Watch on YouTube
Watch on Vimeo
Francois Tallet of VMware by Broadcom detailed how VCF Networking handles north-south traffic for VPCs using the distributed transit gateway introduced in VCF 9. The session covered VPC subnet types and tenant roles, centralized versus distributed external connectivity, EVPN-based connections, the Virtual Network Appliance, and a live vCenter demo of VPC connectivity policies. Tallet, a technical marketing engineer in the VCF networking division, presented at Networking Field Day 41.
Tallet explained that VPCs offer private subnets scoped to a single VPC, public subnets reachable from the physical network, and transit gateway private subnets scoped to a tenant. A VPC gateway routes within each VPC, a transit gateway connects VPCs within a tenant, and a provider role handles BGP and the physical handoff. He described the external connection as a contract that hides networking details from tenant admins, who consume pre-provisioned IP blocks under quotas without involving the network team. In the traditional centralized model, an edge VM hosts the transit gateway and tier-0, advertising public subnets via BGP. VCF 9 adds a distributed VLAN external connection that runs the transit gateway on every ESX host and sends traffic directly out the host uplink, though it requires one VLAN spanning all hosts. An EVPN option instead uses a route server advertising /32 type 5 routes and VXLAN to EVPN gateways. Stateful services such as SNAT, load balancing, and DHCP relay run on the Virtual Network Appliance.
Tallet argued that removing the edge VM also removes a political problem, since its ownership often divided compute and network teams, and that the distributed model largely matches centralized capabilities. His demo created a VPC, a public subnet with a default /26 and DHCP, and a private subnet entirely in vCenter, then used a Gemini-generated PowerCLI script to deploy more VPCs. He applied connectivity policies borrowing private VLAN terminology: isolated VPCs reach only the outside world, while a promiscuous shared services VPC remains reachable by all. These policies rely on routing reachability rather than access lists, which Tallet presented as proof that a virtualization admin can build segmented, externally connected networks without understanding default gateways or coordinating with the physical network team.
Personnel: Francois Tallet
Thank you for being part of the Tech Field Day community! Our mailing list is a great way to stay up to date on our events and technical content, and we appreciate your signup.
We promise that we’ll never spam you, send ads, or sell your information. This list will only be used to communicate with our community about our events and content. And we’ll limit it to no more than one message per week.
Although we only need your email address, it would be nice if you provided a little more information to help us get to know you better!