Category: VMware
-
NSX 9 Gateway Firewall and Perimeter Policy: North-South Security at the Edge (NSX Series, Part 14)
The Gateway Firewall secures north-south traffic at the Tier-0 or Tier-1, separate from the Distributed Firewall. How it differs from the DFW, where it runs, and defense in depth.
-
NSX 9 Distributed Firewall Fundamentals: Categories, Applied-To and Zero Trust (NSX Series, Part 12)
The Distributed Firewall puts stateful enforcement at every vNIC. Rule categories and order, the anatomy of a rule, why Applied-To matters most, and the zero-trust pivot.
-
NSX 9 NAT, DHCP and DNS Forwarder: The Gateway Services That Need the Edge (NSX Series, Part 11)
NAT, DHCP and the DNS forwarder are the first services that require a service router on the Edge. NAT types and the active-active trap, DHCP modes, and DNS forwarding.
-
NSX 9 Tier-1 Gateways and East-West Routing: DR, SR and the Hairpin Trap (NSX Series, Part 10)
The Tier-1 is half distributed router, half service router, and knowing the difference decides whether east-west traffic stays local or hairpins to the Edge.
-
NSX 9 Tier-0 Gateways and North-South Routing: BGP, ECMP and VRF (NSX Series, Part 9)
The Tier-0 is where NSX peers with your physical fabric. BGP design, ECMP and the URPF trap, route redistribution, and VRF-Lite for multi-tenant routing.
-
NSX 9 Host Transport Node Prep: VDS, EDP and Verifying It Worked (NSX Series, Part 6)
Preparing an ESXi host as an NSX 9 transport node: what it installs, how the Transport Node Profile applies VDS and EDP across the cluster, and how to verify it.
-
NSX 9 Manager Deployment and Cluster Bring-Up in VCF 9 (NSX Series, Part 5)
In VCF 9 you do not install NSX Manager, VCF does. Here is what the workflow deploys, the prerequisites that decide success, shared vs dedicated, and how to verify.
-
NSX 9 Design and Planning: Transport Zones, MTU, TEP Pools and EDP (NSX Series, Part 4)
The NSX 9 design decisions that decide whether your overlay works: the single overlay transport zone, GENEVE MTU, TEP IP pools and VLANs, and EDP mode.
-
NSX 9 Licensing and Editions: VCF vs Standalone and the vDefend Trap (NSX Series, Part 3)
How NSX 9 is licensed in VCF 9: what the base bundle includes, why security needs a vDefend add-on at full core count, and when standalone NSX makes sense.
Architect’s Toolkit
PJ’s Tools
VMware Cloud Foundation
- VCF Documentation
- VCF 9 Planning & Preparation Workbook
- VCF Bill of Materials (BoM)
- VMware Compatibility Guide
- VMware Interoperability Matrix
- VMware Configuration Maximums
- VMware Ports & Protocols
- VMware Hands-on Labs
- RVTools Download
Nutanix
AI & Cloud-Native Platform
- NVIDIA Build (Model Catalog)
- NVIDIA AI Enterprise Reference Architecture
- NVIDIA NIM Performance Benchmarking
- NVIDIA NGC Catalog
- NeMo Microservices Helm Chart
- Helm Charts Repository
- Hugging Face Models
Architecture & Design
About the Author

Dr Pranay Jha
Dr. Pranay Jha is a Cloud and AI Consultant with 18+ years of experience in hybrid cloud, virtualization, and enterprise infrastructure transformation. He specializes in VMware technologies, multi-cloud strategy, and Generative AI solutions. He holds a PhD in Computer Applications with research focused on Cloud and AI, has published multiple research papers, and has been a VMware vExpert since 2016 and a VMUG Community Leader.
You May Have Missed
