Migration graphic showing VMware NSX-T moving to Azure Local SDN.

From VMware NSX-T to Azure Local SDN: Migration Planning and Gotchas

TL;DR – Quick Summary Introduction: The SDN Shift Is Underway In today’s cloud-first, software-defined datacenter landscape, network virtualization is no longer optional. VMware NSX-T has long been the go-to solution for enterprises seeking microsegmentation and programmable network constructs — but the landscape is changing fast. With recent licensing uncertainty following Broadcom’s acquisition of VMware and … Explore: From VMware NSX-T to Azure Local SDN: Migration…

Azure Local SDN deployment mistakes graphic highlighting ten common issues and fixes.

Top 10 Mistakes Made in Azure Local SDN Deployments (And How to Fix Them)

In the evolving world of hybrid cloud infrastructure, Azure Local (formerly Azure Stack HCI) with SDN provides enterprises with scalable, policy-driven network virtualization. Yet, many Azure architects and IT administrators face significant challenges when deploying these SDN environments. This article outlines the top 10 most common mistakes in Azure Local SDN deployments and provides actionable … Explore: Top 10 Mistakes Made in Azure Local SDN…

Azure Local SDN hybrid networking graphic.

Why Azure Local SDN is the Future of Hybrid Networking

Introduction In today’s enterprise landscape, the demand for agile, secure, and scalable hybrid connectivity is accelerating. As organizations move to adopt multi-cloud strategies, connect edge environments, and integrate legacy infrastructure with modern workloads, traditional networking models are showing their age. VLANs, static routes, and manual IP management simply can’t keep pace with the dynamic requirements … Explore: Why Azure Local SDN is the Future of…

Multi-site Azure Local SDN routing graphic with BGP, gateway pools, and software load balancing.

Multi-Site Azure Local SDN: Routing Between Sites with BGP, Gateway Pools, and SLB

Introduction In today’s hybrid cloud world, organizations often operate across multiple sites — from on-prem data centers to edge locations — while requiring seamless, secure, and scalable network connectivity. Azure Local SDN (formerly Azure Stack HCI SDN) enables powerful software-defined networking capabilities across these distributed environments. When operating across multiple locations, routing between sites becomes … Explore: Multi-Site Azure Local SDN: Routing Between Sites with…

Azure Local SDN capacity planning graphic for NIC teams, SLB limits, and virtual switch scaling.

Capacity Planning for Azure Local SDN: NIC Teams, SLB Limits, vSwitch Scaling

Summary In the evolving landscape of hybrid cloud, capacity planning is critical for deploying resilient and high-performance Software Defined Networking (SDN) infrastructures. Azure Local SDN (formerly Azure Stack HCI) enables enterprise-grade connectivity on-premises while integrating with the broader Azure ecosystem. This article dives deep into how to plan capacity for Azure Local SDN deployments, covering … Explore: Capacity Planning for Azure Local SDN: NIC Teams,…

NSG flow logging graphic with Microsoft Sentinel integration for packet monitoring.

Logging Every Packet: NSG Flow Logs and Integration with Microsoft Sentinel

Introduction In the evolving landscape of cloud security, network visibility is more critical than ever. As enterprises adopt hybrid and cloud-native architectures, understanding east-west and north-south traffic becomes essential for both operational insight and threat detection. In Microsoft Azure, Network Security Group (NSG) Flow Logs offer powerful telemetry by logging metadata about network traffic traversing … Explore: Logging Every Packet: NSG Flow Logs and Integration…

Zero Trust architecture graphic built on Azure Local SDN.

Building a Zero Trust Architecture on Azure Local SDN

Introduction Zero Trust Architecture (ZTA) has become a cornerstone of modern enterprise security. Unlike traditional perimeter-based models, Zero Trust assumes that no network—internal or external—is inherently trustworthy. Instead, it mandates verification at every level: user, device, workload, and network segment. In this article, we explore how to build a Zero Trust Architecture using Azure Local … Explore: Building a Zero Trust Architecture on Azure Local…

Azure Local SDN ACL configuration graphic for scenarios and caveats.

Azure Local SDN ACLs: Scenarios, Configs, Caveats

Introduction As organizations modernize their datacenters using Azure Local SDN (formerly Azure Stack HCI), granular network segmentation becomes critical for ensuring security and compliance. Access Control Lists (ACLs) offer a powerful mechanism to filter traffic at the virtual switch layer, enabling enforcement of fine-grained controls on east-west and north-south communications. This article dives deep into … Explore: Azure Local SDN ACLs: Scenarios, Configs, Caveats

Azure Local SDN networking graphic comparing VLAN and VXLAN traffic handling.

How Azure Local SDN Handles VLANs and VXLANs: What Every Network Admin Must Know

Introduction In the evolving world of hybrid and on-prem data centers, Azure Local SDN (formerly Azure Stack HCI SDN) has emerged as a critical component for achieving secure, scalable, and policy-driven networking. As more enterprises modernize their infrastructure, understanding how Azure Local SDN leverages VLANs and VXLANs becomes essential for network administrators tasked with architecting … Explore: How Azure Local SDN Handles VLANs and VXLANs:…

Azure Arc hybrid governance graphic extending Azure network control to on-premises infrastructure.

Extend Azure Network Governance to On-Prem with Azure Arc: Unified Hybrid Cloud Control

TL;DR:Azure Arc extends Microsoft’s powerful cloud-native networking tools—like Azure Network Manager, Policy, and Monitor—to your on-premises datacenter. This blog breaks down how Arc enables centralized network governance, visibility, and policy enforcement across hybrid environments using a single control plane. Includes architecture diagrams, real-world examples, and best practices. Introduction: The Hybrid Networking Challenge Many enterprises are … Explore: Extend Azure Network Governance to On-Prem with Azure…

End-to-end Azure Local SDN setup graphic for virtual networks, gateways, software load balancing, and NSGs.

End-to-End Setup: Create Azure Local Virtual Network, Gateway, SLB, and NSGs from Scratch

Introduction Azure Local, formerly known as Azure Stack HCI, has evolved into a robust hybrid cloud platform that brings Azure capabilities to your datacenter. With its Software Defined Networking (SDN) features, administrators can deploy secure, scalable, and automated network infrastructures that mirror Azure’s public cloud constructs—right on-premises. This guide provides an end-to-end walkthrough of how … Explore: End-to-End Setup: Create Azure Local Virtual Network, Gateway,…

Azure Local SDN Layer 4 load-balancing graphic comparing internal and external SLB configurations.

Layer 4 Load Balancing with Azure Local SDN: Internal vs External SLB Configurations

Introduction As hybrid cloud continues to dominate IT strategy, many enterprises are turning to Microsoft Azure Local SDN (formerly Azure Stack HCI) to extend cloud-native networking into their datacenters. One key capability is Layer 4 load balancing, delivered via Software Load Balancer (SLB) services. But not all SLBs are created equal—understanding the distinction between Internal … Explore: Layer 4 Load Balancing with Azure Local SDN:…

Azure Local SDN automation graphic using PowerShell, Windows Admin Center, and Bicep.

Automating Azure Local SDN with PowerShell, WAC, and Bicep: Step‑by‑Step Guide

TL;DR Introduction Azure Local SDN (formerly Azure Stack HCI SDN) introduces software-defined networking to on-premises infrastructure. As enterprises seek agility and consistent governance across hybrid environments, automating the configuration and management of SDN becomes essential. Using PowerShell, Windows Admin Center (WAC), and Bicep together allows infrastructure teams to move away from manual provisioning and toward … Explore: Automating Azure Local SDN with PowerShell, WAC, and…

Compliance-first Azure Local SDN network design graphic.

Compliance-First Network Design for Azure Local SDN

TL;DR / Quick Summary Enterprises adopting Azure Local SDN (formerly Azure Stack HCI) must embed regulatory compliance directly into their network design to reduce risk, meet audit requirements, and ensure secure multi-tenant and hybrid workloads. This article outlines key architecture patterns, configuration strategies, and enforcement mechanisms aligned with major compliance frameworks like NIST, ISO 27001, … Explore: Compliance-First Network Design for Azure Local SDN

Azure Local NSG rules graphic for microsegmentation and traffic isolation.

NSG Rules in Azure Local: Best Practices for Microsegmentation and Traffic Isolation

TL;DR (Quick Summary) Azure Local NSGs (Network Security Groups) provide a critical foundation for securing hybrid environments. By implementing microsegmentation and traffic isolation, administrators can enforce fine-grained controls over east-west and north-south traffic. This article offers best practices, PowerShell and Bicep examples, and real-world scenarios to strengthen your Azure Local SDN security posture. Introduction In … Explore: NSG Rules in Azure Local: Best Practices for…

NSX-T Set BGP Neighbors panel showing zero neighbors and the Add BGP Neighbor control.

Create Stretched Tier-0 Gateway in VMware NSX-T Federation

It is time to deploy a Stretched Tier-0 Gateway First we need to log into the Primary Global Manager Networking > Conenectivity > Segments ADD SEGMENT Name the Segment – I recommend putting something to indicate stretched uplink Choose the primary location and the primary VLAN Transport Zone Provide the VLAN ID and save No … Explore: Create Stretched Tier-0 Gateway in VMware NSX-T Federation

NSX-T Local Manager actions menu with the Import to GM command selected.

Importing Objects from Local Manager into Global Manager VMware NSX-T Federation

To continue from where the previous article left off we will now import objects to the Global Managers Pre-Req: Check the status on all of your T0 GWs, T1 GWs, and segments  Time to import Location 1’s Objects Log into your Primary Site NSX-T Global Manager System > Configuration > Location Manager Under your Primary … Explore: Importing Objects from Local Manager into Global Manager…

Global Manager location view confirming the Dallas Local Manager import and showing its Networking tab.

Configuring RTEPs in VMware NSX-T Federation

In this article I will cover creating an RTEP for Local 1 and Local 2 and validating the RTEP status. Creating the RTEP for Location 1 – Example Dallas System > Configuration > Location Manager > Locations > Location-1 LM (Dallas) > NETWORKING Click CONFIGURE on the RTEP cluster you’ve already created Select your edge … Explore: Configuring RTEPs in VMware NSX-T Federation

Primary Global Manager Tier-1 Gateways page before creating the Dallas-Fort Worth stretched Tier-1 gateway.

Create Stretched Networks in VMware NSX-T Federation

First lets create Tier-1 GW to provide connectivity between Location-1 and Location 2 (Dallas/FortWorth) through RTEP In your primary Global Manager go to Networking > Connectivity > Tier-1 Gateways Add Tier-1 GW Provide a name.  I recommend putting something in the name to indicate this is a stretched T1 Keep failover to Non-Preemptive In Edges … Explore: Create Stretched Networks in VMware NSX-T Federation

NSX-T segment editor configuring a VLAN transport-zone trunk segment for VRF Lite gateway uplinks.

How to Deploy a VRF Lite Gateway in VMware NSX-T 3.2

A virtual routing and forwarding (VRF) gateway makes it possible for multiple instances of a routing table to exist within the same gateway at the same time. VRFs are the layer 3 equivalent of a VLAN. A VRF gateway must be linked to a tier-0 gateway. From the tier-0 gateway, the VRF gateway inherits the … Explore: How to Deploy a VRF Lite Gateway in…