How to Deploy a VMware NSX-T 3.2 Tier-0 Gateway (T0 GW)

Tier-0 Gateway (also known as Tier-0 Logical Router): interfaces with the physical network and exchange routing information with external routers via static routing or eBGP. In active-standby mode, the gateway can also provide stateful services.

The Tier-0 router performs gateway services between overlay and non-overlay hosts (for example, a physical server or the Internet router).

There can be only one Tier-0 gateway per Edge node

The SR component of the NSX-T Tier-0 Logical Router is responsible for establishing eBGP peering with the leaf switches and enabling North-South routing.

How to deploy T0 GW

NSX-T Segments page showing existing application segments before the Tier-0 uplink VLAN segments are created.

First if you have not already done so we need to create an uplink segment
These segments will be used by the T0 to connect to the upstream physical router

Segment editor configuring a BGP uplink segment on the production VLAN transport zone for the Tier-0 gateway.

Provide a name
select your VLAN TZ
Save
Rinse and repeat for your second uplink

NSX-T Segments inventory showing both Tier-0 BGP uplink VLAN segments alongside the application segments.

Now we move on to creating the T0 GW

NSX-T Tier-0 Gateways page where the production Tier-0 gateway will be created.

Click tier-0

Tier-0 gateway editor naming TX-Prod-T0-01, selecting Active-Active mode, and assigning the production edge cluster.

Must provide a name

Select your edge cluster previously created

Save

NSX-T confirmation that the TX-Prod-T0-01 Tier-0 gateway was created successfully.

Yes

NSX-T Tier-0 gateway configuration showing the Set control for interfaces.

Set

Set Interfaces dialog for TX-Prod-T0-01 before external uplink interfaces are added.

Add interface

Tier-0 interface form requesting the uplink name, IP mask, connected segment, edge node, and profile.

Provide the name of the uplink

Enter the IP and mask

Connected segments select the new uplink segment

Select an edge node previously created

Save

Tier-0 interface list showing the two production BGP uplink interfaces after they were added successfully.

When finished

Tier-0 BGP configuration with local AS, ECMP, graceful restart, route aggregation, and neighbor controls.

Next we need to configure out BGP neighbor

Set Local AS

NSX-T Tier-0 gateway BGP configuration showing the Set control for BGP neighbors.

Set

Set BGP Neighbors dialog for TX-Prod-T0-01 before any peers are configured.

Add BGP neighbor

Tier-0 BGP-neighbor form with peer IP, remote AS, source address, BFD, graceful restart, and hop-limit fields.

Enter IP address

Remote AS number

Source IP

Tier-0 BGP-neighbor list showing both configured peers in Success status.

Ensure both connections are in successful status

Tier-0 BGP section showing two configured neighbors and unsaved changes ready to save.

Save

Tier-0 route-redistribution section with BGP status enabled and the Set control for adding a rule.

Set

Set Route Re-distribution dialog for TX-Prod-T0-01 before a rule is added.

Add

Tier-0 route-redistribution editor requesting a rule name and opening its route-source selector.

Add a name then clickset

Tier-0 route-source selector for static routes, connected interfaces and segments, and advertised Tier-1 subnets.

Choose your T0 and T1 routes you want to redistribute

Apply

Tier-0 route-redistribution section showing one configured rule, BGP status on, and unsaved changes ready to save.

Save

Keep exploring

Choose your next step

Continue with the path that best matches the architecture or operating challenge in front of you.

Leave a Reply

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading