  choosing to avoid hair-pinning and other deploy risky
routing schemes
•	Increased complexity in supporting the dynamic nature of today’s cloud data center environments.
It’s Time to Virtualize the Network
The solution to these challenges is to virtualize the network. Do for networking the same thing that has been
done for compute and storage. In fact, network virtualization is conceptually very similar to server virtualization
(see Figure 1).
With server virtualization, a software abstraction layer (server hypervisor) reproduces the familiar attributes of
an x86 physical server (e.g., CPU, RAM, Disk, NIC) in software, allowing them to be programmatically assembled
in any arbitrary combination to produce a unique virtual machine (VM) in a matter of seconds.
With network virtualization, the functional equivalent of a “network hypervisor” reproduces the complete set of
Layer 2 to Layer 7 networking services (e.g., switching, routing, access control, firewalling, QoS, and load
balancing) in software. As a result, they too can be programmatically assembled in any arbitrary combination,
this time to produce a unique virtual network in a matter of seconds.
Not surprisingly, similar benefits are also derived. For example, just as VMs are independent of the underlying
x86 platform and allow IT to treat physical hosts as a pool of compute capacity, virtual networks are
independent of the underlying IP network hardware and allow IT to treat the physical network as a pool of
transport capacity that can be consumed and repurposed on demand.
T E C H N I C A L W H I T E P A P E R / 5
The VMware NSX Network
Virtualization Platform
More importantly, network virtualization provides a strong foundation for resolving the networking challenges
keeping today’s organizations from realizing the full potential of the software defined data center (see text box
“Why the Software defined Data Center Makes More Sense”)
Introducing VMware NSX – The Platform for Network Virtualization
VMware NSX is the market leading implementation of network virtualization from VMware. By delivering a
completely new operational model for networking that breaks through current physical network barriers, NSX
enables data center operators to achieve orders of magnitude better agility, economics, and choice.
Figure 1: How Network Virtualization Parallels Server Virtualization.
Why the Software defined Data Center Makes More Sense
The software defined data center (SDDC) approach to building next generation data centers has several
compelling advantages over emerging hardware defined data center (HDDC) alternatives. First and foremost,
SDDC is proven. Indeed, building advanced, software-based intelligence into their applications and platforms
is what has enabled Google and Amazon to deliver the largest, most agile and efficient data centers in the
world today. Another major advantage of SDDC is that innovation occurs at the speed of software releases,
instead of being tied to ASIC and hardware-upgrade cycles of three to five years, or more. Moreover,
adopting new innovations no longer requires forklift hardware upgrades. Best of all, a software defined data
center works with the physical infrastructure you already have and can be deployed non-disruptively
alongside your existing configurations at whatever pace your organization chooses.
T E C H N I C A L W H I T E P A P E R / 6
The VMware NSX Network
Virtualization Platform
With NSX, virtual networks are programmatically created, provisioned and managed, utilizing the underlying
physical network as a simple packet forwarding backplane. Network and security services in software are
distributed to hypervisors and “attached” to individual VMs in accordance with networking and security policies
defined for each connected application. When a VM is moved to another host, its networking and security
services move with it. And when new VMs are created to scale an application, the necessary policies are
dynamically applied to those VMs as well.
NSX is completely non-disruptive solution:,
•	Deploys on hypervisors connected to any existing physical network infrastructure and supports next-
generation fabrics and topologies from any vendor;
•	Requires no changes to existing applications and workloads
•	Allows IT departments to incrementally implement virtual networks at whatever pace they choose (without
any impact to existing applications and network configurations)
•	Extends visibility to existing networking monitoring and management tools to deliver increased visibility into
virtualized networks
The net result is a transformative approach to data center networking that – among its many other benefits –
matches the velocity demands of today’s businesses by reducing service delivery times from weeks to seconds.
How VMware NSX Works
Figure 2: The “Network Hypervisor”
Figure 2: NSX is a multi-hypervisor
solution that leverages the vSwitches
already present in server hypervisors
across the data center. NSX coordinates
these vSwitches and the network services
pushed to them for connected VMs to
effectively deliver a platform – or “network
hypervisor” – for the creation of virtual
networks.
Similar to how a virtual machine is a
software container that presents logical
compute services to an application, a
virtual network is a software container that
presents logical network services – logical
switches, logical routers, logical firewalls,
logical load balancers, logical VPNs and
more – to connected workloads. These
network and security services are
delivered in software and require only IP
packet forwarding from the underlying
physical network.
The following diagrams reveal the
fundamentals of how NSX works. They
also set the stage for further exploring the
technical characteristics, capabilities, and
value propositions that define the NSX
solution.
Figure 2: The “Network Hypervisor”
T E C H N I C A L W H I T E P A P E R / 7
The VMware NSX Network
Virtualization Platform
Figure 3: Virtual Network Provisioning
Figure 4: The Virtual Network – From the Workload’s
Perspective (i.e., Logical)
Figure 5: The Virtual Network – From the Network’s
Perspective (i.e., Physical)
Figure 3: Virtual networks are
provisioned by taking advantage of a cloud
management platform (CMP) which uses
the RESTful API exposed by the NSX
Controller to request the virtual network
and security services be instantiated for
the corresponding workloads (step 1). The
Controller then distributes the necessary
services to the corresponding vSwitches
and logically attaches them to the
corresponding workloads (step 2).
This approach not only allows different
virtual networks to be associated with
different workloads on the same
hypervisor, but also enables the creation of
everything from basic virtual networks
involving as few as two nodes, to very
advanced constructs that match the
complex, multi-segment network
topologies used to deliver multi-tier
applications.
Figure 4: To connected workloads, a
virtual network looks and operates like a
traditional physical network. Workloads
“see” the same Layer 2, Layer 3, and Layer
4-7 network services that they would in a
traditional physical configuration. It’s just
that these network services are now
logical instances of distributed software
modules running in the hypervisor on the
local host and applied at the vSwitch
virtual interface. applications.
Figure 5: To connected workloads, a
virtual network looks and operates like a
traditional physical network. Workloads
“see” the same Layer 2, Layer 3, and Layer
4-7 network services that they would in a
traditional physical configuration. It’s just
that these network services are now
logical instances of distributed software
modules running in the hypervisor on the
local host and applied at the vSwitch
virtual interface. applications.
T E C H N I C A L W H I T E P A P E R / 8
The VMware NSX Network
Virtualization Platform
Compelling Technical Features and Characteristics
Several key features and characteristics are instrumental to the value NSX delivers, both to IT and the business
at-large. These include the ability to work with your existing network infrastructure, support progressive
adoption of network virtualization, and substantially reduce network complexity.
NSX fits right in. Simply put, NSX works with:
•	Any application. Workloads/applications need not be modified in anyway as the virtual network appears no
different to them than the physical network.
•	Any hypervisor. Out-of-the box support is available for many hypervisors (e.g., Xen, KVM, and VMware ESXi),
while coverage can be extended to others (e.g., Microsoft Hyper-V) by re-configuring them to incorporate
standard vSwitch capabilities.
•	Any network infrastructure. Hardware independence is achieved based on the fact that NSX virtual networks
require nothing more than connectivity and packet-forwarding from the underlying IP infrastructure.
•	Any cloud management platform. Out-of-the-box support is available for many cloud management platforms
(including CloudStack, OpenStack, VMware vCloud Automation Center,), and integration with other
management platforms is provided through the NSX API.
Figure 6a: Distributed Routing with NSX Figure 6b: Distributed Firewall with NSX
Figures 6a and 6b: The ability to apply/enforce security services at the vSwitch virtual
interface also eliminates “hair-pinning” – an unfortunate “feature” of traditional physical network
architectures where East-West communications traffic – for example, between two VMs on the
same hypervisor but in different subnets – is required to traverse the network to reach essential
services, such as routing and firewalling. With NSX, inefficient traffic patterns such as these,
which often lead to core link over-subscription, become a thing of the past.
T E C H N I C A L W H I T E P A P E R / 9
The VMware NSX Network
Virtualization Platform
NSX network virtualization is not an all-or-nothing proposition. Because NSX virtual networks require no
configuration changes to the underlying physical network (outside of allowing NSX encapsulated packets
through existing firewalls) they transparently co-exist with existing application deployments on the physical
network today. IT departments have the flexibility to virtualize portions of the network by simply adding
hypervisor nodes to the NSX platform. In addition, Gateways – available as software from VMware or top-of-rack
switch hardware from several NSX partners – deliver the ability to seamlessly inter-connect virtual and physical
networks. These can be used, for example, to support Internet access by workloads connected to virtual
networks, or to directly connect legacy VLANs and bare metal workloads to virtual networks.
NSX simplifies networking. NSX abstracts virtual networks from the underlying physical network enabling
increased automation. Operators are not required to interact with the physical network and are therefore spared
the inconsistencies across platforms. Operators no longer need to deal with VLANs, ACLs, spanning trees,
complex sets of firewall rules, and convoluted hair-pinning traffic patterns – because these are no longer
necessary when the network is virtualized. NSX network virtualization is not an all or nothing proposition. As
organizations incementally employ NSX virtual networks, they can increasingly streamline their physical network
configuration and design. Vendor lock-in becomes a thing of the past, since the physical network only needs to
deliver reliable high-speed packet-forwarding, it’s then possible to mix and match hardware from different
product lines and vendors.
NSX provides essential isolation, security, and network segmentation. Because each virtual network operates
in its own address space, it is inherently isolated from all other virtual networks, and the underlying physical
network, by default. This approach effectively delivers the principle of least privilege, without the need for
physical subnets, VLANs, ACLs, or firewall rules. It also makes it possible to have separate development, test and
production virtual networks – each with different application versions but using the same IP addresses – all
operating at the same time and on the same underlying physical infrastructure. In addition, NSX virtual networks
can easily support multi-tier network environments. For example, multiple Layer 2 segments, Layer 3
segmentation, and/or micro-segmentation on a single Layer 2 segment (using distributed firewall rules) can all
be implemented in whatever combination is needed to effectively segment traffic between the different
components of an n-tier web application.
NSX delivers proven performance and scale.
•	The processing required for execution of distributed network services is only incremental to what the vSwitch
is already doing for connected workloads – typically between 25% and 50% of one core on each host
•	The vSwitch, along with all of the NSX network services run as a kernel-integrated module
•	Virtual network capacity scales linearly (alongside VM capacity) with the introduction of each new hypervisor/
host adding 40 Gbps of switching and routing capacity and 30 Gbps of firewalling capacity
•	Key components, such as the NSX Controller, feature a scale-out architecture that enables seamless scaling of
additional capacity, while also delivering service provider class high-availability
The outcome is real-world, production NSX deployments where a single controller cluster is being used to
deliver over 10,000 virtual networks in support of over 100,000 virtual machines.
NSX enables unparalleled visibility: With the traditional approach to networking, configuration and forwarding
state is spread across a multitude of disparate network devices. This situation often impairs visibility and can
impede related troubleshooting efforts. In comparison, NSX provides all configuration and state information for
all network connections and services in one place. Connectivity status and logs for all NSX components and
virtual network elements (logical switches, routers, etc.) are readily accessible, as is the mapping between virtual
network topologies and the underlying physical network. Furthermore, network administrators can continue to
take advantage of all the familiar monitoring, management, and analysis tools they’ve been using right along.
T E C H N I C A L W H I T E P A P E R / 1 0
The VMware NSX Network
Virtualization Platform
NSX is extremely flexible, highly extensible, and widely supported. A powerful traffic steering capability
allows any combination of network and security services to be chained together in any order as defined by
application policies, for every application workload. This high degree of flexibility applies not only for native NSX
services, but also for a wide variety of compatible third-party solutions – including virtual and physical instances
of next generation firewalls, application delivery controllers, and intrusion prevention systems. By enabling
network and security teams to leverage familiar products and technologies within the virtual network environ-
ment, NSX increases operational efficiency and ensures consistent service delivery while allowing organizations
to extract maximum value from their existing investments in hardware-based networking and security solutions.
The availability of an extensive array of NSX-compatible partner products is also indicative of the broad industry
acceptance and backing for the new operational model delivered by NSX network virtualization.
Compelling Capabilities and Business Value
The technical foundation put in place by the NSX network virtualization platform paves the way for several
compelling IT/networking capabilities and a number of key value propositions.
NSX accelerates network provisioning and streamlines operations. NSX reduces both the effort and time to
provision network and security services - from weeks to minutes With NSX:
•	Network engineers no longer need to scrutinize each network configuration change to ensure it will
notadversely impact delivery of other applications . With NSX each virtual network is not only customizable for
the workloads it supports but also isolated from all other virtual networks
•	Network administrators no longer need to bounce between multiple fragmented management consoles. All
requisite network services can be configured and monitored from a single interface
•	Network administrators can leverage a new operational approach to networking that allows them to
programmatically create, provision, snapshot, delete and restore complex networks all in software
Most importantly, by aligningnetwork and security provisioning with compute/storage provisioning, NSX enables
organizations to develop, test and deploy new applications faster than ever before. For many NSX customers a
faster time-to-market has resulted in a tangible competitive advantage and increased top line revenue by.
A Proven Solution with Many Powerful Use Cases. NSX has been deployed in full production, at scale, by
several of the largest cloud service providers, global financials and enterprise data centers in the world.
AT&T, NTT, Rackspace, eBay, and PayPal are just a handful of the companies that have virtualized their
networks with NSX and are now benefiting from the speed and operational efficiency this game changing
solution delivers. Typical use cases include:
Data Center Automation
•	rapid application deployment with automated network provisioning in lock-step with compute and storage
provisioning
•	quick and easy insertion for both virtual and physical services
Data Center Simplification
•	freedom from VLAN sprawl, firewall rule sprawl, and convoluted traffic patterns
•	isolated development, test, and production environments all operating on the same physical infrastructure
Data Center Enhancement
•	fully distributed security and network services, with centralized administration
•	push-button, no-compromise disaster recovery / business continuity
Multi-tenant Clouds
•	automated network provisioning for tenants while enabling complete customization and isolation
•	maximized hardware sharing across tenants (and physical sites)
T E C H N I C A L W H I T E P A P E R / 1 1
The VMware NSX Network
Virtualization Platform
NSX provides flexible, highly adaptable networking. Traditional networks are rigid, and their functionality is
slow to evolve. In comparison, NSX virtual networks can be re-configured on the fly, and new services – whether
they are virtual or physical – can be inserted as needed, and as they become available. In addition, networking
features and capabilities now evolve at software release cycle speeds (months) instead of hardware release
cycle and refresh/upgrade speeds (years). Other aspects of the solution also deliver tremendous flexibility. For
example, the ability of NSX virtual networks to accommodate overlapping IP addresses and provide Layer 2
adjacency between geographically dispersed data centers makes it considerably easier for organizations to take
advantage of hybrid cloud configurations (e.g., for cloud offload/bursting). A software defined data center
architecture, leveraging NSX network virtualization also allows data centers, either internal or external, to have
different physical network hardware. This supports easy integration for data center mergers and acquisitions
and the broadest choice of external services providers. In comparison, an HDDC architecture would require that
all data centers, whether internal or external, have the same version of physical hardware to deliver consistent
services.
NSX enables unrestricted workload mobility and placement. With NSX, workloads can freely move (or
“vMotion”) across subnets and availability zones, and their placement is not dependent on the physical topology
and availability of physical network services in a given location. Everything a VM needs from a networking
perspective is provided to it by NSX, wherever it physically resides. An important benefit of this capability is that
it’s no longer necessary to over-provision server capacity within each application/network pod. Instead,
organizations can take advantage of available resources wherever they’re located, thereby allowing substantially
greater optimization of resource utilization and consolidation.
NSX dramatically enhances network security. NSX improves network security in several distinct ways. To begin
with, policies can be applied more granularly. Instead of being tied primarily (or even solely) to IP addresses,
rules can be enabled based on virtual containers, applications, and Active Directory identities – and they can be
richer too, for example, by taking advantage of VM introspection capabilities. Two other gains in this area are the
result of policy enforcement becoming both more dynamic and more distributed.
•	Dynamic network security – With NSX virtual networks, security policies are automatically attached to
workloads at the time of VM creation based on a flexible, hierarchical policy model. Moreover, not only do
these policies and the capabilities to enforce them migrate along with their respective VMs, but centrally
made changes to the policies are immediately distributed to each virtual network that is impacted.
•	Distributed network security – With NSX virtual networks, security policies – including those associated
with inserted physical security services – are enforced at the very edges of the network (i.e., at the ingress/
egress ports of each workload’s hypervisor-based vSwitch). This approach is far more effective than that
used with traditional physical networks, where organizations typically rely on a handful of centrally located
security devices (which are blind to the majority of east-west traffic), and/or resort to an excessive amount
of hair-pinning to ensure that inter-VM traffic gets properly controlled and inspected.
NSX enables push-button, zero-compromise disaster recovery. With the traditional approach to networking,
utilizing a back-up site for disaster recovery requires striking a balance between cost and capabilities. Rather
than faithfully reproducing their network topology and services in a second location, most organizations opt for
a “good enough” solution where tradeoffs made to reduce costs translate into diminished capabilities relative to
their primary data center. NSX eliminates the need to compromise. With NSX network virtualization running
alongside the organization’s compute and storage virtualization solutions, IT can snapshot a complete
“application architecture” and then ship a copy off to a disaster recovery site where it’s on standby for push-
button recovery – on any hardware and without any fall-off in functionality.
NSX reduces network TCO. NSX delivers numerous opportunities for reducing both operational and capital
expenditures related to networking. For example, NSX:
•	Automates network provisioning and configuration, while also eliminating manually introduced errors and
downtime
T E C H N I C A L W H I T E P A P E R / 1 2
The VMware NSX Network
Virtualization Platform
•	Streamlines ongoing administration, monitoring, and troubleshooting by enhancing network visibility and
eliminating the need to navigate and maintain VLANs, ACLs, and complex firewall rule sets
•	Obviates the need to invest in separate, standalone solutions for many of the networking and security
functions that are fundamental to data center networking, including distributed routing, firewalling and load
balancing
•	Requires fewer switch ports and less switching capacity overall – as a result of reducing the need for
standalone networking and security appliances and eliminating the need for traffic hair-pinning, respectively
•	Allows selection of least-cost networking equipment – as all that’s needed when building/extending physical
networks are basic forwarding and resiliency capabilities
•	Enables “data center de-fragmentation” – as server utilization can be optimized across application/networking
pods and even greater degrees of data center consolidation can be achieved
•	Eliminates the need to purchase new networking equipment and/or conduct forklift  upgrades in order to take
advantage of new innovations in networking technology
•	Supports development, testing, and production “environments” all on the same physical infrastructure
The result is the ability for both enterprises and service providers to save thousands – if not millions – of dollars
in periodic and recurring costs associated with their networks.
Unleashing the Software defined Data Center
The platform for network virtualization, VMware NSX decouples network services from the data center network
hardware, reproducing and making them available in software so they can be programmatically configured in
lockstep with the workloads they serve, in any combination and location needed. By matching the capabilities
and benefits derived from familiar server and storage virtualization solutions, this transformative approach to
networking unleashes the full potential of the software defined data center – enabling data center managers to
achieve orders of magnitude better agility, economics, and choice. Furthermore, NSX accomplishes all of this in a
way that allows organizations to fully leverage their existing physical network infrastructure and investments.
With NSX, organizations already have the network needed for the next-generation data center today.
For more information, please visit www.vmware.com/products/nsx/
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2013 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed
at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be
trademarks of their respective companies. Item No: VMware NSX Network Virtualization Platform_WP	12/13

More Related Content

What's hot

Optimizing oracle-on-sun-cmt-platform
Optimizing oracle-on-sun-cmt-platformOptimizing oracle-on-sun-cmt-platform
Optimizing oracle-on-sun-cmt-platformSal Marcus
 
Perf vsphere-memory management
Perf vsphere-memory managementPerf vsphere-memory management
Perf vsphere-memory managementRam Prasad Ohnu
 
Perf best practices_v_sphere5.0
Perf best practices_v_sphere5.0Perf best practices_v_sphere5.0
Perf best practices_v_sphere5.0Ram Prasad Ohnu
 
Juniper Networks Solutions for VMware NSX
Juniper Networks Solutions for VMware NSXJuniper Networks Solutions for VMware NSX
Juniper Networks Solutions for VMware NSXJuniper Networks
 
Maa wp sun_apps11i_db10g_r2-2
Maa wp sun_apps11i_db10g_r2-2Maa wp sun_apps11i_db10g_r2-2
Maa wp sun_apps11i_db10g_r2-2Sal Marcus
 
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDE
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDECITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDE
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDELorscheider Santiago
 
Juniper Networks: Security for cloud
Juniper Networks: Security for cloudJuniper Networks: Security for cloud
Juniper Networks: Security for cloudTechnologyBIZ
 
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...Accenture
 
Creating a VMware Software-Defined Data Center Reference Architecture
Creating a VMware Software-Defined Data Center Reference Architecture Creating a VMware Software-Defined Data Center Reference Architecture
Creating a VMware Software-Defined Data Center Reference Architecture EMC
 
Whats-New-VMware-vCloud-Director-15-Technical-Whitepaper
Whats-New-VMware-vCloud-Director-15-Technical-WhitepaperWhats-New-VMware-vCloud-Director-15-Technical-Whitepaper
Whats-New-VMware-vCloud-Director-15-Technical-WhitepaperDjbilly Mixe Pour Toi
 
WHITE PAPER▶ Software Defined Storage at the Speed of Flash
WHITE PAPER▶ Software Defined Storage at the Speed of FlashWHITE PAPER▶ Software Defined Storage at the Speed of Flash
WHITE PAPER▶ Software Defined Storage at the Speed of FlashSymantec
 
Backing up web sphere application server with tivoli storage management redp0149
Backing up web sphere application server with tivoli storage management redp0149Backing up web sphere application server with tivoli storage management redp0149
Backing up web sphere application server with tivoli storage management redp0149Banking at Ho Chi Minh city
 
RDB Synchronization, Transcoding and LDAP Directory Services ...
RDB Synchronization, Transcoding and LDAP Directory Services ...RDB Synchronization, Transcoding and LDAP Directory Services ...
RDB Synchronization, Transcoding and LDAP Directory Services ...Videoguy
 
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...EMC
 

What's hot (19)

Optimizing oracle-on-sun-cmt-platform
Optimizing oracle-on-sun-cmt-platformOptimizing oracle-on-sun-cmt-platform
Optimizing oracle-on-sun-cmt-platform
 
Poc guide vsan
Poc guide vsanPoc guide vsan
Poc guide vsan
 
Perf vsphere-memory management
Perf vsphere-memory managementPerf vsphere-memory management
Perf vsphere-memory management
 
Perf best practices_v_sphere5.0
Perf best practices_v_sphere5.0Perf best practices_v_sphere5.0
Perf best practices_v_sphere5.0
 
Juniper Networks Solutions for VMware NSX
Juniper Networks Solutions for VMware NSXJuniper Networks Solutions for VMware NSX
Juniper Networks Solutions for VMware NSX
 
Maa wp sun_apps11i_db10g_r2-2
Maa wp sun_apps11i_db10g_r2-2Maa wp sun_apps11i_db10g_r2-2
Maa wp sun_apps11i_db10g_r2-2
 
Metro ethernet-dg
Metro ethernet-dgMetro ethernet-dg
Metro ethernet-dg
 
Lenovo midokura
Lenovo midokuraLenovo midokura
Lenovo midokura
 
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDE
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDECITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDE
CITRIX XENSERVER FREE/ADVANCED 5.6 HARDENING GUIDE
 
Juniper Networks: Security for cloud
Juniper Networks: Security for cloudJuniper Networks: Security for cloud
Juniper Networks: Security for cloud
 
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...
Tr 3998 -deployment_guide_for_hosted_shared_desktops_and_on-demand_applicatio...
 
Creating a VMware Software-Defined Data Center Reference Architecture
Creating a VMware Software-Defined Data Center Reference Architecture Creating a VMware Software-Defined Data Center Reference Architecture
Creating a VMware Software-Defined Data Center Reference Architecture
 
Whats-New-VMware-vCloud-Director-15-Technical-Whitepaper
Whats-New-VMware-vCloud-Director-15-Technical-WhitepaperWhats-New-VMware-vCloud-Director-15-Technical-Whitepaper
Whats-New-VMware-vCloud-Director-15-Technical-Whitepaper
 
WHITE PAPER▶ Software Defined Storage at the Speed of Flash
WHITE PAPER▶ Software Defined Storage at the Speed of FlashWHITE PAPER▶ Software Defined Storage at the Speed of Flash
WHITE PAPER▶ Software Defined Storage at the Speed of Flash
 
Rhel Tuningand Optimizationfor Oracle V11
Rhel Tuningand Optimizationfor Oracle V11Rhel Tuningand Optimizationfor Oracle V11
Rhel Tuningand Optimizationfor Oracle V11
 
Sg248203
Sg248203Sg248203
Sg248203
 
Backing up web sphere application server with tivoli storage management redp0149
Backing up web sphere application server with tivoli storage management redp0149Backing up web sphere application server with tivoli storage management redp0149
Backing up web sphere application server with tivoli storage management redp0149
 
RDB Synchronization, Transcoding and LDAP Directory Services ...
RDB Synchronization, Transcoding and LDAP Directory Services ...RDB Synchronization, Transcoding and LDAP Directory Services ...
RDB Synchronization, Transcoding and LDAP Directory Services ...
 
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...
Introduction to the EMC VNX Series VNX5100, VNX5300, VNX5500, VNX5700, and VN...
 

Viewers also liked

ComprehensivePlan
ComprehensivePlanComprehensivePlan
ComprehensivePlanDave Lewis
 
Vmware vsan-layer2-and-layer3-network-topologies
Vmware vsan-layer2-and-layer3-network-topologiesVmware vsan-layer2-and-layer3-network-topologies
Vmware vsan-layer2-and-layer3-network-topologiesCloudSyntrix
 
Datto 2017-progress
Datto 2017-progressDatto 2017-progress
Datto 2017-progressCloudSyntrix
 
Unified framework for streaming databases
Unified framework for streaming databasesUnified framework for streaming databases
Unified framework for streaming databasesAlejandro Grez
 
Smart play hyperflex-program-guide-v2.5
Smart play hyperflex-program-guide-v2.5Smart play hyperflex-program-guide-v2.5
Smart play hyperflex-program-guide-v2.5CloudSyntrix
 
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...Akash Jaiswal
 
ABS Cloud Computing Implementation Guide 1.1
ABS Cloud Computing Implementation Guide 1.1ABS Cloud Computing Implementation Guide 1.1
ABS Cloud Computing Implementation Guide 1.1CloudSyntrix
 
Mr. Reynaldo L. Tabulo Resume
Mr. Reynaldo L. Tabulo ResumeMr. Reynaldo L. Tabulo Resume
Mr. Reynaldo L. Tabulo ResumeReynaldo Tabulo
 
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......Akash Jaiswal
 
تمارين من امتحانات وطنية سابقة Resumé
تمارين من امتحانات وطنية سابقة Resuméتمارين من امتحانات وطنية سابقة Resumé
تمارين من امتحانات وطنية سابقة ResuméFatima Ezahra Rochdi
 
Presentación Informática
Presentación InformáticaPresentación Informática
Presentación InformáticaOrnella Sforzini
 
Robert Pacisco
Robert PaciscoRobert Pacisco
Robert PaciscoOlena Ursu
 
NAVEGANDO HACIA JERUSALEN CON JESUS-Primaria
NAVEGANDO HACIA JERUSALEN CON JESUS-PrimariaNAVEGANDO HACIA JERUSALEN CON JESUS-Primaria
NAVEGANDO HACIA JERUSALEN CON JESUS-PrimariaLaura Aguilar Ramírez
 

Viewers also liked (18)

ComprehensivePlan
ComprehensivePlanComprehensivePlan
ComprehensivePlan
 
Vmware vsan-layer2-and-layer3-network-topologies
Vmware vsan-layer2-and-layer3-network-topologiesVmware vsan-layer2-and-layer3-network-topologies
Vmware vsan-layer2-and-layer3-network-topologies
 
Datto 2017-progress
Datto 2017-progressDatto 2017-progress
Datto 2017-progress
 
Unified framework for streaming databases
Unified framework for streaming databasesUnified framework for streaming databases
Unified framework for streaming databases
 
Dom konstruktor
Dom konstruktorDom konstruktor
Dom konstruktor
 
Smart play hyperflex-program-guide-v2.5
Smart play hyperflex-program-guide-v2.5Smart play hyperflex-program-guide-v2.5
Smart play hyperflex-program-guide-v2.5
 
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...
Hemostats Market: Approvals, Alliances, Relocation & Licensing, and New Brand...
 
ABS Cloud Computing Implementation Guide 1.1
ABS Cloud Computing Implementation Guide 1.1ABS Cloud Computing Implementation Guide 1.1
ABS Cloud Computing Implementation Guide 1.1
 
Mr. Reynaldo L. Tabulo Resume
Mr. Reynaldo L. Tabulo ResumeMr. Reynaldo L. Tabulo Resume
Mr. Reynaldo L. Tabulo Resume
 
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......
The Global Hemodynamic Monitoring Systems Market is expected to reach USD.......
 
تمارين من امتحانات وطنية سابقة Resumé
تمارين من امتحانات وطنية سابقة Resuméتمارين من امتحانات وطنية سابقة Resumé
تمارين من امتحانات وطنية سابقة Resumé
 
Presentación Informática
Presentación InformáticaPresentación Informática
Presentación Informática
 
El soniDO en CuaREsma
El soniDO en CuaREsmaEl soniDO en CuaREsma
El soniDO en CuaREsma
 
Tendencias educativas edwin
Tendencias educativas edwinTendencias educativas edwin
Tendencias educativas edwin
 
Oraciones cuaresma para ninos
Oraciones cuaresma para ninosOraciones cuaresma para ninos
Oraciones cuaresma para ninos
 
Robert Pacisco
Robert PaciscoRobert Pacisco
Robert Pacisco
 
Reconocimiento
ReconocimientoReconocimiento
Reconocimiento
 
NAVEGANDO HACIA JERUSALEN CON JESUS-Primaria
NAVEGANDO HACIA JERUSALEN CON JESUS-PrimariaNAVEGANDO HACIA JERUSALEN CON JESUS-Primaria
NAVEGANDO HACIA JERUSALEN CON JESUS-Primaria
 

Similar to Vmware nsx-network-virtualization-platform-white-paper

Integrating SDN into the Data Center
Integrating SDN into the Data CenterIntegrating SDN into the Data Center
Integrating SDN into the Data CenterJuniper Networks
 
Presentation data center design overview
Presentation   data center design overviewPresentation   data center design overview
Presentation data center design overviewxKinAnx
 
NSX Reference Design version 3.0
NSX Reference Design version 3.0NSX Reference Design version 3.0
NSX Reference Design version 3.0Doddi Priyambodo
 
VMware Network Virtualization Design Guide
VMware Network Virtualization Design GuideVMware Network Virtualization Design Guide
VMware Network Virtualization Design GuideEMC
 
Presentation data center deployment guide
Presentation   data center deployment guidePresentation   data center deployment guide
Presentation data center deployment guidexKinAnx
 
Cisco Virtualization Experience Infrastructure
Cisco Virtualization Experience InfrastructureCisco Virtualization Experience Infrastructure
Cisco Virtualization Experience Infrastructureogrossma
 
Juniper: Data Center Evolution
Juniper: Data Center EvolutionJuniper: Data Center Evolution
Juniper: Data Center EvolutionTechnologyBIZ
 
Everything You Need To Know About Cloud Computing
Everything You Need To Know About Cloud ComputingEverything You Need To Know About Cloud Computing
Everything You Need To Know About Cloud ComputingDarrell Jordan-Smith
 
Integrated-Security-Solution-for-the-virtual-data-center-and-cloud
Integrated-Security-Solution-for-the-virtual-data-center-and-cloudIntegrated-Security-Solution-for-the-virtual-data-center-and-cloud
Integrated-Security-Solution-for-the-virtual-data-center-and-cloudJohn Atchison
 
Set Up Security and Integration with DataPower XI50z
Set Up Security and Integration with DataPower XI50zSet Up Security and Integration with DataPower XI50z
Set Up Security and Integration with DataPower XI50zSarah Duffy
 
VMware Networking 5.0
VMware Networking 5.0VMware Networking 5.0
VMware Networking 5.0rashedmasood
 
Construction ofanoracle10glinuxserver 0.5
Construction ofanoracle10glinuxserver 0.5Construction ofanoracle10glinuxserver 0.5
Construction ofanoracle10glinuxserver 0.5sopan sonar
 
inSync Cloud FAQ
inSync Cloud FAQinSync Cloud FAQ
inSync Cloud FAQDruva
 
Cloud Computing Sun Microsystems
Cloud Computing Sun MicrosystemsCloud Computing Sun Microsystems
Cloud Computing Sun Microsystemsdanielfc
 
White Paper: EMC Compute-as-a-Service
White Paper: EMC Compute-as-a-Service   White Paper: EMC Compute-as-a-Service
White Paper: EMC Compute-as-a-Service EMC
 
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...Configuring a highly available Microsoft Lync Server 2013 environment on Dell...
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...Principled Technologies
 
IBM Flex System Networking in an Enterprise Data Center
IBM Flex System Networking in an Enterprise Data CenterIBM Flex System Networking in an Enterprise Data Center
IBM Flex System Networking in an Enterprise Data CenterIBM India Smarter Computing
 

Similar to Vmware nsx-network-virtualization-platform-white-paper (20)

Integrating SDN into the Data Center
Integrating SDN into the Data CenterIntegrating SDN into the Data Center
Integrating SDN into the Data Center
 
Presentation data center design overview
Presentation   data center design overviewPresentation   data center design overview
Presentation data center design overview
 
NSX Reference Design version 3.0
NSX Reference Design version 3.0NSX Reference Design version 3.0
NSX Reference Design version 3.0
 
VMware Network Virtualization Design Guide
VMware Network Virtualization Design GuideVMware Network Virtualization Design Guide
VMware Network Virtualization Design Guide
 
Presentation data center deployment guide
Presentation   data center deployment guidePresentation   data center deployment guide
Presentation data center deployment guide
 
2000330 en
2000330 en2000330 en
2000330 en
 
Cisco Virtualization Experience Infrastructure
Cisco Virtualization Experience InfrastructureCisco Virtualization Experience Infrastructure
Cisco Virtualization Experience Infrastructure
 
Juniper: Data Center Evolution
Juniper: Data Center EvolutionJuniper: Data Center Evolution
Juniper: Data Center Evolution
 
04367a
04367a04367a
04367a
 
Everything You Need To Know About Cloud Computing
Everything You Need To Know About Cloud ComputingEverything You Need To Know About Cloud Computing
Everything You Need To Know About Cloud Computing
 
Integrated-Security-Solution-for-the-virtual-data-center-and-cloud
Integrated-Security-Solution-for-the-virtual-data-center-and-cloudIntegrated-Security-Solution-for-the-virtual-data-center-and-cloud
Integrated-Security-Solution-for-the-virtual-data-center-and-cloud
 
Set Up Security and Integration with DataPower XI50z
Set Up Security and Integration with DataPower XI50zSet Up Security and Integration with DataPower XI50z
Set Up Security and Integration with DataPower XI50z
 
VMware Networking 5.0
VMware Networking 5.0VMware Networking 5.0
VMware Networking 5.0
 
Construction ofanoracle10glinuxserver 0.5
Construction ofanoracle10glinuxserver 0.5Construction ofanoracle10glinuxserver 0.5
Construction ofanoracle10glinuxserver 0.5
 
inSync Cloud FAQ
inSync Cloud FAQinSync Cloud FAQ
inSync Cloud FAQ
 
Cloud Computing Sun Microsystems
Cloud Computing Sun MicrosystemsCloud Computing Sun Microsystems
Cloud Computing Sun Microsystems
 
ITSM Approach for Clouds
 ITSM Approach for Clouds ITSM Approach for Clouds
ITSM Approach for Clouds
 
White Paper: EMC Compute-as-a-Service
White Paper: EMC Compute-as-a-Service   White Paper: EMC Compute-as-a-Service
White Paper: EMC Compute-as-a-Service
 
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...Configuring a highly available Microsoft Lync Server 2013 environment on Dell...
Configuring a highly available Microsoft Lync Server 2013 environment on Dell...
 
IBM Flex System Networking in an Enterprise Data Center
IBM Flex System Networking in an Enterprise Data CenterIBM Flex System Networking in an Enterprise Data Center
IBM Flex System Networking in an Enterprise Data Center
 

More from CloudSyntrix

Vmware nsx network virtualization platform white paper
Vmware nsx network virtualization platform white paperVmware nsx network virtualization platform white paper
Vmware nsx network virtualization platform white paperCloudSyntrix
 
Datto 2017-progress
Datto 2017-progressDatto 2017-progress
Datto 2017-progressCloudSyntrix
 
Cisco smart play hyperflex-program-guide-v2.5
Cisco smart play hyperflex-program-guide-v2.5Cisco smart play hyperflex-program-guide-v2.5
Cisco smart play hyperflex-program-guide-v2.5CloudSyntrix
 
Hybrid Cloud Opportunity with Microsoft and Cisco
Hybrid Cloud Opportunity with Microsoft and CiscoHybrid Cloud Opportunity with Microsoft and Cisco
Hybrid Cloud Opportunity with Microsoft and CiscoCloudSyntrix
 
AWS Hybrid Cloud Connectivity
AWS Hybrid Cloud ConnectivityAWS Hybrid Cloud Connectivity
AWS Hybrid Cloud ConnectivityCloudSyntrix
 
Cloud computing services by cloudsyntrix
Cloud computing  services by cloudsyntrixCloud computing  services by cloudsyntrix
Cloud computing services by cloudsyntrixCloudSyntrix
 
Cloud Computing- Easy to use and Affordable
Cloud Computing- Easy to use and AffordableCloud Computing- Easy to use and Affordable
Cloud Computing- Easy to use and AffordableCloudSyntrix
 
Vmware services provider overview
Vmware services provider overviewVmware services provider overview
Vmware services provider overviewCloudSyntrix
 
Introduction of Cloud Computing
Introduction of Cloud Computing Introduction of Cloud Computing
Introduction of Cloud Computing CloudSyntrix
 
Datto whats in a cloud purpose vs publics
Datto whats in a cloud purpose vs publicsDatto whats in a cloud purpose vs publics
Datto whats in a cloud purpose vs publicsCloudSyntrix
 
Virtualization and Cloud Management Solutions
Virtualization and Cloud Management SolutionsVirtualization and Cloud Management Solutions
Virtualization and Cloud Management SolutionsCloudSyntrix
 
Introduction to Cloud Computing
Introduction to Cloud Computing Introduction to Cloud Computing
Introduction to Cloud Computing CloudSyntrix
 
Introduction to Cloud Computing
Introduction to Cloud Computing Introduction to Cloud Computing
Introduction to Cloud Computing CloudSyntrix
 
VCloud Air Network Guide
VCloud Air Network Guide VCloud Air Network Guide
VCloud Air Network Guide CloudSyntrix
 
Servicenow overview
Servicenow overviewServicenow overview
Servicenow overviewCloudSyntrix
 
SD-WAN: Why should you care?
SD-WAN: Why should you care?SD-WAN: Why should you care?
SD-WAN: Why should you care?CloudSyntrix
 
Virtualization for Cloud Computing
Virtualization for Cloud ComputingVirtualization for Cloud Computing
Virtualization for Cloud ComputingCloudSyntrix
 

More from CloudSyntrix (17)

Vmware nsx network virtualization platform white paper
Vmware nsx network virtualization platform white paperVmware nsx network virtualization platform white paper
Vmware nsx network virtualization platform white paper
 
Datto 2017-progress
Datto 2017-progressDatto 2017-progress
Datto 2017-progress
 
Cisco smart play hyperflex-program-guide-v2.5
Cisco smart play hyperflex-program-guide-v2.5Cisco smart play hyperflex-program-guide-v2.5
Cisco smart play hyperflex-program-guide-v2.5
 
Hybrid Cloud Opportunity with Microsoft and Cisco
Hybrid Cloud Opportunity with Microsoft and CiscoHybrid Cloud Opportunity with Microsoft and Cisco
Hybrid Cloud Opportunity with Microsoft and Cisco
 
AWS Hybrid Cloud Connectivity
AWS Hybrid Cloud ConnectivityAWS Hybrid Cloud Connectivity
AWS Hybrid Cloud Connectivity
 
Cloud computing services by cloudsyntrix
Cloud computing  services by cloudsyntrixCloud computing  services by cloudsyntrix
Cloud computing services by cloudsyntrix
 
Cloud Computing- Easy to use and Affordable
Cloud Computing- Easy to use and AffordableCloud Computing- Easy to use and Affordable
Cloud Computing- Easy to use and Affordable
 
Vmware services provider overview
Vmware services provider overviewVmware services provider overview
Vmware services provider overview
 
Introduction of Cloud Computing
Introduction of Cloud Computing Introduction of Cloud Computing
Introduction of Cloud Computing
 
Datto whats in a cloud purpose vs publics
Datto whats in a cloud purpose vs publicsDatto whats in a cloud purpose vs publics
Datto whats in a cloud purpose vs publics
 
Virtualization and Cloud Management Solutions
Virtualization and Cloud Management SolutionsVirtualization and Cloud Management Solutions
Virtualization and Cloud Management Solutions
 
Introduction to Cloud Computing
Introduction to Cloud Computing Introduction to Cloud Computing
Introduction to Cloud Computing
 
Introduction to Cloud Computing
Introduction to Cloud Computing Introduction to Cloud Computing
Introduction to Cloud Computing
 
VCloud Air Network Guide
VCloud Air Network Guide VCloud Air Network Guide
VCloud Air Network Guide
 
Servicenow overview
Servicenow overviewServicenow overview
Servicenow overview
 
SD-WAN: Why should you care?
SD-WAN: Why should you care?SD-WAN: Why should you care?
SD-WAN: Why should you care?
 
Virtualization for Cloud Computing
Virtualization for Cloud ComputingVirtualization for Cloud Computing
Virtualization for Cloud Computing
 

Recently uploaded

Local Call Girls in Jharsuguda 9332606886 HOT & SEXY Models beautiful and ch...
Local Call Girls in Jharsuguda  9332606886 HOT & SEXY Models beautiful and ch...Local Call Girls in Jharsuguda  9332606886 HOT & SEXY Models beautiful and ch...
Local Call Girls in Jharsuguda 9332606886 HOT & SEXY Models beautiful and ch...Sareena Khatun
 
Local Call Girls in Gomati 9332606886 HOT & SEXY Models beautiful and charmi...
Local Call Girls in Gomati  9332606886 HOT & SEXY Models beautiful and charmi...Local Call Girls in Gomati  9332606886 HOT & SEXY Models beautiful and charmi...
Local Call Girls in Gomati 9332606886 HOT & SEXY Models beautiful and charmi...Sareena Khatun
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样ayvbos
 
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budgetCall Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budgetkumargunjan9515
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC
 
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC
 
Down bad crying at the gym t shirtsDown bad crying at the gym t shirts
Down bad crying at the gym t shirtsDown bad crying at the gym t shirtsDown bad crying at the gym t shirtsDown bad crying at the gym t shirts
Down bad crying at the gym t shirtsDown bad crying at the gym t shirtsrahman018755
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...gajnagarg
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfJOHNBEBONYAP1
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制pxcywzqs
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdfMatthew Sinclair
 
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...meghakumariji156
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformonhackersuli
 
Delivery in 20 Mins Call Girls Cuttack 9332606886 HOT & SEXY Models beautifu...
Delivery in 20 Mins Call Girls Cuttack  9332606886 HOT & SEXY Models beautifu...Delivery in 20 Mins Call Girls Cuttack  9332606886 HOT & SEXY Models beautifu...
Delivery in 20 Mins Call Girls Cuttack 9332606886 HOT & SEXY Models beautifu...Sareena Khatun
 
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu DhabiAbu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu DhabiMonica Sydney
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...kajalverma014
 
一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理SS
 
Mira Road Housewife Call Girls 07506202331, Nalasopara Call Girls
Mira Road Housewife Call Girls 07506202331, Nalasopara Call GirlsMira Road Housewife Call Girls 07506202331, Nalasopara Call Girls
Mira Road Housewife Call Girls 07506202331, Nalasopara Call GirlsPriya Reddy
 

Recently uploaded (20)

Local Call Girls in Jharsuguda 9332606886 HOT & SEXY Models beautiful and ch...
Local Call Girls in Jharsuguda  9332606886 HOT & SEXY Models beautiful and ch...Local Call Girls in Jharsuguda  9332606886 HOT & SEXY Models beautiful and ch...
Local Call Girls in Jharsuguda 9332606886 HOT & SEXY Models beautiful and ch...
 
Local Call Girls in Gomati 9332606886 HOT & SEXY Models beautiful and charmi...
Local Call Girls in Gomati  9332606886 HOT & SEXY Models beautiful and charmi...Local Call Girls in Gomati  9332606886 HOT & SEXY Models beautiful and charmi...
Local Call Girls in Gomati 9332606886 HOT & SEXY Models beautiful and charmi...
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budgetCall Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budget
Call Girls Mehdipatnam ( 8250092165 ) Cheap rates call girls | Get low budget
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
Down bad crying at the gym t shirtsDown bad crying at the gym t shirts
Down bad crying at the gym t shirtsDown bad crying at the gym t shirtsDown bad crying at the gym t shirtsDown bad crying at the gym t shirts
Down bad crying at the gym t shirtsDown bad crying at the gym t shirts
 
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
call girls in Anand Vihar (delhi) call me [🔝9953056974🔝] escort service 24X7
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
20240507 QFM013 Machine Intelligence Reading List April 2024.pdf
 
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
Tadepalligudem Escorts Service Girl ^ 9332606886, WhatsApp Anytime Tadepallig...
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
[Hackersuli] Élő szövet a fémvázon: Python és gépi tanulás a Zeek platformon
 
Delivery in 20 Mins Call Girls Cuttack 9332606886 HOT & SEXY Models beautifu...
Delivery in 20 Mins Call Girls Cuttack  9332606886 HOT & SEXY Models beautifu...Delivery in 20 Mins Call Girls Cuttack  9332606886 HOT & SEXY Models beautifu...
Delivery in 20 Mins Call Girls Cuttack 9332606886 HOT & SEXY Models beautifu...
 
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu DhabiAbu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
Abu Dhabi Escorts Service 0508644382 Escorts in Abu Dhabi
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理一比一原版澳大利亚迪肯大学毕业证如何办理
一比一原版澳大利亚迪肯大学毕业证如何办理
 
Mira Road Housewife Call Girls 07506202331, Nalasopara Call Girls
Mira Road Housewife Call Girls 07506202331, Nalasopara Call GirlsMira Road Housewife Call Girls 07506202331, Nalasopara Call Girls
Mira Road Housewife Call Girls 07506202331, Nalasopara Call Girls
 

Vmware nsx-network-virtualization-platform-white-paper

  • 1. The VMware NSX Network Virtualization Platform VMware Solutions: Designed for Early and Ongoing Success T E C H N I C A L W H I T E P A P E R
  • 2. The VMware NSX Network Virtualization Platform T E C H N I C A L W H I T E P A P E R / 2 Table of Contents Executive Summary. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Networking is Stuck in the Past. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 The Glass is only Half Full. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Network provisioning is slow. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 Workload placement and mobility is limited. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 It’s Time to Virtualize the Network. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4 Introducting VMware NSX –The Platform for Network Virtualization. . . . . . . . . . . . . . . 5 How VMware NSX Works. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6 Compelling Technical Features and Characteristics. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 NSX fits right in. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8 NSX network virtualization is not an all-or-nothing proposition. . . . . . . . . . . . . . . . . . . . 9 NSX simplifies networking . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 NSX provides essential isolation, security, and network segmentation . . . . . . . . . . . . . 9 NSX delivers proven performance and scale. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 NSX enables unparalleled visibility. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 NSX is extremely flexible, highly extensible, and widely supported . . . . . . . . . . . . . . . 10 A Proven Solution with Many Powerful Use Cases. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Data Center Automation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Data Center Simplification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Data Center Enhancement. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 Multi-tenant Clouds. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10 Compelling Capabilities and Business Value. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10 NSX accelerates network provisioning and streamlines operations. . . . . . . . . . . . . . . . 10 NSX provides flexible, highly adaptable networking. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 NSX enables unrestricted workload mobility and placement. . . . . . . . . . . . . . . . . . . . . 11 NSX dramatically enhances network security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11 NSX enables push-button, zero-compromise disaster recovery . . . . . . . . . . . . . . . . . . 11 NSX reduces network TCO. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12 Unleashing the Software defined Data Center. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
  • 3. T E C H N I C A L W H I T E P A P E R / 3 The VMware NSX Network Virtualization Platform Executive Summary VMware’s Software Defined Data Center (SDDC) vision leverages core data center virtualization technologies to transform data center economics and business agility through automation and non-disruptive deployment that embraces and extends existing compute, network and storage infrastructure investments. Enterprise data centers are already realizing the tremendous benefits of server and storage virtualization solutions to consolidate and repurpose infrastructure resources, reduce operational complexity and dynamically align and scale their application infrastructure in response to business priorities. However, the data center network has not kept pace and remains rigid, complex, proprietary and closed to innovation – a barrier to realizing the full potential of the virtualization and the SDDCs. The VMware NSX network virtualization platform provides the critical third pillar of VMware’s Software Defined Data Center (SDDC) architecture. NSX network virtualization delivers for networking what VMware has already delivered for compute and storage. In much the same way that server virtualization allows operators to programmatically create, snapshot, delete and restore software-based virtual machines (VMs) on demand, NSX enables virtual networks to be created, saved and deleted and restored on demand without requiring any reconfiguration of the physical network. The result fundamentally transforms the data center network operational model, reduces network provisioning time from days or weeks to minutes and dramatically simplifies network operations. NSX is a non-disruptive solution that is deployed on any IP network, including existing data center network designs or next generation fabric architectures from any networking vendor. With NSX, you already have the physical network infrastructure you need to deliver a software defined data center. Networking is Stuck in the Past Traditional approaches to networking not only prevent today’s organizations from realizing the full promise of the software defined data center, but also subject them to limited flexibility and operational challenges. The Glass is only Half Full Server and storage virtualization solutions have dramatically transformed the data center by delivering significant operational savings through automation, capital savings through consolidation and hardware independence, and greater agility through on-demand and self-service approaches to provisioning. As significant as these gains have been, however, much of the potential for these solutions remains untapped. More to the point, these businesses are being held back, by an antiquated network operationaL. Networking and network services have been stuck in the status quo and are out-of-step with server and storage solutions that can be quickly provisioned but are constrained by networking services that still require manual provisioning and are anchored to vendor specific hardware and topology. This directly impacts application deployment time because applications need both compute and networking resources. Network provisioning is slow. The current operational model has resulted in slow, manual, error-prone provisioning of network services to support application deployment.. Network operators are dependent on terminal, keyboard, scripting and CLIs to manipulate a multitude of VLANs, firewall rules, load balancers and ACL, QoS, VRF and MAC/IP tables. Complexity and risk are further compounded by the need to ensure that changes to the network for one application do not adversely impact other applications . Given the complexity of this situation, it’s no surprise that several recent studies point to manual configuration errors as the cause for
  • 4. T E C H N I C A L W H I T E P A P E R / 4 The VMware NSX Network Virtualization Platform more than 60% of network downtime and/or security breaches. The result is that in addition to the frequent, inevitable configuration mis-steps, IT response time to new business requirements is too slow, as rapidly re-purposed compute and storage infrastructure must still wait for the network to catch up. Workload placement and mobility is limited. The current device-centric approach to networking confines workload mobility to individual physical subnets and availability zones. In order to reach available compute resources in the data center, network operators are forced to perform manual box-by-box configuration of VLANs, ACLs, firewall rules, and so forth. This process is not only slow and complex, but also one that will eventually reach configuration limits (e.g., 4096 for total VLANs). Organizations often resort to expensive over- provisioning of server capacity for each application/networking pod, resulting in stranded resources and sub- optimal resource utilization. Additional Data Center Networking Challenges Related challenges data center networking teams face with traditional networking approaches include: • VLAN sprawl caused by constantly having to overcome IP addressing and physical topology limitations required to logically group sets of resources • Firewall rule sprawl resulting from centralized firewalls deployed in increasingly dynamic environments coupled with the common practice of adding new rules but rarely removing any for fear of disrupting service availability; • Performance choke points and increased network capacity costs due to the need for hair-pinning and multiple hops to route traffic through essential network services that are not pervasively available. The increase of East- West traffic in a data center exacerbates this problem • Security and network service blind spots that result in choosing to avoid hair-pinning and other deploy risky routing schemes • Increased complexity in supporting the dynamic nature of today’s cloud data center environments. It’s Time to Virtualize the Network The solution to these challenges is to virtualize the network. Do for networking the same thing that has been done for compute and storage. In fact, network virtualization is conceptually very similar to server virtualization (see Figure 1). With server virtualization, a software abstraction layer (server hypervisor) reproduces the familiar attributes of an x86 physical server (e.g., CPU, RAM, Disk, NIC) in software, allowing them to be programmatically assembled in any arbitrary combination to produce a unique virtual machine (VM) in a matter of seconds. With network virtualization, the functional equivalent of a “network hypervisor” reproduces the complete set of Layer 2 to Layer 7 networking services (e.g., switching, routing, access control, firewalling, QoS, and load balancing) in software. As a result, they too can be programmatically assembled in any arbitrary combination, this time to produce a unique virtual network in a matter of seconds. Not surprisingly, similar benefits are also derived. For example, just as VMs are independent of the underlying x86 platform and allow IT to treat physical hosts as a pool of compute capacity, virtual networks are independent of the underlying IP network hardware and allow IT to treat the physical network as a pool of transport capacity that can be consumed and repurposed on demand.
  • 5. T E C H N I C A L W H I T E P A P E R / 5 The VMware NSX Network Virtualization Platform More importantly, network virtualization provides a strong foundation for resolving the networking challenges keeping today’s organizations from realizing the full potential of the software defined data center (see text box “Why the Software defined Data Center Makes More Sense”) Introducing VMware NSX – The Platform for Network Virtualization VMware NSX is the market leading implementation of network virtualization from VMware. By delivering a completely new operational model for networking that breaks through current physical network barriers, NSX enables data center operators to achieve orders of magnitude better agility, economics, and choice. Figure 1: How Network Virtualization Parallels Server Virtualization. Why the Software defined Data Center Makes More Sense The software defined data center (SDDC) approach to building next generation data centers has several compelling advantages over emerging hardware defined data center (HDDC) alternatives. First and foremost, SDDC is proven. Indeed, building advanced, software-based intelligence into their applications and platforms is what has enabled Google and Amazon to deliver the largest, most agile and efficient data centers in the world today. Another major advantage of SDDC is that innovation occurs at the speed of software releases, instead of being tied to ASIC and hardware-upgrade cycles of three to five years, or more. Moreover, adopting new innovations no longer requires forklift hardware upgrades. Best of all, a software defined data center works with the physical infrastructure you already have and can be deployed non-disruptively alongside your existing configurations at whatever pace your organization chooses.
  • 6. T E C H N I C A L W H I T E P A P E R / 6 The VMware NSX Network Virtualization Platform With NSX, virtual networks are programmatically created, provisioned and managed, utilizing the underlying physical network as a simple packet forwarding backplane. Network and security services in software are distributed to hypervisors and “attached” to individual VMs in accordance with networking and security policies defined for each connected application. When a VM is moved to another host, its networking and security services move with it. And when new VMs are created to scale an application, the necessary policies are dynamically applied to those VMs as well. NSX is completely non-disruptive solution:, • Deploys on hypervisors connected to any existing physical network infrastructure and supports next- generation fabrics and topologies from any vendor; • Requires no changes to existing applications and workloads • Allows IT departments to incrementally implement virtual networks at whatever pace they choose (without any impact to existing applications and network configurations) • Extends visibility to existing networking monitoring and management tools to deliver increased visibility into virtualized networks The net result is a transformative approach to data center networking that – among its many other benefits – matches the velocity demands of today’s businesses by reducing service delivery times from weeks to seconds. How VMware NSX Works Figure 2: The “Network Hypervisor” Figure 2: NSX is a multi-hypervisor solution that leverages the vSwitches already present in server hypervisors across the data center. NSX coordinates these vSwitches and the network services pushed to them for connected VMs to effectively deliver a platform – or “network hypervisor” – for the creation of virtual networks. Similar to how a virtual machine is a software container that presents logical compute services to an application, a virtual network is a software container that presents logical network services – logical switches, logical routers, logical firewalls, logical load balancers, logical VPNs and more – to connected workloads. These network and security services are delivered in software and require only IP packet forwarding from the underlying physical network. The following diagrams reveal the fundamentals of how NSX works. They also set the stage for further exploring the technical characteristics, capabilities, and value propositions that define the NSX solution. Figure 2: The “Network Hypervisor”
  • 7. T E C H N I C A L W H I T E P A P E R / 7 The VMware NSX Network Virtualization Platform Figure 3: Virtual Network Provisioning Figure 4: The Virtual Network – From the Workload’s Perspective (i.e., Logical) Figure 5: The Virtual Network – From the Network’s Perspective (i.e., Physical) Figure 3: Virtual networks are provisioned by taking advantage of a cloud management platform (CMP) which uses the RESTful API exposed by the NSX Controller to request the virtual network and security services be instantiated for the corresponding workloads (step 1). The Controller then distributes the necessary services to the corresponding vSwitches and logically attaches them to the corresponding workloads (step 2). This approach not only allows different virtual networks to be associated with different workloads on the same hypervisor, but also enables the creation of everything from basic virtual networks involving as few as two nodes, to very advanced constructs that match the complex, multi-segment network topologies used to deliver multi-tier applications. Figure 4: To connected workloads, a virtual network looks and operates like a traditional physical network. Workloads “see” the same Layer 2, Layer 3, and Layer 4-7 network services that they would in a traditional physical configuration. It’s just that these network services are now logical instances of distributed software modules running in the hypervisor on the local host and applied at the vSwitch virtual interface. applications. Figure 5: To connected workloads, a virtual network looks and operates like a traditional physical network. Workloads “see” the same Layer 2, Layer 3, and Layer 4-7 network services that they would in a traditional physical configuration. It’s just that these network services are now logical instances of distributed software modules running in the hypervisor on the local host and applied at the vSwitch virtual interface. applications.
  • 8. T E C H N I C A L W H I T E P A P E R / 8 The VMware NSX Network Virtualization Platform Compelling Technical Features and Characteristics Several key features and characteristics are instrumental to the value NSX delivers, both to IT and the business at-large. These include the ability to work with your existing network infrastructure, support progressive adoption of network virtualization, and substantially reduce network complexity. NSX fits right in. Simply put, NSX works with: • Any application. Workloads/applications need not be modified in anyway as the virtual network appears no different to them than the physical network. • Any hypervisor. Out-of-the box support is available for many hypervisors (e.g., Xen, KVM, and VMware ESXi), while coverage can be extended to others (e.g., Microsoft Hyper-V) by re-configuring them to incorporate standard vSwitch capabilities. • Any network infrastructure. Hardware independence is achieved based on the fact that NSX virtual networks require nothing more than connectivity and packet-forwarding from the underlying IP infrastructure. • Any cloud management platform. Out-of-the-box support is available for many cloud management platforms (including CloudStack, OpenStack, VMware vCloud Automation Center,), and integration with other management platforms is provided through the NSX API. Figure 6a: Distributed Routing with NSX Figure 6b: Distributed Firewall with NSX Figures 6a and 6b: The ability to apply/enforce security services at the vSwitch virtual interface also eliminates “hair-pinning” – an unfortunate “feature” of traditional physical network architectures where East-West communications traffic – for example, between two VMs on the same hypervisor but in different subnets – is required to traverse the network to reach essential services, such as routing and firewalling. With NSX, inefficient traffic patterns such as these, which often lead to core link over-subscription, become a thing of the past.
  • 9. T E C H N I C A L W H I T E P A P E R / 9 The VMware NSX Network Virtualization Platform NSX network virtualization is not an all-or-nothing proposition. Because NSX virtual networks require no configuration changes to the underlying physical network (outside of allowing NSX encapsulated packets through existing firewalls) they transparently co-exist with existing application deployments on the physical network today. IT departments have the flexibility to virtualize portions of the network by simply adding hypervisor nodes to the NSX platform. In addition, Gateways – available as software from VMware or top-of-rack switch hardware from several NSX partners – deliver the ability to seamlessly inter-connect virtual and physical networks. These can be used, for example, to support Internet access by workloads connected to virtual networks, or to directly connect legacy VLANs and bare metal workloads to virtual networks. NSX simplifies networking. NSX abstracts virtual networks from the underlying physical network enabling increased automation. Operators are not required to interact with the physical network and are therefore spared the inconsistencies across platforms. Operators no longer need to deal with VLANs, ACLs, spanning trees, complex sets of firewall rules, and convoluted hair-pinning traffic patterns – because these are no longer necessary when the network is virtualized. NSX network virtualization is not an all or nothing proposition. As organizations incementally employ NSX virtual networks, they can increasingly streamline their physical network configuration and design. Vendor lock-in becomes a thing of the past, since the physical network only needs to deliver reliable high-speed packet-forwarding, it’s then possible to mix and match hardware from different product lines and vendors. NSX provides essential isolation, security, and network segmentation. Because each virtual network operates in its own address space, it is inherently isolated from all other virtual networks, and the underlying physical network, by default. This approach effectively delivers the principle of least privilege, without the need for physical subnets, VLANs, ACLs, or firewall rules. It also makes it possible to have separate development, test and production virtual networks – each with different application versions but using the same IP addresses – all operating at the same time and on the same underlying physical infrastructure. In addition, NSX virtual networks can easily support multi-tier network environments. For example, multiple Layer 2 segments, Layer 3 segmentation, and/or micro-segmentation on a single Layer 2 segment (using distributed firewall rules) can all be implemented in whatever combination is needed to effectively segment traffic between the different components of an n-tier web application. NSX delivers proven performance and scale. • The processing required for execution of distributed network services is only incremental to what the vSwitch is already doing for connected workloads – typically between 25% and 50% of one core on each host • The vSwitch, along with all of the NSX network services run as a kernel-integrated module • Virtual network capacity scales linearly (alongside VM capacity) with the introduction of each new hypervisor/ host adding 40 Gbps of switching and routing capacity and 30 Gbps of firewalling capacity • Key components, such as the NSX Controller, feature a scale-out architecture that enables seamless scaling of additional capacity, while also delivering service provider class high-availability The outcome is real-world, production NSX deployments where a single controller cluster is being used to deliver over 10,000 virtual networks in support of over 100,000 virtual machines. NSX enables unparalleled visibility: With the traditional approach to networking, configuration and forwarding state is spread across a multitude of disparate network devices. This situation often impairs visibility and can impede related troubleshooting efforts. In comparison, NSX provides all configuration and state information for all network connections and services in one place. Connectivity status and logs for all NSX components and virtual network elements (logical switches, routers, etc.) are readily accessible, as is the mapping between virtual network topologies and the underlying physical network. Furthermore, network administrators can continue to take advantage of all the familiar monitoring, management, and analysis tools they’ve been using right along.
  • 10. T E C H N I C A L W H I T E P A P E R / 1 0 The VMware NSX Network Virtualization Platform NSX is extremely flexible, highly extensible, and widely supported. A powerful traffic steering capability allows any combination of network and security services to be chained together in any order as defined by application policies, for every application workload. This high degree of flexibility applies not only for native NSX services, but also for a wide variety of compatible third-party solutions – including virtual and physical instances of next generation firewalls, application delivery controllers, and intrusion prevention systems. By enabling network and security teams to leverage familiar products and technologies within the virtual network environ- ment, NSX increases operational efficiency and ensures consistent service delivery while allowing organizations to extract maximum value from their existing investments in hardware-based networking and security solutions. The availability of an extensive array of NSX-compatible partner products is also indicative of the broad industry acceptance and backing for the new operational model delivered by NSX network virtualization. Compelling Capabilities and Business Value The technical foundation put in place by the NSX network virtualization platform paves the way for several compelling IT/networking capabilities and a number of key value propositions. NSX accelerates network provisioning and streamlines operations. NSX reduces both the effort and time to provision network and security services - from weeks to minutes With NSX: • Network engineers no longer need to scrutinize each network configuration change to ensure it will notadversely impact delivery of other applications . With NSX each virtual network is not only customizable for the workloads it supports but also isolated from all other virtual networks • Network administrators no longer need to bounce between multiple fragmented management consoles. All requisite network services can be configured and monitored from a single interface • Network administrators can leverage a new operational approach to networking that allows them to programmatically create, provision, snapshot, delete and restore complex networks all in software Most importantly, by aligningnetwork and security provisioning with compute/storage provisioning, NSX enables organizations to develop, test and deploy new applications faster than ever before. For many NSX customers a faster time-to-market has resulted in a tangible competitive advantage and increased top line revenue by. A Proven Solution with Many Powerful Use Cases. NSX has been deployed in full production, at scale, by several of the largest cloud service providers, global financials and enterprise data centers in the world. AT&T, NTT, Rackspace, eBay, and PayPal are just a handful of the companies that have virtualized their networks with NSX and are now benefiting from the speed and operational efficiency this game changing solution delivers. Typical use cases include: Data Center Automation • rapid application deployment with automated network provisioning in lock-step with compute and storage provisioning • quick and easy insertion for both virtual and physical services Data Center Simplification • freedom from VLAN sprawl, firewall rule sprawl, and convoluted traffic patterns • isolated development, test, and production environments all operating on the same physical infrastructure Data Center Enhancement • fully distributed security and network services, with centralized administration • push-button, no-compromise disaster recovery / business continuity Multi-tenant Clouds • automated network provisioning for tenants while enabling complete customization and isolation • maximized hardware sharing across tenants (and physical sites)
  • 11. T E C H N I C A L W H I T E P A P E R / 1 1 The VMware NSX Network Virtualization Platform NSX provides flexible, highly adaptable networking. Traditional networks are rigid, and their functionality is slow to evolve. In comparison, NSX virtual networks can be re-configured on the fly, and new services – whether they are virtual or physical – can be inserted as needed, and as they become available. In addition, networking features and capabilities now evolve at software release cycle speeds (months) instead of hardware release cycle and refresh/upgrade speeds (years). Other aspects of the solution also deliver tremendous flexibility. For example, the ability of NSX virtual networks to accommodate overlapping IP addresses and provide Layer 2 adjacency between geographically dispersed data centers makes it considerably easier for organizations to take advantage of hybrid cloud configurations (e.g., for cloud offload/bursting). A software defined data center architecture, leveraging NSX network virtualization also allows data centers, either internal or external, to have different physical network hardware. This supports easy integration for data center mergers and acquisitions and the broadest choice of external services providers. In comparison, an HDDC architecture would require that all data centers, whether internal or external, have the same version of physical hardware to deliver consistent services. NSX enables unrestricted workload mobility and placement. With NSX, workloads can freely move (or “vMotion”) across subnets and availability zones, and their placement is not dependent on the physical topology and availability of physical network services in a given location. Everything a VM needs from a networking perspective is provided to it by NSX, wherever it physically resides. An important benefit of this capability is that it’s no longer necessary to over-provision server capacity within each application/network pod. Instead, organizations can take advantage of available resources wherever they’re located, thereby allowing substantially greater optimization of resource utilization and consolidation. NSX dramatically enhances network security. NSX improves network security in several distinct ways. To begin with, policies can be applied more granularly. Instead of being tied primarily (or even solely) to IP addresses, rules can be enabled based on virtual containers, applications, and Active Directory identities – and they can be richer too, for example, by taking advantage of VM introspection capabilities. Two other gains in this area are the result of policy enforcement becoming both more dynamic and more distributed. • Dynamic network security – With NSX virtual networks, security policies are automatically attached to workloads at the time of VM creation based on a flexible, hierarchical policy model. Moreover, not only do these policies and the capabilities to enforce them migrate along with their respective VMs, but centrally made changes to the policies are immediately distributed to each virtual network that is impacted. • Distributed network security – With NSX virtual networks, security policies – including those associated with inserted physical security services – are enforced at the very edges of the network (i.e., at the ingress/ egress ports of each workload’s hypervisor-based vSwitch). This approach is far more effective than that used with traditional physical networks, where organizations typically rely on a handful of centrally located security devices (which are blind to the majority of east-west traffic), and/or resort to an excessive amount of hair-pinning to ensure that inter-VM traffic gets properly controlled and inspected. NSX enables push-button, zero-compromise disaster recovery. With the traditional approach to networking, utilizing a back-up site for disaster recovery requires striking a balance between cost and capabilities. Rather than faithfully reproducing their network topology and services in a second location, most organizations opt for a “good enough” solution where tradeoffs made to reduce costs translate into diminished capabilities relative to their primary data center. NSX eliminates the need to compromise. With NSX network virtualization running alongside the organization’s compute and storage virtualization solutions, IT can snapshot a complete “application architecture” and then ship a copy off to a disaster recovery site where it’s on standby for push- button recovery – on any hardware and without any fall-off in functionality. NSX reduces network TCO. NSX delivers numerous opportunities for reducing both operational and capital expenditures related to networking. For example, NSX: • Automates network provisioning and configuration, while also eliminating manually introduced errors and downtime
  • 12. T E C H N I C A L W H I T E P A P E R / 1 2 The VMware NSX Network Virtualization Platform • Streamlines ongoing administration, monitoring, and troubleshooting by enhancing network visibility and eliminating the need to navigate and maintain VLANs, ACLs, and complex firewall rule sets • Obviates the need to invest in separate, standalone solutions for many of the networking and security functions that are fundamental to data center networking, including distributed routing, firewalling and load balancing • Requires fewer switch ports and less switching capacity overall – as a result of reducing the need for standalone networking and security appliances and eliminating the need for traffic hair-pinning, respectively • Allows selection of least-cost networking equipment – as all that’s needed when building/extending physical networks are basic forwarding and resiliency capabilities • Enables “data center de-fragmentation” – as server utilization can be optimized across application/networking pods and even greater degrees of data center consolidation can be achieved • Eliminates the need to purchase new networking equipment and/or conduct forklift upgrades in order to take advantage of new innovations in networking technology • Supports development, testing, and production “environments” all on the same physical infrastructure The result is the ability for both enterprises and service providers to save thousands – if not millions – of dollars in periodic and recurring costs associated with their networks. Unleashing the Software defined Data Center The platform for network virtualization, VMware NSX decouples network services from the data center network hardware, reproducing and making them available in software so they can be programmatically configured in lockstep with the workloads they serve, in any combination and location needed. By matching the capabilities and benefits derived from familiar server and storage virtualization solutions, this transformative approach to networking unleashes the full potential of the software defined data center – enabling data center managers to achieve orders of magnitude better agility, economics, and choice. Furthermore, NSX accomplishes all of this in a way that allows organizations to fully leverage their existing physical network infrastructure and investments. With NSX, organizations already have the network needed for the next-generation data center today. For more information, please visit www.vmware.com/products/nsx/
  • 13. VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com Copyright © 2013 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item No: VMware NSX Network Virtualization Platform_WP 12/13