Product offerings for VMware NSX-T Data Center 3.1.x
search cancel

Product offerings for VMware NSX-T Data Center 3.1.x

book

Article ID: 319118

calendar_today

Updated On:

Products

VMware NSX Networking

Issue/Introduction

This article provides information on licensing editions of VMware NSX-T and list of features associated with the various licensing editions in VMware NSX-T Data Center 3.1.x.

New VMware NSX Data Center editions became available to order on June 5th, 2018. The tiers of NSX Data Center licenses are as follows:

NSX Data Center Editions
  • NSX Data Center Standard Edition: For organizations needing agility and automation of the network.
  • NSX Data Center Professional Edition: For organizations needing Standard, plus micro-segmentation, and may have public cloud endpoints.
  • NSX Data Center Advanced Edition: For organizations needing Professional, plus advanced networking and security services, and may have multiple sites.
  • NSX Data Center Enterprise Plus Edition: For organizations needing the most advanced capabilities NSX Data Center has to offer, plus network visibility and security operations with vRealize Network Insight™, and hybrid cloud mobility with VMware HCX.
  • NSX Data Center for Remote Office Branch Office: For organizations that need to virtualize networking and security for applications in the remote office or branch office.
NSX Editions (Sold May 2016 - June 2018) (no longer available for purchase)⁹
  • NSX Standard Edition - For organizations needing agility and automation of the network.
  • NSX Advanced Edition - For organizations needing Standard, plus a fundamentally more secure data center with micro-segmentation.
  • NSX Enterprise Edition - For organizations needing Advanced, plus networking and security across multiple domains.


Environment

VMware NSX-T Data Center 3.x
VMware NSX-T Data Center

Resolution

The following table outlines specific functions available by edition. NSX Data Center is available as a single download image with license keys required to enable specific functionality.

 NSX Editions (Sold May 2016 - June 2018)NSX Data Center Editions

Feature

StandardAdvancedEnterprise

Standard

Professional

Advanced

Enterprise Plus

Remote Office / Branch Office

Platform Features        
vSphere Distributed Switch   YesYesYesYesYes
ESXi Support1YesYesYesYesYesYesYesYes
KVM Support2NoNoNoYesYesYesYesNo
Controller ClusteringYesYesYesYesYesYesYesYes
vCenter Integration1YesYesYesYesYesYesYesYes
Multi-vCenter® Networking and SecurityNoNoYesNoNoYesYesNo
FederationNoNoNoNoNoNoYesNo
Edge Platform FeaturesStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Edge in VM Form FactorYesYesYesYesYesYesYesYes
Edge in Bare-Metal Form FactorYesYesYesYesYesYesYesNo
DPDK Optimized ForwardingYesYesYesYesYesYesYesYes
SwitchingStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
vSphere Distributed Switch¹⁰YesYesYesYesYesYesYesYes
Distributed SwitchingYesYesYesYesYesYesYesNo
VLAN Backed Logical SwitchingYesYesYesYesYesYesYesYes
Overlay Backed Logical SwitchingYesYesYesYesYesYesYesNo
Multiple TEP SupportYesYesYesYesYesYesYesNo
Optimized ARP Learning and Broadcast SuppressionYesYesYesYesYesYesYesNo
GENEVE EncapsulationYesYesYesYesYesYesYesNo
Unicast ReplicationYesYesYesYesYesYesYesNo
Headend ReplicationYesYesYesYesYesYesYesNo
SpoofguardYesYesYesYesYesYesYesNo
LACP (Edge and Host)YesYesYesYesYesYesYesYes
L2 MulticastYesYesYesYesYesYesYesNo
L3 MulticastNoYesYesNoNoYesYesNo
Quality of Service (QoS)StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
QoS MarkingYesYesYesYesYesYesYesNo
QoS DSCP Trust BoundaryYesYesYesYesYesYesYesNo
L2 Bridging to Physical EnvironmentStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Software Based L2 Bridge to Physical EnvironmentsYesYesYesYesYesYesYesNo
RoutingStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed RoutingYesYesYesYesYesYesYesNo
Multi-Tier RoutingYesYesYesYesYesYesYesNo
Dynamic Routing with ECMPYesYesYesYesYesYesYesNo
Virtual Routing and Forwarding (Tier-0 Gateway VRFs)NoYesYesNoNoYesYesNo
E-VPNNoNoYesNoNoNoYesNo
Static Routing - IPv4StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Static RoutingYesYesYesYesYesYesYesYes
BFDYesYesYesYesYesYesYesYes
Null RoutesYesYesYesYesYesYesYesYes
Device RoutesYesYesYesYesYesYesYesYes
Static Routing - IPv6StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Static RoutingYesYesYesYesYesYesYesNo
Null RoutesYesYesYesYesYesYesYesNo
Device RoutesYesYesYesYesYesYesYesNo
BGP - IPv4 UnicastStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
eBGPYesYesYesYesYesYesYesNo
eBGP MultihopYesYesYesYesYesYesYesNo
iBGPYesYesYesYesYesYesYesNo
Graceful RestartYesYesYesYesYesYesYesNo
BFDYesYesYesYesYesYesYesNo
4-byte ASNYesYesYesYesYesYesYesNo
BGP - IPv6 UnicastStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
eBGPNoYesYesNoNoYesYesNo
eBGP MultihopNoYesYesNoNoYesYesNo
iBGPNoYesYesNoNoYesYesNo
Graceful RestartNoYesYesNoNoYesYesNo
4-byte ASNNoYesYesNoNoYesYesNo
BFD - IPv4StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Sub-Second Keepalive TimerYesYesYesYesYesYesYesNo
Route MapsStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Match on Prefix-List and Community-ListYesYesYesYesYesYesYesNo
Set Weight, MED, AS Path, Prepending, Local Preference, and CommunityYesYesYesYesYesYesYesNo
OtherStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
High Availability Virtual IP (HA VIP)YesYesYesYesYesYesYesNo
Route RedistributionYesYesYesYesYesYesYesNo
IP Prefix-ListsYesYesYesYesYesYesYesNo
Active / Active RedundancyYesYesYesYesYesYesYesNo
Active / Standby RedundancyYesYesYesYesYesYesYes

No

Per Interface RPF CheckYesYesYesYesYesYesYesNo
NATStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
NAT on North/South and East/West Logical RoutersYesYesYesYesYesYesYesYes
Source NATYesYesYesYesYesYesYesYes
Destination NATYesYesYesYesYesYesYesYes
NAT N:NYesYesYesYesYesYesYesYes
Stateless NATYesYesYesYesYesYesYesYes
NAT LoggingYesYesYesYesYesYesYesYes
NAT64NoYesYesNoNoYesYesNo
FirewallStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Edge FirewallYesYesYesYesYesYesYesYes
Distributed FirewallingNoYesYesNoYesYesYesYes
Common Firewall User InterfaceYesYesYesYesYesYesYesYes
Firewall SectionsYesYesYesYesYesYesYesYes
Firewall LoggingYesYesYesYesYesYesYesYes
Stateful L2 and L3 RulesYesYesYesYesYesYesYesYes
Stateless L2 and L3 RulesYesYesYesYesYesYesYesYes
Tag Based RulesYesYesYesYesYesYesYesYes
Distributed Firewall based IPFIXNoYesYesNoYesYesYesYes
Distributed FQDN WhitelistingNoNoYesNoNoYesYesNo
L7 Application Identification RulesYesYesYesYesYesYesYesYes
Agent-Based enforcement for Physical ServersYesYesYesYesYesYesYesYes
Identity FirewallStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Identity based Groups using Active DirectoryNoYesYesNoNoYesYesNo
NSX Distributed Threat Prevention7StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed IDSNoYesYesNoNoYesYesNo
Distributed IPSNoYesYesNoNoYesYesNo
Policy, Tagging and GroupingStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Object Tagging / Security TagsYesYesYesYesYesYesYesYes
Network Centric GroupingYesYesYesYesYesYesYesYes
Workload Centric GroupingYesYesYesYesYesYesYesYes
IP Based GroupsYesYesYesYesYesYesYesYes
MAC Based GroupsYesYesYesYesYesYesYesYes
Intent based Networking and Security PolicyYesYesYesYesYesYesYesYes
DNS, DHCP and IPAM (DDI)StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
IPAMYesYesYesYesYesYesYesYes
IP BlocksYesYesYesYesYesYesYesYes
IP SubnetsYesYesYesYesYesYesYesYes
IP PoolsYesYesYesYesYesYesYesYes
IPv4 DHCP ServerYesYesYesYesYesYesYesYes
IPv6 DHCP ServerNoYesYesNoNoYesYesNo
IPv4 DHCP RelayYesYesYesYesYesYesYesYes
IPv6 DHCP RelayNoYesYesNoNoYesYesNo
IPv4 DHCP Static Bindings / Fixed AddressesYesYesYesYesYesYesYesYes
IPv6 DHCP Static Bindings / Fixed AddressesNoYesYesNoNoYesYesNo
IPv4 DNS Relay / DNS ProxyYesYesYesYesYesYesYesYes
IPv4 Meta-Data ProxyYesYesYesYesYesYesYesNo
Load Balancing8StandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Protocols        
TCP (L4-L7)NoYesYesNoNoYesYesYes
UDPNoYesYesNoNoYesYesYes
HTTPNoYesYesNoNoYesYesYes
Load Balancing Methods        
Round RobinNoYesYesNoNoYesYesYes
Source IP HashNoYesYesNoNoYesYesYes
Least ConnectionsNoYesYesNoNoYesYesYes
L7 Application Rules with RegEx SupportNoYesYesNoNoYesYesYes
VPNStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
L2 VPNNoYesYesNoYesYesYesYes
L3 VPNNoYesYesNoYesYesYesYes
Health Checks        
TCPNoYesYesNoNoYesYesYes
ICMPNoYesYesNoNoYesYesYes
UDPNoYesYesNoNoYesYesYes
HTTPNoYesYesNoNoYesYesYes
HTTPSNoYesYesNoNoYesYesYes
Monitoring        
View VIP / Pool / Server ObjectsNoYesYesNoNoYesYesYes
View VIP / Pool / Server StatisticsNoYesYesNoNoYesYesYes
View Global Statistics VIP SessionsNoYesYesNoNoYesYesYes
Load Balancing Automation        
Pool Members Based on vCenter Context or IP AddressesNoYesYesNoNoYesYesYes
Other        
Connection ThrottlingNoYesYesNoNoYesYesYes
High-AvailabilityNoYesYesNoNoYesYesYes
API Driven AutomationStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
REST APIYesYesYesYesYesYesYesYes
Hierarchical Policy APIYesYesYesYesYesYesYesYes
JSON SupportYesYesYesYesYesYesYesYes
OpenAPI / Swagger SpecYesYesYesYesYesYesYesYes
Java SDKYesYesYesYesYesYesYesYes
Python SDKYesYesYesYesYesYesYesYes
Auto-generated API DocumentationYesYesYesYesYesYesYesYes
Terraform Provider6YesYesYesYesYesYesYesYes
Ansible Modules6YesYesYesYesYesYesYesYes
Cloud Native and Integration with Cloud Management PlatformsStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Container Networking and SecurityNoYesYesNoNoYesYesNo
Integration with vRealize Automation1,6YesYesYesYesYesYesYesNo
Integration with vCloud Director1,6YesYesYesYesYesYesYesNo
Integration with VMware Integrated OpenStack1,6YesYesYesYesYesYesYesNo
Integration with other OpenStack Platform3, 6YesYesYesYesYesYesYesNo
Service Insertion IntegrationsStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Endpoint ProtectionYesYesYesYesYesYesYesYes
Network IntrospectionNoYesYesNoNoYesYesYes
NSX IntelligenceStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Layer 4 VM-to-VM Traffic Flow AnalysisNoNoNoNoNoNoYesNo
Layer 4 Firewall VisibilityNoNoNoNoNoNoYesNo
Layer 4 Automated Security PolicyNoNoNoNoNoNoYesNo
Layer 4 Rule and Group Recommendation AnalyticsNoNoNoNoNoNoYesNo
Integration with NSX Cloud for AWS and Azure SupportStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
NSX on-prem license portability for Public Cloud workloadsNoYesYesNoNoYesYesYes
NSX Enforced Mode (Agent-Based Cloud Security)NoYesYesNoYesYesYesYes
Cloud Enforced Mode (Agentless Based Cloud Security)NoYesYesNoYesYesYesYes
L7 Security Features (AppID, URL Filtering)NoYesYesNoYesYesYesYes
Service InsertionNoYesYesNoYesYesYesYes
NSX Security for VDI workloads on Azure HorizonNoYesYesNoYesYesYesYes
VPN (on-prem to public cloud; public cloud - public cloud; intra public cloud)NoYesYesNoYesYesYesYes
Support for AWS Gov Cloud and Azure Government Cloud workloadsNoYesYesNoYesYesYesYes
Authentication and AuthorizationStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Authentication using Workspace ONE Access1, 5YesYesYesYesYesYesYesYes
Direct Active Directory Integration via LDAPYesYesYesYesYesYesYesYes
Authentication via OpenLDAPYesYesYesYesYesYesYesYes
Session Based AuthenticationYesYesYesYesYesYesYesYes
Certificate Based Authentication (Principle Identity)YesYesYesYesYesYesYesYes
Role Based Access ControlYesYesYesYesYesYesYesYes
Log ManagementStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
vRealize Log Insight Integration1, 4YesYesYesYesYesYesYesYes
Splunk Integration2YesYesYesYesYesYesYesYes
InstallationStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Automated Controller DeploymentYesYesYesYesYesYesYesYes
Manual Controller DeploymentYesYesYesYesYesYesYesYes
Automated Edge DeploymentYesYesYesYesYesYesYesYes
Manual Edge DeploymentYesYesYesYesYesYesYesYes
Automated Host Preparation by ClusterYesYesYesYesYesYesYesYes
OperationsStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Port MirroringYesYesYesYesYesYesYesYes
TraceflowYesYesYesYesYesYesYesYes
Tunnel Health MonitoringYesYesYesYesYesYesYesNo
Port Connectivity ToolYesYesYesYesYesYesYesYes
Switch Based IPFIXYesYesYesYesYesYesYesYes
LLDPYesYesYesYesYesYesYesYes
Automated Technical Support BundlesYesYesYesYesYesYesYesYes
Packet CaptureYesYesYesYesYesYesYesYes
Backup and RestoreYesYesYesYesYesYesYesYes
SNMP v1/v2/v3 with TrapsYesYesYesYesYesYesYesYes
Upgrades and MigrationsStandardAdvancedEnterpriseStandardProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Upgrade CoordinatorYesYesYesYesYesYesYesYes
NSX for vSphere to NSX-T Migration CoordinatorYesYesYesYesYesYesYesYes

Notes:
 

1 Please refer to the VMware Product Interoperability Matrices for specific versions supported with NSX-T Data Center.
2 Please refer to the NSX-T Data Center release notes for specific versions.
3 Please refer to the NSX-T Data Center partner website for specific versions.
4 VMware vRealize Log Insight for NSX provides intelligent log analytics for NSX Data Center. Log Insight provides monitoring and troubleshooting capabilities and customizable dashboards for network virtualization, flow analysis, and alerts. VMware vRealize Log Insight version 3.3.2 and later accepts NSX Data Center Standard/ProfessionalAdvanced/Enterprise Plus edition license keys issued for NSX-T 1.0.0 and later. This means you will have an enterprise-level Log Insight license for every license of NSX Data Center.

5 VMware Workspace ONE Access - A license to use VMware NSX Data Center includes an entitlement to use the VMware Workspace ONE Access feature, but only for the following functionalities:

  • Directory integration functionality of VMware Workspace ONE Access to authenticate users in a user directory such as Microsoft Active Directory or LDAP.
  • Conditional access policy.
  • Single-sign-on integration functionality with third party Identity providers to allow third party identity providers’ users to single-sign-on into NSX Data Center.
  • Two-factor authentication solution through integration with third party systems. VMware Verify, VMware’s multi-factor authentication solution, received as part of VMware Workspace ONE Access may not be used as part of NSX Data Center.
  • Single-sign-on functionality to access VMware products that support single-sign-on capabilities.

6 Integration with automation tools such as vRealize Automation, vCloud Director, VMware Integrated OpenStack, and other OpenStack distributions, Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Data Center  Advanced, Enterprise Plus, or ROBO.

7 NSX Distributed Threat Prevention requires an additional subscription-based purchase.

8 Both IPv4 and IPv6 are supported for all Load Balancing features except for IPv6-VIP-to-IPv4-member and IPv4-VIP-to-IPv6-member translations.

9 Customers who have purchased the legacy NSX editions can apply their licenses to NSX-T Data Center.

10 Requires VDS 7.0 or higher

11 Migration Coordinator will migrate the deployment in NSX for vSphere and the features used in NSX-T. It is the responsibility of the customer to ensure the version of NSX-T allows the use of those features.

12 Network Detection and Response supports event and artifact submission from Distributed Firewall only. It is a hosted service running from various VMware Regions.

13 A single sensor socket entitles up to 250 artifact submissions per day with a maximum artifact size of 64MB.

14 Subject to Gateway Firewall features available in that specific SKU

Additional Information

For Product offerings for VMware NSX-T Data Center 4.0.x, refer to https://kb.vmware.com/s/article/89137
For Product offerings for VMware NSX-T Data Center 3.2.x, refer to https://kb.vmware.com/s/article/86095
For NSX editions no longer available for purchase, refer to https://kb.vmware.com/s/article/88846