Watch on YouTube
Watch on Vimeo
Andrew Voltmer of VMware by Broadcom explained how NSX has evolved within VCF Networking to bring a public cloud operating model to the private cloud. The session covered self-service VPCs, consistent networking across sites and regions, Enhanced Data Path performance and NIC offloads, integrated deployment within VMware Cloud Foundation, and EVPN integration with physical switching fabrics. Voltmer, Director of Product Management for VCF Networking, opened the VMware by Broadcom presentation at Networking Field Day 41.
Voltmer said the VPC construct, modeled on AWS VPCs and Azure VNets, replaces the older tier-0 and tier-1 model that once required specialist training. A single UI and API provisions isolated networks for workloads such as PCI or HIPAA zones, using routing isolation similar to VRFs alongside vDefend Layer 7 firewall rules with IDS/IPS and malware prevention. VPCs are now available directly in vCenter and VCF Automation, with Terraform, PowerCLI, and Antrea supporting automated and Kubernetes workflows. He highlighted long-standing use cases, including workload mobility over the Geneve overlay, disaster recovery that preserves IP addresses and security policy, and federation across global regions. Enhanced Data Path mode delivers line-rate switching on high-speed NICs up to 400G, with hardware offloads and a low-latency pass-through for AI workloads on NVIDIA ConnectX-7 NICs. EDP is opt-in today but is expected to become the default.
Voltmer described two complementary goals: making networking simple for virtualization admins and enabling sophisticated designs for network experts. NSX now installs as part of VCF fleet lifecycle, supports singleton managers and edgeless deployments, and renames the NSX Edge as the Virtual Network Appliance. For network teams, VMware is improving integration with Cisco, Arista, and Juniper fabrics so VPC constructs can be layered onto existing networks. The most significant change is EVPN support, in which NSX dynamically selects encapsulation, using Geneve between hosts and VXLAN when talking directly to a switch VTEP. Delegates raised concerns about losing underlay visibility, but Voltmer argued overlays are now universal. By removing the need for a centralized edge gateway, this approach offers a substantial performance benefit and positions NSX as a peer to the physical fabric rather than a layer hidden on top of it.
Personnel: Andrew Voltmer
Thank you for being part of the Tech Field Day community! Our mailing list is a great way to stay up to date on our events and technical content, and we appreciate your signup.
We promise that we’ll never spam you, send ads, or sell your information. This list will only be used to communicate with our community about our events and content. And we’ll limit it to no more than one message per week.
Although we only need your email address, it would be nice if you provided a little more information to help us get to know you better!