VMware NSX-T 3.x
VMware NSX 4.x
The following table outlines specific functions available by edition. NSX Data Center is available as a single download image with license keys required to enable specific functionality.
NSX Editions (Sold May 2016 - June 2018) | NSX Data Center Editions | |||||||
---|---|---|---|---|---|---|---|---|
Feature |
Standard | Advanced | Enterprise |
Standard |
Professional |
Advanced |
Enterprise Plus |
Remote Office / Branch Office |
Platform Features | ||||||||
vSphere Distributed Switch | Yes | Yes | Yes | Yes | Yes | |||
ESXi Support1 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
KVM Support2 | No | No | No | Yes | Yes | Yes | Yes | No |
Controller Clustering | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
vCenter Integration1 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Multi-vCenter® Networking and Security | No | No | Yes | No | No | Yes | Yes | No |
Federation | No | No | No | No | No | No | Yes | No |
Edge Platform Features | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Edge in VM Form Factor | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Edge in Bare-Metal Form Factor | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
DPDK Optimized Forwarding | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Switching | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
vSphere Distributed Switch¹⁰ | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Distributed Switching | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
VLAN Backed Logical Switching | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Overlay Backed Logical Switching | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Multiple TEP Support | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Optimized ARP Learning and Broadcast Suppression | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
GENEVE Encapsulation | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Unicast Replication | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Headend Replication | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Spoofguard | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
LACP (Edge and Host) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
L2 Multicast | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
L3 Multicast | No | Yes | Yes | No | No | Yes | Yes | No |
Quality of Service (QoS) | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
QoS Marking | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
QoS DSCP Trust Boundary | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
L2 Bridging to Physical Environment | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Software Based L2 Bridge to Physical Environments | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Routing | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Distributed Routing | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Multi-Tier Routing | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Dynamic Routing with ECMP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Virtual Routing and Forwarding (Tier-0 Gateway VRFs) | No | Yes | Yes | No | No | Yes | Yes | No |
E-VPN | No | No | Yes | No | No | No | Yes | No |
Static Routing - IPv4 | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Static Routing | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
BFD | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Null Routes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Device Routes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Static Routing - IPv6 | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Static Routing | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Null Routes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Device Routes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
BGP - IPv4 Unicast | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
eBGP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
eBGP Multihop | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
iBGP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Graceful Restart | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
BFD | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
4-byte ASN | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
BGP - IPv6 Unicast | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
eBGP | No | Yes | Yes | No | No | Yes | Yes | No |
eBGP Multihop | No | Yes | Yes | No | No | Yes | Yes | No |
iBGP | No | Yes | Yes | No | No | Yes | Yes | No |
Graceful Restart | No | Yes | Yes | No | No | Yes | Yes | No |
4-byte ASN | No | Yes | Yes | No | No | Yes | Yes | No |
BFD - IPv4 | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Sub-Second Keepalive Timer | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Route Maps | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Match on Prefix-List and Community-List | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Set Weight, MED, AS Path, Prepending, Local Preference, and Community | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Other | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
High Availability Virtual IP (HA VIP) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Route Redistribution | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
IP Prefix-Lists | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Active / Active Redundancy | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Active / Standby Redundancy | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
No |
Per Interface RPF Check | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
NAT | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
NAT on North/South and East/West Logical Routers | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Source NAT | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Destination NAT | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
NAT N:N | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Stateless NAT | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
NAT Logging | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
NAT64 | No | Yes | Yes | No | No | Yes | Yes | No |
Firewall | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Edge Firewall | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Distributed Firewalling | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Common Firewall User Interface | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Firewall Sections | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Firewall Logging | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Stateful L2 and L3 Rules | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Stateless L2 and L3 Rules | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Tag Based Rules | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Distributed Firewall based IPFIX | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Distributed FQDN Whitelisting | No | No | Yes | No | No | Yes | Yes | No |
L7 Application Identification Rules | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Agent-Based enforcement for Physical Servers | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Identity Firewall | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Identity based Groups using Active Directory | No | Yes | Yes | No | No | Yes | Yes | No |
NSX Distributed Threat Prevention7 | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Distributed IDS | No | Yes | Yes | No | No | Yes | Yes | No |
Distributed IPS | No | Yes | Yes | No | No | Yes | Yes | No |
Policy, Tagging and Grouping | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Object Tagging / Security Tags | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Network Centric Grouping | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Workload Centric Grouping | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IP Based Groups | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
MAC Based Groups | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Intent based Networking and Security Policy | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
DNS, DHCP and IPAM (DDI) | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
IPAM | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IP Blocks | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IP Subnets | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IP Pools | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPv4 DHCP Server | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPv6 DHCP Server | No | Yes | Yes | No | No | Yes | Yes | No |
IPv4 DHCP Relay | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPv6 DHCP Relay | No | Yes | Yes | No | No | Yes | Yes | No |
IPv4 DHCP Static Bindings / Fixed Addresses | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPv6 DHCP Static Bindings / Fixed Addresses | No | Yes | Yes | No | No | Yes | Yes | No |
IPv4 DNS Relay / DNS Proxy | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
IPv4 Meta-Data Proxy | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Load Balancing8 | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Protocols | ||||||||
TCP (L4-L7) | No | Yes | Yes | No | No | Yes | Yes | Yes |
UDP | No | Yes | Yes | No | No | Yes | Yes | Yes |
HTTP | No | Yes | Yes | No | No | Yes | Yes | Yes |
Load Balancing Methods | ||||||||
Round Robin | No | Yes | Yes | No | No | Yes | Yes | Yes |
Source IP Hash | No | Yes | Yes | No | No | Yes | Yes | Yes |
Least Connections | No | Yes | Yes | No | No | Yes | Yes | Yes |
L7 Application Rules with RegEx Support | No | Yes | Yes | No | No | Yes | Yes | Yes |
VPN | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
L2 VPN | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
L3 VPN | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Health Checks | ||||||||
TCP | No | Yes | Yes | No | No | Yes | Yes | Yes |
ICMP | No | Yes | Yes | No | No | Yes | Yes | Yes |
UDP | No | Yes | Yes | No | No | Yes | Yes | Yes |
HTTP | No | Yes | Yes | No | No | Yes | Yes | Yes |
HTTPS | No | Yes | Yes | No | No | Yes | Yes | Yes |
Monitoring | ||||||||
View VIP / Pool / Server Objects | No | Yes | Yes | No | No | Yes | Yes | Yes |
View VIP / Pool / Server Statistics | No | Yes | Yes | No | No | Yes | Yes | Yes |
View Global Statistics VIP Sessions | No | Yes | Yes | No | No | Yes | Yes | Yes |
Load Balancing Automation | ||||||||
Pool Members Based on vCenter Context or IP Addresses | No | Yes | Yes | No | No | Yes | Yes | Yes |
Other | ||||||||
Connection Throttling | No | Yes | Yes | No | No | Yes | Yes | Yes |
High-Availability | No | Yes | Yes | No | No | Yes | Yes | Yes |
API Driven Automation | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
REST API | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Hierarchical Policy API | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
JSON Support | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
OpenAPI / Swagger Spec | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Java SDK | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Python SDK | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Auto-generated API Documentation | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Terraform Provider6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Ansible Modules6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Cloud Native and Integration with Cloud Management Platforms | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Container Networking and Security | No | Yes | Yes | No | No | Yes | Yes | No |
Integration with vRealize Automation1,6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Integration with vCloud Director1,6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Integration with VMware Integrated OpenStack1,6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Integration with other OpenStack Platform3, 6 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Service Insertion Integrations | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Endpoint Protection | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Network Introspection | No | Yes | Yes | No | No | Yes | Yes | Yes |
NSX Intelligence | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Layer 4 VM-to-VM Traffic Flow Analysis | No | No | No | No | No | No | Yes | No |
Layer 4 Firewall Visibility | No | No | No | No | No | No | Yes | No |
Layer 4 Automated Security Policy | No | No | No | No | No | No | Yes | No |
Layer 4 Rule and Group Recommendation Analytics | No | No | No | No | No | No | Yes | No |
Integration with NSX Cloud for AWS and Azure Support | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
NSX on-prem license portability for Public Cloud workloads | No | Yes | Yes | No | No | Yes | Yes | Yes |
NSX Enforced Mode (Agent-Based Cloud Security) | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Cloud Enforced Mode (Agentless Based Cloud Security) | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
L7 Security Features (AppID, URL Filtering) | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Service Insertion | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
NSX Security for VDI workloads on Azure Horizon | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
VPN (on-prem to public cloud; public cloud - public cloud; intra public cloud) | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Support for AWS Gov Cloud and Azure Government Cloud workloads | No | Yes | Yes | No | Yes | Yes | Yes | Yes |
Authentication and Authorization | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Authentication using Workspace ONE Access1, 5 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Direct Active Directory Integration via LDAP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Authentication via OpenLDAP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Session Based Authentication | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Certificate Based Authentication (Principle Identity) | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Role Based Access Control | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Log Management | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
vRealize Log Insight Integration1, 4 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Splunk Integration2 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Installation | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Automated Controller Deployment | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Manual Controller Deployment | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Automated Edge Deployment | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Manual Edge Deployment | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Automated Host Preparation by Cluster | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Operations | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Port Mirroring | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Traceflow | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Tunnel Health Monitoring | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
Port Connectivity Tool | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Switch Based IPFIX | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
LLDP | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Automated Technical Support Bundles | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Packet Capture | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Backup and Restore | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
SNMP v1/v2/v3 with Traps | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Upgrades and Migrations | Standard | Advanced | Enterprise | Standard | Professional | Advanced | Enterprise Plus | Remote Office / Branch Office |
Upgrade Coordinator | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
NSX for vSphere to NSX-T Migration Coordinator | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
Notes:
1 Please refer to the VMware Product Interoperability Matrices for specific versions supported with NSX-T Data Center.
2 Please refer to the NSX-T Data Center release notes for specific versions.
3 Please refer to the NSX-T Data Center partner website for specific versions.
4 VMware vRealize Log Insight for NSX provides intelligent log analytics for NSX Data Center. Log Insight provides monitoring and troubleshooting capabilities and customizable dashboards for network virtualization, flow analysis, and alerts. VMware vRealize Log Insight version 3.3.2 and later accepts NSX Data Center Standard/ProfessionalAdvanced/Enterprise Plus edition license keys issued for NSX-T 1.0.0 and later. This means you will have an enterprise-level Log Insight license for every license of NSX Data Center.
5 VMware Workspace ONE Access - A license to use VMware NSX Data Center includes an entitlement to use the VMware Workspace ONE Access feature, but only for the following functionalities:
6 Integration with automation tools such as vRealize Automation, vCloud Director, VMware Integrated OpenStack, and other OpenStack distributions, Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Data Center Advanced, Enterprise Plus, or ROBO.
7 NSX Distributed Threat Prevention requires an additional subscription-based purchase.
8 Both IPv4 and IPv6 are supported for all Load Balancing features except for IPv6-VIP-to-IPv4-member and IPv4-VIP-to-IPv6-member translations.
9 Customers who have purchased the legacy NSX editions can apply their licenses to NSX-T Data Center.
10 Requires VDS 7.0 or higher
11 Migration Coordinator will migrate the deployment in NSX for vSphere and the features used in NSX-T. It is the responsibility of the customer to ensure the version of NSX-T allows the use of those features.
12 Network Detection and Response supports event and artifact submission from Distributed Firewall only. It is a hosted service running from various VMware Regions.
13 A single sensor socket entitles up to 250 artifact submissions per day with a maximum artifact size of 64MB.
14 Subject to Gateway Firewall features available in that specific SKU
For Product offerings for VMware NSX-T Data Center 4.0.x, refer to https://knowledge.broadcom.com/external/article?legacyId=89137
For Product offerings for VMware NSX-T Data Center 3.2.x, refer to https://knowledge.broadcom.com/external/article?legacyId=86095