Product offerings for VMware NSX-T Data Center 3.0.0
search cancel

Product offerings for VMware NSX-T Data Center 3.0.0


Article ID: 315188


Updated On:


VMware NSX


This article provides information on licensing editions of VMware NSX-T and list of features associated with the various licensing editions in VMware NSX-T Data Center 3.0.0.


VMware NSX-T Data Center 3.x
VMware NSX-T Data Center


The new VMware NSX Data Center editions became available to order on June 5th, 2018. The tiers of NSX Data Center licenses are as follows:
  • NSX Data Center Standard Edition: For organizations needing agility and automation of the network.
  • NSX Data Center Professional Edition: For organizations needing Standard, plus micro-segmentation, and may have public cloud endpoints.
  • NSX Data Center Advanced Edition: For organizations needing Professional, plus advanced networking and security services, and may have multiple sites.
  • NSX Data Center Enterprise Plus Edition: For organizations needing the most advanced capabilities NSX Data Center has to offer, plus network visibility and security operations with vRealize Network Insight™, and hybrid cloud mobility with VMware HCX.
  • NSX Data Center for Remote Office Branch Office: For organizations that need to virtualize networking and security for applications in the remote office or branch office.
The following table outlines specific functions available by edition. NSX Data Center is available as a single download image with license keys required to enable specific functionality.
FeatureStandardProfessionalAdvancedEnterprise PlusRemote Branch Office
Platform Features
ESXi Support1YesYesYesYesYes
KVM Support2YesYesYesYesNo
Controller ClusteringYesYesYesYesYes
vCenter Integration1YesYesYesYesYes
Multi-vCenter® Networking and SecurityNoNoYesYesNo
Edge Platform Features     
Edge in VM Form FactorYesYesYesYesYes
Edge in Bare-Metal Form FactorYesYesYesYesNo
DPDK Optimized ForwardingYesYesYesYesYes
Distributed SwitchingYesYesYesYesNo
VLAN Backed Logical SwitchingYesYesYesYesYes
Overlay Backed Logical SwitchingYesYesYesYesNo
Multiple TEP SupportYesYesYesYesNo
Optimized ARP Learning and Broadcast SuppressionYesYesYesYesNo
GENEVE EncapsulationYesYesYesYesNo
Unicast ReplicationYesYesYesYesNo
Headend ReplicationYesYesYesYesNo
LACP (Edge and Host)YesYesYesYesYes
Quality of Service (QoS)     
QoS MarkingYesYesYesYesNo
QoS DSCP Trust BoundaryYesYesYesYesNo
L2 Bridging to Physical Environment     
Software Based L2 Bridge to Physical EnvironmentsYesYesYesYesNo
Distributed RoutingYesYesYesYesNo
Multi-Tier RoutingYesYesYesYesNo
Dynamic Routing with ECMPYesYesYesYesNo
Virtual Routing and Forwarding (Tier-0 Gateway VRFs)NoNoYesYesNo
Static Routing - IPv4     
Static RoutingYesYesYesYesYes
Null RoutesYesYesYesYesYes
Device RoutesYesYesYesYesYes
Static Routing - IPv6     
Static RoutingYesYesYesYesNo
Null RoutesYesYesYesYesNo
Device RoutesYesYesYesYesNo
BGP - IPv4 Unicast     
eBGP MultihopYesYesYesYesNo
Graceful RestartYesYesYesYesNo
4-byte ASNYesYesYesYesNo
BGP - IPv6 Unicast     
eBGP MultihopNoNoYesYesNo
Graceful RestartNoNoYesYesNo
4-byte ASNNoNoYesYesNo
BFD - IPv4     
Sub-Second Keepalive TimerYesYesYesYesNo
Route Maps     
Match on Prefix-List and Community-ListYesYesYesYesNo
Set Weight, MED, AS Path, Prepending, Local Preference, and CommunityYesYesYesYesNo
High Availability Virtual IP (HA VIP)YesYesYesYesNo
Route RedistributionYesYesYesYesNo
IP Prefix-ListsYesYesYesYesNo
Active / Active RedundancyYesYesYesYesNo
Active / Standby RedundancyYesYesYesYesNo
Per Interface RPF CheckYesYesYesYesNo
NAT on North/South and East/West Logical RoutersYesYesYesYesYes
Source NATYesYesYesYesYes
Destination NATYesYesYesYesYes
NAT N:NYesYesYesYesYes
Stateless NATYesYesYesYesYes
NAT LoggingYesYesYesYesYes
Edge FirewallYesYesYesYesYes
Distributed FirewallingNoYesYesYesYes
Common Firewall User InterfaceYesYesYesYesYes
Firewall SectionsYesYesYesYesYes
Firewall LoggingYesYesYesYesYes
Stateful L2 and L3 RulesYesYesYesYesYes
Stateless L2 and L3 RulesYesYesYesYesYes
Tag Based RulesYesYesYesYesYes
Distributed Firewall based IPFIXNoYesYesYesYes
URL AllowlistsNoNoYesYesNo
Identity Firewall     
Identity based Groups using Active DirectoryNoNoYesYesNo
NSX Distributed Threat Prevention7     
Distributed IDSNoNoYesYesNo
Policy, Tagging and Grouping     
Object Tagging / Security TagsYesYesYesYesYes
Network Centric GroupingYesYesYesYesYes
Workload Centric GroupingYesYesYesYesYes
IP Based GroupsYesYesYesYesYes
MAC Based GroupsYesYesYesYesYes
Intent based Networking and Security PolicyYesYesYesYesYes
DNS, DHCP and IPAM (DDI)     
IP BlocksYesYesYesYesYes
IP SubnetsYesYesYesYesYes
IP PoolsYesYesYesYesYes
IPv4 DHCP ServerYesYesYesYesYes
IPv6 DHCP ServerNoNoYesYesNo
IPv4 DHCP RelayYesYesYesYesYes
IPv6 DHCP RelayNoNoYesYesNo
IPv4 DHCP Static Bindings / Fixed AddressesYesYesYesYesYes
IPv6 DHCP Static Bindings / Fixed AddressesNoNoYesYesNo
IPv4 DNS Relay / DNS ProxyYesYesYesYesYes
IPv4 Meta-Data ProxyYesYesYesYesNo
Load Balancing8     
TCP (L4-L7)NoNoYesYesYes
Load Balancing Methods     
Round RobinNoNoYesYesYes
Source IP HashNoNoYesYesYes
Least ConnectionsNoNoYesYesYes
L7 Application Rules with RegEx SupportNoNoYesYesYes
Health Checks     
View VIP / Pool / Server ObjectsNoNoYesYesYes
View VIP / Pool / Server StatisticsNoNoYesYesYes
View Global Statistics VIP SessionsNoNoYesYesYes
Load Balancing Automation     
Pool Members Based on vCenter Context or IP AddressesNoNoYesYesYes
Connection ThrottlingNoNoYesYesYes
API Driven Automation     
Hierarchical Policy APIYesYesYesYesYes
JSON SupportYesYesYesYesYes
OpenAPI / Swagger SpecYesYesYesYesYes
Java SDKYesYesYesYesYes
Python SDKYesYesYesYesYes
Auto-generated API DocumentationYesYesYesYesYes
Terraform Provider6YesYesYesYesYes
Ansible Modules6YesYesYesYesYes
Cloud Native and Integration with Cloud Management Platforms     
Container Networking and SecurityNoNoYesYesNo
Integration with vRealize Automation6YesYesYesYesNo
Integration with vCloud Director6YesYesYesYesNo
Integration with VMware Integrated OpenStack1, 6YesYesYesYesNo
Integration with RedHat OpenStack Platform3, 6YesYesYesYesNo
Service Insertion Integrations     
Endpoint ProtectionYesYesYesYesYes
Network IntrospectionNoNoYesYesYes
NSX Intelligence     
Layer 4 VM-to-VM Traffic Flow AnalysisNoNoNoYesNo
Layer 4 Firewall VisibilityNoNoNoYesNo
Layer 4 Automated Security PolicyNoNoNoYesNo
Layer 4 Rule and Group Recommended AnalyticsNoNoNoYesNo
Integration with NSX Cloud for AWS and Azure Support     
NSX on-prem license portability for Public Cloud workloadsNoNoYesYesYes
NSX Enforced Mode (Agent-Based Cloud Security)NoYesYesYesYes
Cloud Enforced Mode (Agentless Based Cloud Security)NoYesYesYesYes
L7 Security Features (AppID, URL Filtering)NoYesYesYesYes
Service InsertionNoYesYesYesYes
NSX Security for VDI workloads on Azure HorizonNoYesYesYesYes
VPN (on-prem to public cloud; public cloud - public cloud; intra public cloud)NoYesYesYesYes
Support for AWS Gov Cloud and Azure Government Cloud WorkloadsNoYesYesYesYes
Authentication and Authorization     
Authentication using vIDM1, 5YesYesYesYesYes
Direct Active Directory Integration via LDAPYesYesYesYesYes
Authentication via OpenLDAPYesYesYesYesYes
Session Based AuthenticationYesYesYesYesYes
Certificate Based Authentication (Principle Identity)YesYesYesYesYes
Log Management     
vRealize Log Insight Integration1, 4YesYesYesYesYes
Splunk Integration2YesYesYesYesYes
Automated Controller DeploymentYesYesYesYesYes
Manual Controller DeploymentYesYesYesYesYes
Automated Edge DeploymentYesYesYesYesYes
Manual Edge DeploymentYesYesYesYesYes
Automated Host Preparation by ClusterYesYesYesYesYes
Port MirroringYesYesYesYesYes
Tunnel Health MonitoringYesYesYesYesNo
Port Connectivity ToolYesYesYesYesYes
Switch Based IPFIXYesYesYesYesYes
Automated Technical Support BundlesYesYesYesYesYes
Packet CaptureYesYesYesYesYes
Backup and RestoreYesYesYesYesYes
SNMP v1/v2/v3 with Polling and TrapsYesYesYesYesYes
Upgrades and Migrations     
Upgrade CoordinatorYesYesYesYesYes
NSX for vSphere to NSX-T Migration CoordinatorYesYesYesYesYes


1 Please refer to the VMware Product Interoperability Matrices for specific versions supported with NSX-T Data Center.
2 Please refer to the NSX-T Data Center release notes for specific versions.
3 Please refer to the NSX Data Center partner web site for specific versions.
4 VMware vRealize Log Insight for NSX provides intelligent log analytics for NSX Data Center. Log Insight provides monitoring and troubleshooting capabilities and customizable dashboards for network virtualization, flow analysis, and alerts. VMware vRealize Log Insight version 3.3.2 and later accepts NSX Data Center Standard/ProfessionalAdvanced/Enterprise Plus/ROBO edition license keys issued for NSX-T 1.0.0 and later. This means you will have an enterprise level Log Insight license for every license of NSX Data Center.
5 VMware Identity Manager - A license to use VMware NSX Data Center includes an entitlement to use the VMware Identity Manager feature, but only for the following functionalities:
  • Directory integration functionality of VMware Identity Manager to authenticate users in a user directory such as Microsoft Active Directory or LDAP.
  • Conditional access policy.
  • Single-sign-on integration functionality with third party Identity providers to allow third party identity providers’ users to single-sign-on into NSX Data Center.
  • Two-factor authentication solution through integration with third party systems. VMware Verify, VMware’s multi-factor authentication solution, received as part of VMware Identity Manager, may not be used as part of NSX Data Center.
  • Single-sign-on functionality to access VMware products that support single-sign-on capabilities.
6 Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Data Center  Advanced, Enterprise Plus or ROBO.
NSX Distributed Thread Prevention requires an additional subscription based purchase.
Both IPv4 and IPv6 are supported for all Load Balancing features except for IPv6-VIP-toIPv4-member and IPv4-VIP-to-IPv6-member translations.