Product offerings for VMware NSX-T Data Center 3.0.0
search cancel

Product offerings for VMware NSX-T Data Center 3.0.0

book

Article ID: 315188

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

This article provides information on licensing editions of VMware NSX-T and list of features associated with the various licensing editions in VMware NSX-T Data Center 3.0.0.

Environment

VMware NSX-T Data Center 3.x
VMware NSX-T Data Center

Resolution

The new VMware NSX Data Center editions became available to order on June 5th, 2018. The tiers of NSX Data Center licenses are as follows:
  • NSX Data Center Standard Edition: For organizations needing agility and automation of the network.
  • NSX Data Center Professional Edition: For organizations needing Standard, plus micro-segmentation, and may have public cloud endpoints.
  • NSX Data Center Advanced Edition: For organizations needing Professional, plus advanced networking and security services, and may have multiple sites.
  • NSX Data Center Enterprise Plus Edition: For organizations needing the most advanced capabilities NSX Data Center has to offer, plus network visibility and security operations with vRealize Network Insight™, and hybrid cloud mobility with VMware HCX.
  • NSX Data Center for Remote Office Branch Office: For organizations that need to virtualize networking and security for applications in the remote office or branch office.
The following table outlines specific functions available by edition. NSX Data Center is available as a single download image with license keys required to enable specific functionality.
 
FeatureStandardProfessionalAdvancedEnterprise PlusRemote Branch Office
Platform Features
ESXi Support1YesYesYesYesYes
KVM Support2YesYesYesYesNo
Controller ClusteringYesYesYesYesYes
vCenter Integration1YesYesYesYesYes
Multi-vCenter® Networking and SecurityNoNoYesYesNo
FederationNoNoNoYesNo
      
Edge Platform Features     
Edge in VM Form FactorYesYesYesYesYes
Edge in Bare-Metal Form FactorYesYesYesYesNo
DPDK Optimized ForwardingYesYesYesYesYes
      
Switching     
Distributed SwitchingYesYesYesYesNo
VLAN Backed Logical SwitchingYesYesYesYesYes
Overlay Backed Logical SwitchingYesYesYesYesNo
Multiple TEP SupportYesYesYesYesNo
Optimized ARP Learning and Broadcast SuppressionYesYesYesYesNo
GENEVE EncapsulationYesYesYesYesNo
Unicast ReplicationYesYesYesYesNo
Headend ReplicationYesYesYesYesNo
SpoofguardYesYesYesYesNo
LACP (Edge and Host)YesYesYesYesYes
      
Quality of Service (QoS)     
QoS MarkingYesYesYesYesNo
QoS DSCP Trust BoundaryYesYesYesYesNo
      
L2 Bridging to Physical Environment     
Software Based L2 Bridge to Physical EnvironmentsYesYesYesYesNo
      
Routing     
Distributed RoutingYesYesYesYesNo
Multi-Tier RoutingYesYesYesYesNo
Dynamic Routing with ECMPYesYesYesYesNo
Virtual Routing and Forwarding (Tier-0 Gateway VRFs)NoNoYesYesNo
E-VPNNoNoNoYesNo
      
Static Routing - IPv4     
Static RoutingYesYesYesYesYes
BFDYesYesYesYesYes
Null RoutesYesYesYesYesYes
Device RoutesYesYesYesYesYes
      
Static Routing - IPv6     
Static RoutingYesYesYesYesNo
Null RoutesYesYesYesYesNo
Device RoutesYesYesYesYesNo
      
BGP - IPv4 Unicast     
eBGPYesYesYesYesNo
eBGP MultihopYesYesYesYesNo
iBGPYesYesYesYesNo
Graceful RestartYesYesYesYesNo
BFDYesYesYesYesNo
4-byte ASNYesYesYesYesNo
      
BGP - IPv6 Unicast     
eBGPNoNoYesYesNo
eBGP MultihopNoNoYesYesNo
iBGPNoNoYesYesNo
Graceful RestartNoNoYesYesNo
4-byte ASNNoNoYesYesNo
      
BFD - IPv4     
Sub-Second Keepalive TimerYesYesYesYesNo
      
Route Maps     
Match on Prefix-List and Community-ListYesYesYesYesNo
Set Weight, MED, AS Path, Prepending, Local Preference, and CommunityYesYesYesYesNo
      
Other     
High Availability Virtual IP (HA VIP)YesYesYesYesNo
Route RedistributionYesYesYesYesNo
IP Prefix-ListsYesYesYesYesNo
Active / Active RedundancyYesYesYesYesNo
Active / Standby RedundancyYesYesYesYesNo
Per Interface RPF CheckYesYesYesYesNo
      
NAT     
NAT on North/South and East/West Logical RoutersYesYesYesYesYes
Source NATYesYesYesYesYes
Destination NATYesYesYesYesYes
NAT N:NYesYesYesYesYes
Stateless NATYesYesYesYesYes
NAT LoggingYesYesYesYesYes
NAT64NoNoYesYesNo
      
Firewall     
Edge FirewallYesYesYesYesYes
Distributed FirewallingNoYesYesYesYes
Common Firewall User InterfaceYesYesYesYesYes
Firewall SectionsYesYesYesYesYes
Firewall LoggingYesYesYesYesYes
Stateful L2 and L3 RulesYesYesYesYesYes
Stateless L2 and L3 RulesYesYesYesYesYes
Tag Based RulesYesYesYesYesYes
Distributed Firewall based IPFIXNoYesYesYesYes
URL AllowlistsNoNoYesYesNo
      
Identity Firewall     
Identity based Groups using Active DirectoryNoNoYesYesNo
      
NSX Distributed Threat Prevention7     
Distributed IDSNoNoYesYesNo
      
Policy, Tagging and Grouping     
Object Tagging / Security TagsYesYesYesYesYes
Network Centric GroupingYesYesYesYesYes
Workload Centric GroupingYesYesYesYesYes
IP Based GroupsYesYesYesYesYes
MAC Based GroupsYesYesYesYesYes
Intent based Networking and Security PolicyYesYesYesYesYes
      
DNS, DHCP and IPAM (DDI)     
IPAMYesYesYesYesYes
IP BlocksYesYesYesYesYes
IP SubnetsYesYesYesYesYes
IP PoolsYesYesYesYesYes
IPv4 DHCP ServerYesYesYesYesYes
IPv6 DHCP ServerNoNoYesYesNo
IPv4 DHCP RelayYesYesYesYesYes
IPv6 DHCP RelayNoNoYesYesNo
IPv4 DHCP Static Bindings / Fixed AddressesYesYesYesYesYes
IPv6 DHCP Static Bindings / Fixed AddressesNoNoYesYesNo
IPv4 DNS Relay / DNS ProxyYesYesYesYesYes
IPv4 Meta-Data ProxyYesYesYesYesNo
      
Load Balancing8     
Protocols     
TCP (L4-L7)NoNoYesYesYes
UDPNoNoYesYesYes
HTTPNoNoYesYesYes
      
Load Balancing Methods     
Round RobinNoNoYesYesYes
Source IP HashNoNoYesYesYes
Least ConnectionsNoNoYesYesYes
L7 Application Rules with RegEx SupportNoNoYesYesYes
      
Health Checks     
TCPNoNoYesYesYes
ICMPNoNoYesYesYes
UDPNoNoYesYesYes
HTTPNoNoYesYesYes
HTTPSNoNoYesYesYes
      
Monitoring     
View VIP / Pool / Server ObjectsNoNoYesYesYes
View VIP / Pool / Server StatisticsNoNoYesYesYes
View Global Statistics VIP SessionsNoNoYesYesYes
      
Load Balancing Automation     
Pool Members Based on vCenter Context or IP AddressesNoNoYesYesYes
      
Other     
Connection ThrottlingNoNoYesYesYes
High-AvailabilityNoNoYesYesYes
      
API Driven Automation     
REST APIYesYesYesYesYes
Hierarchical Policy APIYesYesYesYesYes
JSON SupportYesYesYesYesYes
OpenAPI / Swagger SpecYesYesYesYesYes
Java SDKYesYesYesYesYes
Python SDKYesYesYesYesYes
Auto-generated API DocumentationYesYesYesYesYes
Terraform Provider6YesYesYesYesYes
Ansible Modules6YesYesYesYesYes
      
Cloud Native and Integration with Cloud Management Platforms     
Container Networking and SecurityNoNoYesYesNo
Integration with vRealize Automation6YesYesYesYesNo
Integration with vCloud Director6YesYesYesYesNo
Integration with VMware Integrated OpenStack1, 6YesYesYesYesNo
Integration with RedHat OpenStack Platform3, 6YesYesYesYesNo
      
Service Insertion Integrations     
Endpoint ProtectionYesYesYesYesYes
Network IntrospectionNoNoYesYesYes
      
NSX Intelligence     
Layer 4 VM-to-VM Traffic Flow AnalysisNoNoNoYesNo
Layer 4 Firewall VisibilityNoNoNoYesNo
Layer 4 Automated Security PolicyNoNoNoYesNo
Layer 4 Rule and Group Recommended AnalyticsNoNoNoYesNo
      
Integration with NSX Cloud for AWS and Azure Support     
NSX on-prem license portability for Public Cloud workloadsNoNoYesYesYes
NSX Enforced Mode (Agent-Based Cloud Security)NoYesYesYesYes
Cloud Enforced Mode (Agentless Based Cloud Security)NoYesYesYesYes
L7 Security Features (AppID, URL Filtering)NoYesYesYesYes
Service InsertionNoYesYesYesYes
NSX Security for VDI workloads on Azure HorizonNoYesYesYesYes
VPN (on-prem to public cloud; public cloud - public cloud; intra public cloud)NoYesYesYesYes
Support for AWS Gov Cloud and Azure Government Cloud WorkloadsNoYesYesYesYes
      
Authentication and Authorization     
Authentication using vIDM1, 5YesYesYesYesYes
Direct Active Directory Integration via LDAPYesYesYesYesYes
Authentication via OpenLDAPYesYesYesYesYes
Session Based AuthenticationYesYesYesYesYes
Certificate Based Authentication (Principle Identity)YesYesYesYesYes
      
Log Management     
vRealize Log Insight Integration1, 4YesYesYesYesYes
Splunk Integration2YesYesYesYesYes
      
Installation     
Automated Controller DeploymentYesYesYesYesYes
Manual Controller DeploymentYesYesYesYesYes
Automated Edge DeploymentYesYesYesYesYes
Manual Edge DeploymentYesYesYesYesYes
Automated Host Preparation by ClusterYesYesYesYesYes
      
Operations     
Port MirroringYesYesYesYesYes
TraceflowYesYesYesYesYes
Tunnel Health MonitoringYesYesYesYesNo
Port Connectivity ToolYesYesYesYesYes
Switch Based IPFIXYesYesYesYesYes
LLDPYesYesYesYesYes
Automated Technical Support BundlesYesYesYesYesYes
Packet CaptureYesYesYesYesYes
Backup and RestoreYesYesYesYesYes
SNMP v1/v2/v3 with Polling and TrapsYesYesYesYesYes
      
Upgrades and Migrations     
Upgrade CoordinatorYesYesYesYesYes
NSX for vSphere to NSX-T Migration CoordinatorYesYesYesYesYes

Notes:

1 Please refer to the VMware Product Interoperability Matrices for specific versions supported with NSX-T Data Center.
2 Please refer to the NSX-T Data Center release notes for specific versions.
3 Please refer to the NSX Data Center partner web site for specific versions.
4 VMware vRealize Log Insight for NSX provides intelligent log analytics for NSX Data Center. Log Insight provides monitoring and troubleshooting capabilities and customizable dashboards for network virtualization, flow analysis, and alerts. VMware vRealize Log Insight version 3.3.2 and later accepts NSX Data Center Standard/ProfessionalAdvanced/Enterprise Plus/ROBO edition license keys issued for NSX-T 1.0.0 and later. This means you will have an enterprise level Log Insight license for every license of NSX Data Center.
5 VMware Identity Manager - A license to use VMware NSX Data Center includes an entitlement to use the VMware Identity Manager feature, but only for the following functionalities:
  • Directory integration functionality of VMware Identity Manager to authenticate users in a user directory such as Microsoft Active Directory or LDAP.
  • Conditional access policy.
  • Single-sign-on integration functionality with third party Identity providers to allow third party identity providers’ users to single-sign-on into NSX Data Center.
  • Two-factor authentication solution through integration with third party systems. VMware Verify, VMware’s multi-factor authentication solution, received as part of VMware Identity Manager, may not be used as part of NSX Data Center.
  • Single-sign-on functionality to access VMware products that support single-sign-on capabilities.
6 Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Data Center  Advanced, Enterprise Plus or ROBO.
NSX Distributed Thread Prevention requires an additional subscription based purchase.
Both IPv4 and IPv6 are supported for all Load Balancing features except for IPv6-VIP-toIPv4-member and IPv4-VIP-to-IPv6-member translations.