Product offerings for VMware NSX-T Data Center 3.2.x
search cancel

Product offerings for VMware NSX-T Data Center 3.2.x

book

Article ID: 319112

calendar_today

Updated On:

Products

VMware NSX Networking

Issue/Introduction

This article provides information on licensing editions of VMware NSX-T and list of features associated with the various licensing editions in VMware NSX-T Data Center 3.2.x.

New VMware NSX-T editions became available to order on August 5th, 2021. The tiers of NSX Data Center licenses are as follows:


NSX-T Editions

  • NSX-T Professional Edition: For organizations needing Standard, plus micro-segmentation, and may have public cloud endpoints.
  • NSX-T Advanced Edition: For organizations needing Professional, plus advanced networking and security services, and may have multiple sites.
  • NSX-T Enterprise Plus Edition: For organizations needing the most advanced capabilities NSX Data Center has to offer, plus network visibility and security operations with vRealize Network Insight™, and hybrid cloud mobility with VMware HCX.
  • NSX-T for Remote Office Branch Office: For organizations that need to virtualize networking and security for applications in the remote office or branch office.


Environment

VMware NSX-T Data Center 3.x
VMware NSX-T Data Center

Resolution

The following tables outline specific functions available by edition. NSX-T is available as a single download image with license keys required to enable specific functionality.

Networking

FeatureNSX-T Editions
SwitchingProfessional            Advanced           Enterprise Plus              Remote Office / Branch Office         
vSphere Distributed Switch10YesYesYesYes
VLAN Backed Logical SwitchingYesYesYesYes
Overlay Backed Logical SwitchingYesYesYesNo
Multiple TEP SupportYesYesYesNo
Optimized ARP Learning and Broadcast SuppressionYesYesYesNo
GENEVE EncapsulationYesYesYesNo
Unicast ReplicationYesYesYesNo
Headend ReplicationYesYesYesNo
SpoofguardYesYesYesNo
LACP (Edge and Host)YesYesYesYes
L2 MulticastYesYesYesNo
L3 MulticastNoYesYesNo
Quality of Service (QoS)Professional  Advanced  Enterprise PlusRemote Office / Branch Office
QoS MarkingYesYesYesNo
QoS DSCP Trust BoundaryYesYesYesNo
QoS  Rate-Limit Northbound Traffic on Tier-1 GatewayYesYesYesNo
L2 Bridging to Physical EnvironmentProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Software Based L2 Bridge to Physical EnvironmentsYesYesYesNo
RoutingProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed RoutingYesYesYesNo
Multi-Tier RoutingYesYesYesNo
Dynamic Routing with ECMPYesYesYesNo
Active / Standby Redundancy for RoutingYesYesYes

No

Active / Active Redundancy for RoutingYesYesYesNo
Virtual Routing and Forwarding (Tier-0 Gateway VRFs)NoYesYesNo
EVPNNoNoYesNo
OSPF v2YesYesYesNo
Static Routing - IPv4ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Static RoutingYesYesYesYes
BFDYesYesYesYes
Null RoutesYesYesYesYes
Device RoutesYesYesYesYes
Static Routing - IPv6ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Static RoutingYesYesYesNo
Null RoutesYesYesYesNo
Device RoutesYesYesYesNo
BGP - IPv4 UnicastProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
eBGPYesYesYesNo
eBGP MultihopYesYesYesNo
iBGPYesYesYesNo
Graceful RestartYesYesYesNo
BFDYesYesYesNo
4-byte ASNYesYesYesNo
BGP - IPv6 UnicastProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
eBGPNoYesYesNo
eBGP MultihopNoYesYesNo
iBGPNoYesYesNo
Graceful RestartNoYesYesNo
4-byte ASNNoYesYesNo
BFD - IPv4ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Sub-Second Keepalive TimerYesYesYesNo
Route MapsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Match on Prefix-List and Community-ListYesYesYesNo
Set Weight, MED, AS Path, Prepending, Local Preference, and CommunityYesYesYesNo
OtherProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
High Availability Virtual IP (HA VIP)YesYesYesNo
Route RedistributionYesYesYesNo
IP Prefix-ListsYesYesYesNo
Per Interface RPF CheckYesYesYesNo
DNS, DHCP and IPAM (DDI)ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
IPAMYesYesYesYes
IP BlocksYesYesYesYes
IP SubnetsYesYesYesYes
IP PoolsYesYesYesYes
IPv4 DHCP ServerYesYesYesYes
IPv6 DHCP ServerNoYesYesNo
IPv4 DHCP RelayYesYesYesYes
IPv6 DHCP RelayNoYesYesNo
IPv4 DHCP Static Bindings / Fixed AddressesYesYesYesYes
IPv6 DHCP Static Bindings / Fixed AddressesNoYesYesNo
IPv4 DNS Relay / DNS ProxyYesYesYesYes
IPv4 Meta-Data ProxyYesYesYesNo

Distributed Security

FeatureNSX-T Editions

Distributed Firewall

Professional       

Advanced       

Enterprise Plus             

Remote Office / Branch Office           

Distributed Firewall for NSX SwitchportsYesYesYesYes
Distributed Firewall for VDS SwitchportsYesYesYesYes
Stateful L2 and L3 RulesYesYesYesYes
Stateless L2 and L3 RulesYesYesYesYes
Distributed FQDN FilteringNoYesYesNo
Basic L7 Application Identification RulesNoYesYesYes
Advanced L7 Application Identification RulesNoNoNoNo
Distributed Flood ProtectionYesYesYesYes
Agent-Based enforcement for Physical ServersYesYesYesYes
User Identity FirewallProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed Identity Firewall using Guest IntrospectionNoYesYesNo
Distributed Identity Firewall using Active Directory Event ServerNoYesYesNo
Distributed Identity Firewall using third-party log sourcesNoNoNoNo
NSX Distributed Threat Prevention7ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed Intrusion Detection Service (IDS)NoRequires additional license7Requires additional license7No
Distributed Behavioral IDSNoRequires additional license7Requires additional license7No
Distributed Intrusion Prevention Service (IPS)NoRequires additional license7Requires additional license7No
NSX Distributed Advanced Threat Prevention9ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed Malware Detection and PreventionNoNoNoNo
Cloud Sandboxing and Artifact Analysis10NoNoNoNo
Distributed IDS Event Forwarding to NDRNoNoNoNo
Distributed Service Insertion IntegrationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Distributed Endpoint ProtectionNoYesYesNo
Distributed Network IntrospectionNoYesYesNo
Policy, Tagging and GroupingProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Object Tagging / Security TagsYesYesYesYes
Network Centric GroupingYesYesYesYes
Workload Centric GroupingYesYesYesYes
IP Based GroupsYesYesYesYes
MAC Based GroupsYesYesYesYes
Tag Based RulesYesYesYesYes
Firewall OperationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Firewall LoggingYesYesYesYes
Distributed Firewall based IPFIXYesYesYesYes
Rule Hit Count, Popularity Index, Flow StatisticsYesYesYesYes
Firewall DraftsYesYesYesYes

 

Gateway Security

 NSX-T Editions

Feature

Professional       

Advanced       

Enterprise Plus               

Remote Office / Branch Office             

Stateful L3 RulesYesYesYesYes
Stateless L3 RulesYesYesYesYes
Basic L7 Application Identification RulesNoYesYesYes
Advanced L7 Application Identification RulesNoNoNoNo
URL FilteringNoNoNoNo
Gateway Flood ProtectionYesYesYesYes
Identity FirewallProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Gateway Identity Firewall using Active Directory Event ServerNoNoNoNo
Gateway Identity Firewall using third-party log sourcesNoNoNoNo
NSX Gateway Threat Prevention7ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Gateway TLS DecryptionNoNoNoNo
Gateway Intrusion Detection Service (IDS) - BehavioralNoNoNoNo
Gateway Intrusion Prevention Service (IPS)NoNoNoNo
NSX Gateway Advanced Threat Prevention7ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Malware DetectionNoNoNoNo
Cloud Sandboxing and Artifact Analysis10NoNoNoNo
NATProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
NAT on North/South and East/West Logical RoutersYesYesYesYes
Source NATYesYesYesYes
Destination NATYesYesYesYes
NAT N:NYesYesYesYes
Stateless NATYesYesYesYes
NAT LoggingYesYesYesYes
NAT64NoYesYesNo
Active/Active NAT ServicesNoNoNoNo
VPNProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
L2 VPNYesYesYesYes
Active / Standby L3 VPNYesYesYesYes
Gateway Service Insertion IntegrationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Gateway Network IntrospectionYesYesYesYes
Gateway Firewall High Availability11ProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Active/Standby Gateway Firewall Services (Firewall, NAT, IDS/IPS, VPN, Malware Detection)YesYesYesYes
Policy, Tagging and GroupingProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Object Tagging / Security TagsYesYesYesYes
Network Centric GroupingYesYesYesYes
Workload Centric GroupingYesYesYesYes
IP Based GroupsYesYesYesYes
Tag Based RulesYesYesYesYes
Per-Gateway and Multi-Gateway Policy ManagementYesYesYesYes
Gateway Firewall OperationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Firewall LoggingYesYesYesYes
Rule Hit Count, Popularity Index, Flow StatisticsYesYesYesYes

NSX Intelligence

 NSX-T Editions
FeatureProfessional       Advanced       Enterprise Plus         Remote Office / Branch Office               
Layer 4 VM-to-VM Traffic Flow AnalysisNoNoYesNo
Layer 4 Firewall VisibilityNoNoYesNo
Layer 4 Automated Security PolicyNoNoYesNo
Layer 4 Rule and Group Recommendation AnalyticsNoNoYesNo
Network Traffic AnalyticsNoNoNoNo

 

Load Balancing8

FeatureNSX-T Editions
ProtocolsProfessional       Advanced       Enterprise Plus          Remote Office / Branch Office       
TCP (L4-L7)NoYesYesYes
UDPNoYesYesYes
HTTPNoYesYesYes
Load Balancing Methods    
Round RobinNoYesYesYes
Source IP HashNoYesYesYes
Least ConnectionsNoYesYesYes
L7 Application Rules with RegEx SupportNoYesYesYes
Health Checks    
TCPNoYesYesYes
ICMPNoYesYesYes
UDPNoYesYesYes
HTTPNoYesYesYes
HTTPSNoYesYesYes
Monitoring    
View VIP / Pool / Server ObjectsNoYesYesYes
View VIP / Pool / Server StatisticsNoYesYesYes
View Global Statistics VIP SessionsNoYesYesYes
Load Balancing Automation    
Pool Members Based on vCenter Context or IP AddressesNoYesYesYes
Other    
Connection ThrottlingNoYesYesYes
High-AvailabilityNoYesYesYes

NSX Cloud for AWS and Azure

FeatureNSX-T Editions
 Professional       Advanced       Enterprise Plus              Remote Office / Branch Office           
NSX on-prem license portability for Public Cloud workloadsNoYesYesYes
NSX Enforced Mode (Agent-Based Cloud Security)YesYesYesYes
Distributed Identity Firewall using Active Directory Event ServerNoYesYesNo
Cloud Enforced Mode (Agentless Based Cloud Security)YesYesYesYes
L7 Security Features (Basic L7 Application Identification Rules)YesYesYesYes
Advanced Security capabilities in Public Cloud GatewayNoNoNoNo
VPN (on-prem to public cloud; public cloud - public cloud; intra public cloud)YesYesYesYes
Support for AWS Gov Cloud and Azure Government Cloud workloadsYesYesYesYes

 

Modern Apps

FeatureNSX-T Editions
 Professional       Advanced       Enterprise Plus         Remote Office / Branch Office        

Container Networking and Security

NoYesYesNo
VMware Container Networking with Project Antrea EnterpriseNoYesYesNo

Automation

FeatureNSX-T Editions
API Driven AutomationProfessional       Advanced       Enterprise Plus         Remote Office / Branch Office     
REST APIYesYesYesYes
Hierarchical Policy APIYesYesYesYes
JSON SupportYesYesYesYes
OpenAPI / Swagger SpecYesYesYesYes
Java SDKYesYesYesYes
Python SDKYesYesYesYes
Auto-generated API DocumentationYesYesYesYes
Terraform Provider6YesYesYesYes
Ansible Modules6YesYesYesYes
Integration with Cloud Management PlatformsProfessional     Advanced     Enterprise Plus     Remote Office / Branch Office          
Integration with vRealize Automation1,6NoYesYesNo
Integration with vCloud Director1,6YesYesYesNo
Integration with VMware Integrated OpenStack1,6YesYesYesNo
Integration with other OpenStack Platform3,6YesYesYesNo

Platform

FeatureNSX-T Editions
Platform FeaturesProfessional       Advanced       Enterprise Plus            Remote Office / Branch Office         
ESXi Support1YesYesYesYes
KVM Support2YesYesYesNo
Controller ClusteringYesYesYesYes
vCenter Integration1YesYesYesYes
Multi-vCenter® Networking and SecurityNoYesYesNo
FederationNoNoYesNo
Edge Platform FeaturesProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Edge in VM Form FactorYesYesYesYes
Edge in Bare-Metal Form Factor for RoutingYesYesYesNo
Edge in Bare-Metal Form Factor for Gateway FirewallNoNoSubscription OnlyNo
DPDK Optimized ForwardingYesYesYesYes
Authentication and AuthorizationProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Authentication using Workspace ONE Access1,5YesYesYesYes
Direct Active Directory Integration via LDAPYesYesYesYes
Authentication via OpenLDAPYesYesYesYes
Session Based AuthenticationYesYesYesYes
Certificate Based Authentication (Principle Identity)YesYesYesYes
Role Based Access ControlYesYesYesYes
Log ManagementProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
vRealize Log Insight Integration1,4YesYesYesYes
Splunk Integration2YesYesYesYes
InstallationProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Automated Manager DeploymentYesYesYesYes
Manual Manager DeploymentYesYesYesYes
Automated Edge DeploymentYesYesYesYes
Manual Edge DeploymentYesYesYesYes
Automated Host Preparation by ClusterYesYesYesYes
OperationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Port MirroringYesYesYesYes
TraceflowYesYesYesYes
NSX Live Traffic AnalysisYesYesYesYes
Tunnel Health MonitoringYesYesYesNo
Port Connectivity ToolYesYesYesNo
Switch Based IPFIXYesYesYesYes
LLDPYesYesYesYes
Automated Technical Support BundlesYesYesYesYes
Packet CaptureYesYesYesYes
Backup and RestoreYesYesYesYes
SNMP v1/v2/v3 with TrapsYesYesYesYes
Time-Series MetricsNoNoSubscription OnlyNo
Upgrades and MigrationsProfessionalAdvancedEnterprise PlusRemote Office / Branch Office
Upgrade CoordinatorYesYesYesYes
NSX for vSphere to NSX-T Migration CoordinatorYesYesYesYes
NSX Manager to Policy PromotionYesYesYesYes


Notes:


1 Please refer to the VMware Product Interoperability Matrices for specific versions supported with NSX-T Data Center.

2 Please refer to the NSX-T Data Center release notes for specific versions.

3 Please refer to the NSX-T Data Center partner website for specific versions.

4 VMware vRealize Log Insight for NSX provides intelligent log analytics for NSX Data Center. Log Insight provides monitoring and troubleshooting capabilities and customizable dashboards for network virtualization, flow analysis, and alerts. VMware vRealize Log Insight version 3.3.2 and later accepts NSX Data Center Standard/ProfessionalAdvanced/Enterprise Plus edition license keys issued for NSX-T 1.0.0 and later. This means you will have an enterprise-level Log Insight license for every license of NSX Data Center.

5 VMware Workspace ONE Access - A license to use VMware NSX Data Center includes an entitlement to use the VMware Workspace ONE Access feature, but only for the following functionalities:

  • Directory integration functionality of VMware Workspace ONE Access to authenticate users in a user directory such as Microsoft Active Directory or LDAP.
  • Conditional access policy.
  • Single-sign-on integration functionality with third party Identity providers to allow third party identity providers’ users to single-sign-on into NSX Data Center.
  • Two-factor authentication solution through integration with third party systems. VMware Verify, VMware’s multi-factor authentication solution, received as part of VMware Workspace ONE Access may not be used as part of NSX Data Center.
  • Single-sign-on functionality to access VMware products that support single-sign-on capabilities.

6 Integration with automation tools such as vRealize Automation, vCloud Director, VMware Integrated OpenStack, and other OpenStack distributions, Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Data Center  Advanced, Enterprise Plus, or ROBO.

7 NSX Distributed Threat Prevention requires an additional subscription-based purchase.

8 Both IPv4 and IPv6 are supported for all Load Balancing features except for IPv6-VIP-to-IPv4-member and IPv4-VIP-to-IPv6-member translations.

9 Customers who have purchased the legacy NSX editions can apply their licenses to NSX-T Data Center.

10 Requires VDS 7.0 or higher

11 Migration Coordinator will migrate the deployment in NSX for vSphere and the features used in NSX-T. It is the responsibility of the customer to ensure the version of NSX-T allows the use of those features.

12 Network Detection and Response supports event and artifact submission from Distributed Firewall only. It is a hosted service running from various VMware Regions.

13 A single sensor socket entitles up to 250 artifact submissions per day with a maximum artifact size of 64MB.

14 Subject to Gateway Firewall features available in that specific SKU. Please refer to the https://kb.vmware.com/s/article/87077

15 Please refer to NSX Security Features covered in https://kb.vmware.com/s/article/87077

Additional Information

For Product offerings for VMware NSX-T Data Center 4.0.x, refer to https://kb.vmware.com/s/article/89137
For NSX-T License editions no longer available for purchase, refer to https://kb.vmware.com/s/article/88846