Diagram of Example Workflow.

VMware NSX-T Security War Games: Testing, Training, and Improving Response Readiness

Introduction Modern enterprise networks face relentless threats from ransomware, insider attacks, and increasingly sophisticated breaches. With the shift to hybrid and multi-cloud architectures, software-defined networking (SDN) platforms like VMware NSX-T are now critical for defense, detection, and rapid containment. Security war games, structured exercises using real-world attack and response scenarios, are the gold standard for … Explore: VMware NSX-T Security War Games: Testing, Training, and…

AI-enhanced SDN policy enforcement and compliance graphic for hybrid environments.

How AI Can Enhance SDN Policy Enforcement and Compliance in Hybrid Environments

Introduction In the evolving landscape of hybrid IT, the fusion of Software-Defined Networking (SDN) with artificial intelligence (AI) is transforming how organizations enforce network policies and maintain compliance. Modern network architects and security admins are expected to manage distributed resources across Azure Local SDN and on-premises infrastructure, often under the weight of strict regulatory requirements. … Explore: How AI Can Enhance SDN Policy Enforcement and…

NSG flow logging graphic with Microsoft Sentinel integration for packet monitoring.

Logging Every Packet: NSG Flow Logs and Integration with Microsoft Sentinel

Introduction In the evolving landscape of cloud security, network visibility is more critical than ever. As enterprises adopt hybrid and cloud-native architectures, understanding east-west and north-south traffic becomes essential for both operational insight and threat detection. In Microsoft Azure, Network Security Group (NSG) Flow Logs offer powerful telemetry by logging metadata about network traffic traversing … Explore: Logging Every Packet: NSG Flow Logs and Integration…

Digital Thought Disruption

Azure Local vs VMware Cloud Foundation vs Nutanix: A 2026 Executive Decision Framework

Choosing a private or hybrid-cloud platform is not a hypervisor feature contest. It is a decision about the operating model your organization can sustain for the next five years: how infrastructure is purchased, governed, upgraded, secured, recovered, and delivered to application teams. Azure Local, VMware Cloud Foundation, and Nutanix can all run important enterprise workloads. … Explore: Azure Local vs VMware Cloud Foundation vs Nutanix:…

NSX-T Set BGP Neighbors panel showing zero neighbors and the Add BGP Neighbor control.

Create Stretched Tier-0 Gateway in VMware NSX-T Federation

It is time to deploy a Stretched Tier-0 Gateway First we need to log into the Primary Global Manager Networking > Conenectivity > Segments ADD SEGMENT Name the Segment – I recommend putting something to indicate stretched uplink Choose the primary location and the primary VLAN Transport Zone Provide the VLAN ID and save No … Explore: Create Stretched Tier-0 Gateway in VMware NSX-T Federation

NSX-T Local Manager actions menu with the Import to GM command selected.

Importing Objects from Local Manager into Global Manager VMware NSX-T Federation

To continue from where the previous article left off we will now import objects to the Global Managers Pre-Req: Check the status on all of your T0 GWs, T1 GWs, and segments  Time to import Location 1’s Objects Log into your Primary Site NSX-T Global Manager System > Configuration > Location Manager Under your Primary … Explore: Importing Objects from Local Manager into Global Manager…

Global Manager location view confirming the Dallas Local Manager import and showing its Networking tab.

Configuring RTEPs in VMware NSX-T Federation

In this article I will cover creating an RTEP for Local 1 and Local 2 and validating the RTEP status. Creating the RTEP for Location 1 – Example Dallas System > Configuration > Location Manager > Locations > Location-1 LM (Dallas) > NETWORKING Click CONFIGURE on the RTEP cluster you’ve already created Select your edge … Explore: Configuring RTEPs in VMware NSX-T Federation

Primary Global Manager Tier-1 Gateways page before creating the Dallas-Fort Worth stretched Tier-1 gateway.

Create Stretched Networks in VMware NSX-T Federation

First lets create Tier-1 GW to provide connectivity between Location-1 and Location 2 (Dallas/FortWorth) through RTEP In your primary Global Manager go to Networking > Connectivity > Tier-1 Gateways Add Tier-1 GW Provide a name.  I recommend putting something in the name to indicate this is a stretched T1 Keep failover to Non-Preemptive In Edges … Explore: Create Stretched Networks in VMware NSX-T Federation

NSX-T segment editor configuring a VLAN transport-zone trunk segment for VRF Lite gateway uplinks.

How to Deploy a VRF Lite Gateway in VMware NSX-T 3.2

A virtual routing and forwarding (VRF) gateway makes it possible for multiple instances of a routing table to exist within the same gateway at the same time. VRFs are the layer 3 equivalent of a VLAN. A VRF gateway must be linked to a tier-0 gateway. From the tier-0 gateway, the VRF gateway inherits the … Explore: How to Deploy a VRF Lite Gateway in…

NSX-T Global Manager system page with controls to make the appliance active and add a standby manager.

Configuring Global Managers and Local Managers in VMware NSX-T Federation

In this article I will cover setting up your first two Global Managers and adding the local managers from your sites. Log into the newly deployed Global Manager System > Configuration > location Manager Make Active Provide the name of your Global Manager Confirm the GM is active SSH into the Global Manager Run the … Explore: Configuring Global Managers and Local Managers in VMware…

NSX-T Tier-1 Gateways page before a production Tier-1 gateway is created.

How to Deploy a VMware NSX-T 3.2 Tier-1 Gateway (T1 GW)

Tier-1 Gateway (also known as Tier-1 Logical Router): provides default gateway services for VMs attached to segments. It connects to one tier-0 gateway for northbound connectivity and one or more overlay networks for southbound connectivity. Both types of gateways can include a distributed router (DR) and a service router (SR). Distributed routers are instantiated on … Explore: How to Deploy a VMware NSX-T 3.2 Tier-1…

NSX-T Segments page showing existing application segments before the Tier-0 uplink VLAN segments are created.

How to Deploy a VMware NSX-T 3.2 Tier-0 Gateway (T0 GW)

Tier-0 Gateway (also known as Tier-0 Logical Router): interfaces with the physical network and exchange routing information with external routers via static routing or eBGP. In active-standby mode, the gateway can also provide stateful services. The Tier-0 router performs gateway services between overlay and non-overlay hosts (for example, a physical server or the Internet router). … Explore: How to Deploy a VMware NSX-T 3.2 Tier-0…

Welcome screen for the VMware Tanzu Kubernetes Grid Installer with management-cluster deployment options.

Deploy VMware Tanzu Kubernetes Grid

Once you have reached the welcome page you will have options For this example we will be deploying Tanzu on a vCF environment so click deploy under vSphere Next enter in your vCenter server name Username/password for your admin account Then click connect to confirm you can connect Deploy TKG Management Cluster Select your Data … Explore: Deploy VMware Tanzu Kubernetes Grid

NSX-T Segments page before the first production overlay segment is added.

How to Create a Segment in VMware NSX-T 3.2

A segment performs the functions of a logical switch. A segment gives tenant network administrators the logical equivalent of a physical Layer 2 switch, allowing them to connect a set of VMs to a common broadcast domain. A segment is a logical entity independent of the physical hypervisor infrastructure and spans many hypervisors, connecting VMs … Explore: How to Create a Segment in VMware NSX-T…

NSX-T Edge Transport Nodes page with the control for adding a new edge node.

How to deploy VMware NSX-T 3.2 Edge Node & Edge Cluster

NSX-T Edge nodes provide routing services and connectivity to networks that are external to the NSX-T deployment. NSX-T Edges are required for establishing external connectivity from the NSX-T domain, through a Tier-0 router over BGP or static routing. Additionally, you must deploy an NSX-T Edge for stateful services at either the Tier-0 or Tier-1 logical … Explore: How to deploy VMware NSX-T 3.2 Edge Node…

NSX-T Global Manager Groups inventory before any global groups have been created.

Configure Global Policies in VMware NSX-T Federation

In this article I will cover creating Global Groups in NSX-T Federation.  Then we will create a policy and a rule to test web traffic in order to show that the new policy/rule applies at both site locations. Log into the Global Manager In the primary global manager go to Inventory > Groups Add Group … Explore: Configure Global Policies in VMware NSX-T Federation

NSX-T Users and Roles LDAP page where an Active Directory identity source can be added.

How to Add AD/LDAP to VMware NSX-T 3.2

NSX-T-T now allows LDAP/AD as an alternative to using the VMware identity manager solution.  This is perfect for environments that only need to control authentication of the NSX-T environment. When integrating with Active Directory, NSX Manager allows users to log in using their samAccountName, or userPrincipalName. If the @domain portion of the userPrincipalName does not match the … Explore: How to Add AD/LDAP to VMware NSX-T 3.2

NSX-T URL Analysis landing page explaining north-south URL visibility and the need to assign a profile to an edge cluster.

VMware NSX-T 3.2 Analyzing URL Traffic

FQDN Analysis allows administrators to gain insight into the type of websites accessed within the organization, and understand the reputation and risk of the accessed websites. How to configure: Security > North South Security > URL Analysis You need to enable the service which is disabled by default Highlight your edge and click enable Yes … Explore: VMware NSX-T 3.2 Analyzing URL Traffic

NSX-T Host Transport Nodes page used to select the vCenter-managed ESXi cluster for preparation.

Prepare ESXi Hosts to Join VMware NSX-T 3.2

A transport node is a node that is capable of participating in an NSX-T Data Center overlay or NSX-T Data Center VLAN networking. Any node can serve as a transport node if it contains an N-VDS. Such nodes include but are not limited to NSX Edges. How to Prepare ESXi Hosts System > Configuration > … Explore: Prepare ESXi Hosts to Join VMware NSX-T 3.2

NSX-T IP Address Pools page with the control for adding a TEP address pool.

How to Create TEP IP Pool VMware NSX-T 3.2

The Tunnel endpoint (TEP) enables Transport nodes to participate in an NSX-T overlay. The NSX-T overlay deploys a Layer 2 network on top of an existing Layer 3 network fabric by encapsulating frames inside packets and transferring the packets over an underlying transport network. The underlying transport network can be another Layer 2 network, or … Explore: How to Create TEP IP Pool VMware NSX-T…