Advanced VCF Networking · Exam 3V0-25.25 · VMware Cloud Foundation 9
Exam 3V0-25.25 asks you to do three different things. Read its blueprint and you find design objectives, build objectives and troubleshooting objectives, all in one exam, all of them about NSX. That is why a workbook for it cannot be only lab tasks, and why preparing for it the way you would prepare for the Administrator exam leaves nearly half the blueprint untouched.
FirstWhat this exam actually is
Facts from the published exam guide, last updated 30 December 2025:
| Item | Detail |
|---|---|
| Exam | 3V0-25.25, leading to Advanced VMware Cloud Foundation Networking |
| Questions | 60 |
| Time | 135 minutes, including extra time for non-native English speakers |
| Pass mark | 300 out of 500, scaled |
| Question types | Multiple choice, multiple selection, build-list, matching, drag-and-drop, point-and-click, hot-area |
| Delivery | Proctored, through Pearson VUE |
| Testable objectives | 22, across Sections 3, 4 and 5 |
Source: the official exam guide for 3V0-25.25, published by Broadcom. Read it yourself before you book. Everything below is written against the objectives in that document.
SecondHow this one divides up against the others
VMware uses one standard five-section frame for every exam blueprint, and each exam fills only the sections its objectives belong to. Line the four advanced VCF 9 exams up and they divide the frame very differently:
| Blueprint section | Networking 3V0-25.25 | VKS 3V0-24.25 | Architect 3V0-12.26 | Administrator 3V0-11.26 |
|---|---|---|---|---|
| 1. IT architectures, technologies, standards | none | 3 | 5 | none |
| 2. VMware products and solutions | none | 6 | 3 | none |
| 3. Plan and design | 5 | 5 | 12 | none |
| 4. Install, configure, administrate | 12 | 14 | none | 60 |
| 5. Troubleshoot and optimise | 5 | 5 | none | none |
The two extremes are easy to describe: Architect is design and nothing else, Administrator is build and nothing else. Networking and VKS both sit in the middle, spanning design, build and troubleshooting. What makes this one distinctive is that it does all three against a single technology, NSX, which means the same objects come back at you from three directions: how you would design them, how you build them, and what it looks like when they break.
ThirdIf you already prepared for the Administrator exam
Then you have done more of this than you think. I compared the two published blueprints line by line, and ten of the 22 objectives here are word for word identical to objectives in 3V0-11.26, with only the numbering changed:
| In 3V0-25.25 | In 3V0-11.26 | Objective, identical wording in both |
|---|---|---|
| 4.1 | 4.48 | Identify the process steps for deploying VMware NSX Federation in VCF |
| 4.2 | 4.49 | Configure NSX components |
| 4.3 | 4.50 | Identify the process for deploying an NSX Edge Cluster |
| 4.4 | 4.51 | Identify the process for creating an NSX Tier-0 gateway |
| 4.5 | 4.53 | Identify the process steps to create an NSX Logical Segment |
| 4.6 | 4.54 | Identify the process for creating an NSX Tier-1 gateway |
| 4.7 | 4.55 | Deploy and manage Virtual Private Cloud (VPC) |
| 4.9 | 4.58 | Configure Projects and Tenancy in NSX |
| 4.10 | 4.59 | Configure advanced NSX integrations |
| 4.11 | 4.60 | Perform operational tasks in a VMware NSX environment |
So the work that is genuinely new to you is the design section, the troubleshooting section, and two build objectives the Administrator exam splits up differently: stateful services and monitoring tooling. That is sections A to E, I, P, and Q to V of the workbook below. If you are coming the other way, from this exam towards the Administrator one, the same ten objectives carry across.
FourthWhere to practise, and how
NSX is the most practisable part of VCF, because most of it runs without the rest of the stack. Three routes:
- A work or customer environment, for whatever your role authorises. The build and operational objectives reward this more than any amount of reading.
- VMware Hands-on Labs, free and in a browser. Check the current catalogue for VCF 9 networking labs, and confirm the version each one runs before you rely on it.
- A nested lab. NSX is friendlier to nesting than vSAN is. A Manager, two edges and a handful of nested hosts will carry most of sections F to S, including every troubleshooting drill.
For the troubleshooting section, do not wait to meet the faults in production. Create each one yourself first. A fault you built is a fault you understand, and you already know the answer, so you can judge whether your diagnostic order was any good. Section R and S are written that way on purpose.
Workbook195 tasks, in build order
Sections A to E are written design work. Sections F to P are performed. Section Q is about choosing the right diagnostic tool, R and S are faults you create and then diagnose, and T and U are the two describe objectives, ECMP and the packet walk. Section V is a set of timed drills. Numbers in grey at the right are the objectives, so a weak score report points you back at a group of tasks.
Written tasks. Get the vocabulary right before you build anything with it.
- 1Draw the NSX management, control and data planes and name what lives in each.3.2›
- 2Write what the NSX Manager cluster does, how many nodes it has, and what a virtual IP buys you.3.2›
- 3Write the difference between a host transport node and an edge transport node, and what each can do alone.3.2›
- 4Write what a transport zone is, the two types, and what a node joining one gains.3.2›
- 5Explain the tunnel endpoint: what it is, where it lives, and what rides over it.3.2›
- 6Draw the path of an east-west packet between two virtual machines on different hosts, same segment.3.2›
- 7Draw the same for different segments, and show where the distributed router does its work.3.2›
- 8Write what the distributed firewall is attached to, and why that placement matters.3.2›
- 9List the NSX components a VCF deployment creates for you, and which ones you still create by hand.3.2›
- 10Write the version and interoperability checks you would run before any NSX change in a VCF fleet.3.2›
Objective 3.3 in one phrase. Most design questions in this exam resolve here.
- 11Write which NSX functions are distributed across hosts and which are centralised on edges.3.3›
- 12Write the test you apply to decide: if the function needs to see every packet of a flow, it is centralised.3.3›
- 13Given a design with only east-west traffic between segments, state whether an edge cluster is needed and justify it.3.3›
- 14Given a design needing NAT and a gateway firewall, state what that forces and why.3.3›
- 15Draw a topology where traffic is hairpinned to an edge unnecessarily, then redraw it without the hairpin.3.3›
- 16Write the throughput consequence of centralising a service, and where the ceiling comes from.3.3›
- 17Design a connectivity solution for three tenants that must not route to each other, and justify centralised or distributed for each decision.3.3›
- 18Write when you would put a service on the Tier-0 and when on the Tier-1, with the reason for each.3.3›
Objective 3.4. Know the options before you are asked to choose between them.
- 19Write the multisite options available in NSX and what problem each one solves.3.4›
- 20Write the difference between a stretched design and a Federation design, in one sentence each.3.4›
- 21Write what Federation gives you that two independent NSX instances do not.3.4›
- 22Record the latency and bandwidth requirements between sites, and which link each applies to.3.4›
- 23Design a two-site solution for disaster recovery, and say what is stretched and what is rebuilt.3.4›
- 24Design a two-site solution for active-active workloads, and say what changes from the recovery design.3.4›
- 25Write what happens to each design when the inter-site link fails, step by step.3.4›
- 26Write the failure domain of each option: what one failure can take out.3.4›
- 27Write which multisite option you would choose for a data residency requirement, and why the others fail it.3.4›
Objective 3.5. Designing NSX across a VCF fleet rather than a single instance.
- 28Write what a fleet means for NSX: how many instances, and what is shared between them.3.5›
- 29Write the decision of one NSX instance per workload domain against one shared across several.3.5›
- 30Write what drives the NSX Manager sizing, and the sizes available.3.5›
- 31Write how NSX lifecycle works in a VCF fleet, and what upgrades it alongside.3.5›
- 32Write the identity and certificate design across a fleet of NSX instances.3.5›
- 33Write the backup design for a fleet: how many targets, how often, and the restore order.3.5›
- 34Write the object count drivers, and which design model grows objects fastest.3.5›
- 35Design the fleet networking for an estate that will double in two years, and say what you did to leave room.3.5›
Objective 3.6. Where performance comes from, and what it costs.
- 36Write what Enhanced Data Path is, note that it is the default host switch mode in VCF 9, and record what each mode requires of the host and the NIC.3.6›
- 37Write the trade-off between EDP interrupt mode and poll mode: what you gain and what you give up.3.6›
- 38Write where NIC offloads help NSX traffic, and which offloads matter for overlay.3.6›
- 39Write the MTU design across the fabric and what breaks when one hop is wrong.3.6›
- 40Write the edge node form factor decision, virtual against bare metal, with the throughput reason.3.6›
- 41Write how you would scale north-south throughput without replacing hardware.3.6›
- 42Given a latency-sensitive workload, make three design decisions to protect it and justify each.3.6›
- 43Write what you would measure to prove an optimisation worked, before and after.3.6›
Build section starts here. Everything from F onward is performed where you can.
- 44Record the process to deploy an NSX Edge cluster, including form factors and the networking each needs.4.3›
- 45Deploy two edge transport nodes and confirm their tunnels to the host transport nodes come up.4.3›
- 46Form an edge cluster from those nodes and check its status.4.3›
- 47Write what the edge cluster is required for that host transport nodes cannot provide.4.3›
- 48Record the uplink design for the edges: how many, to which VLANs, and with what teaming.4.3›
- 49Add a third edge node to an existing cluster and record what rebalances and what does not.4.3›
- 50Put an edge node into maintenance mode and watch where its services move.4.3›
- 51Record the sizing of your edge nodes and the throughput that size is rated for.4.3›
The north-south boundary, and the mode decision that shapes everything above it.
- 52Create a Tier-0 gateway in active-active mode with Stateful left off, and record what that rules out.4.4›
- 53Create a Tier-0 in active-active with Stateful enabled, and confirm you can configure stateful NAT on it.4.4›
- 54Create a Tier-0 in active-standby and configure a stateful service, and record which node is active.4.4›
- 55Write the three modes side by side with what each allows, because the old rule that active-active is always stateless is out of date.4.4›
- 56Record the scale-out rule for stateful active-active: add edge nodes in even numbers so each has a backup.4.4›
- 57Create the uplink interfaces, one per edge node, and confirm the gateway is up on each.4.4›
- 58Configure BGP to two upstream routers and bring both sessions to established.4.4›
- 59Configure route redistribution and prove a segment prefix reaches the upstream router.4.4›
- 60Create a VRF on the Tier-0 and record what it inherits from the parent and what it does not.4.4›
- 61Attach two tenants to two VRFs and prove their routing tables stay separate.4.4›
- 62Record that the high availability mode is fixed at creation, and what that means for your design.4.4›
The tenant-facing layer.
- 63Create a Tier-1 gateway and link it to the Tier-0.4.6›
- 64Assign an edge cluster to the Tier-1 and record when that is required and when it is not.4.6›
- 65Enable route advertisement and confirm the Tier-0 learns the routes.4.6›
- 66Create an overlay logical segment on the Tier-1 and give it a gateway address.4.5›
- 67Attach a virtual machine and test reachability in three steps: gateway, another host, outside.4.5›
- 68Create a VLAN-backed segment and write when you would use one instead of overlay.4.5›
- 69Create a segment with no gateway attached and record what it is useful for.4.5›
- 70Move a Tier-1 between edge clusters with a continuous ping running, and record the loss.4.6›
- 71Delete a segment that still has a workload attached, and record what stops you.4.5›
Objective 4.8, and one of only two Section 4 objectives this exam does not share with the Administrator exam.
- 72List the stateful services NSX offers and where each can run.4.8›
- 73Configure source NAT on a Tier-1 so a segment leaves with a predictable address, and verify at the far end.4.8›
- 74Configure destination NAT to publish one internal service, and restrict it by port.4.8›
- 75Write when NAT is the right answer and when a load balancer is.4.8›
- 76Configure a gateway firewall rule and prove it is enforced at the gateway, not at the vNIC.4.8›
- 77Configure DHCP with a local server on the Tier-1 and confirm a lease.4.8›
- 78Configure a DHCP relay to an external server and verify the request arrives with the right relay address.4.8›
- 79Configure a VPN and record what it requires of the edge cluster.4.8›
- 80Record what every stateful service has in common: it needs an edge cluster and a single owner of the flow.4.8›
- 81Record which stateful services you may run on a Tier-0 in each high availability mode.4.8›
Self-service networking, and a large part of what is new in VCF 9.
- 82Create an NSX Project to hold the VPCs.4.7›
- 83Create a VPC connectivity profile and record what it controls.4.7›
- 84Create a VPC inside the project and list the objects NSX created underneath it.4.7›
- 85Create a private subnet and a public subnet, and record where each address range came from.4.7›
- 86Attach a workload to each subnet and test what can reach what.4.7›
- 87Publish a workload from a private subnet externally, and trace every hop.4.7›
- 88Configure a distributed firewall rule inside the VPC and prove it follows the workload across hosts.4.7›
- 89Configure a Transit Gateway and record what it connects.4.7›
- 90Record what a tenant can do in a VPC without ever contacting the network team.4.7›
- 91Delete a VPC and record what is cleaned up and what is left behind.4.7›
Objective 4.9, shared word for word with the Administrator exam.
- 92Create a Project and assign a quota to it.4.9›
- 93Map a tenant group to the project with the appropriate role.4.9›
- 94Create objects inside the project and confirm a tenant administrator sees only their own.4.9›
- 95Confirm a provider administrator sees every project from above.4.9›
- 96Record which objects stay shared across projects, because that is where the boundary actually sits.4.9›
- 97Exhaust a project quota and record the error the tenant receives.4.9›
- 98Write the difference between a Project and a VPC in one sentence each.4.9›
Objective 4.1. Know the process before you are asked to order its steps.
- 99Write the Federation deployment order: Global Manager, standby Global Manager, then register each Local Manager.4.1›
- 100Write what the Global Manager owns and what stays with the Local Manager.4.1›
- 101Configure remote tunnel endpoints on the edge nodes and record why they are needed.4.1›
- 102Create a stretched segment from the Global Manager and confirm it appears at both sites.4.1›
- 103Create a local object on a Local Manager and confirm the Global Manager does not manage it.4.1›
- 104Record the one-way nature of importing local objects into the Global Manager.4.1›
- 105Write the span of an object and what choosing one site against both actually changes.4.1›
- 106Record what a stretched Tier-0 in active-active mode cannot do, and why.4.1›
- 107Fail one site and record what the Global Manager still lets you do.4.1›
Objective 4.2, the broadest in the blueprint. Work through the surface methodically.
- 108Prepare a cluster of hosts as transport nodes and verify each one individually.4.2›
- 109Create an uplink profile and record what it sets: teaming, MTU, transport VLAN.4.2›
- 110Create an IP pool for tunnel endpoints and record what happens when it is exhausted.4.2›
- 111Create a transport zone and add nodes to it.4.2›
- 112Configure a security group with dynamic membership based on tags.4.2›
- 113Create a distributed firewall policy with rules, and set the default posture deliberately.4.2›
- 114Configure an IP discovery profile and record what fails without one.4.2›
- 115Configure a segment security profile and record what each protection prevents.4.2›
- 116Configure a QoS profile and apply it to a segment.4.2›
- 117Change an uplink profile on a live transport node and record the impact.4.2›
- 118Record which of these configurations VCF created for you and which you created by hand.4.2›
Objective 4.10, shared with the Administrator exam.
- 119Integrate NSX with VCF Operations for Networks and confirm topology appears.4.10›
- 120Integrate NSX with an external identity source and sign in as a mapped group member.4.10›
- 121Integrate NSX with a load balancer such as Avi, and record what each product then owns.4.10›
- 122Record how NSX integrates with the Supervisor, and which objects appear per namespace.4.10›
- 123Record what the Antrea integration gives you for container workloads.4.10›
- 124Configure an automation or API integration and make one change through it rather than the interface.4.10›
- 125Record what each integration costs: another credential, another certificate, another upgrade dependency.4.10›
Objective 4.11, shared with the Administrator exam. Day 2 for the network.
- 126Configure a Manager backup to an SFTP target, with a passphrase stored separately.4.11›
- 127Run a backup on demand and confirm the files land on the target.4.11›
- 128Restore a Manager from backup in a lab and record the restore order.4.11›
- 129Configure syslog export from NSX Manager and prove a line arrives at the collector.4.11›
- 130Take a support bundle and open it, so you know what you are sending.4.11›
- 131Check Manager cluster health and the status of every transport node.4.11›
- 132Replace an NSX certificate and list everything that must be re-registered afterwards.4.11›
- 133Record the upgrade order for NSX within a VCF domain and who drives it.4.11›
- 134Record what a configuration backup does not contain, so you know the limits of a restore.4.11›
Objective 4.12. Knowing which product answers which question.
- 135List the VCF products that can monitor an NSX implementation, and what each one is best at.4.12›
- 136Given a question about flow between two workloads, say which product answers it.4.12›
- 137Given a question about Manager health over time, say which product answers it.4.12›
- 138Given a question about who changed a firewall rule, say which product answers it.4.12›
- 139Build an alert on an NSX condition and trigger it deliberately.4.12›
- 140Build a dashboard showing NSX health for an operator, and say what it deliberately leaves out.4.12›
- 141Record the data each product collects and how long it keeps it.4.12›
Section 5 starts here, and it is the part the other VCF exams do not test at all.
- 142List the NSX troubleshooting tools available and the question each one answers.5.1›
- 143Given a dropped packet between two virtual machines, name the tool you reach for first and why.5.1›
- 144Given a route that is not being learned, name the tool and the specific view.5.1›
- 145Given a tunnel that will not come up, name the tool and the first thing you check.5.1›
- 146Use Traceflow between two workloads and read every hop it reports.5.1›
- 147Use a path trace in VCF Operations for Networks and compare it with the Traceflow result.5.1›
- 148Record what the command line gives you that the interface does not, and when you need it.5.1›
- 149Write the order you would use the tools in, from cheapest to most invasive.5.1›
Create each fault yourself before you diagnose it. A fault you built is a fault you understand.
- 150Break the MTU on one hop and diagnose the result from the symptoms alone.5.2›
- 151Break the transport VLAN on one host and watch which tunnels drop.5.2›
- 152Exhaust the tunnel endpoint IP pool and diagnose a host that will not prepare.5.2›
- 153Stop one NSX Manager node and record what still works and what does not.5.2›
- 154Let a certificate expire in a lab and record the symptom it produces.5.2›
- 155Break time synchronisation on a transport node and record what fails.5.2›
- 156Put an edge node in a state where its tunnels are down, and work out why from the status alone.5.2›
- 157Record the first four checks you would run on any NSX infrastructure problem, in order.5.2›
The largest troubleshooting objective, and the one closest to real incidents.
- 158Create a distributed firewall rule that drops traffic, then find it with Traceflow.5.3›
- 159Create a gateway firewall rule that drops traffic, and note how the symptom differs.5.3›
- 160Break a BGP session deliberately with a wrong autonomous system number, and diagnose from the session state.5.3›
- 161Remove route redistribution and diagnose why a prefix stopped being advertised.5.3›
- 162Misconfigure a NAT rule so return traffic fails, and work out why from one direction working.5.3›
- 163Attach a workload to the wrong segment and diagnose it from the address it receives.5.3›
- 164Create an asymmetric path through two edges and record what breaks when a stateful service is involved.5.3›
- 165Break DHCP and separate a relay problem from a scope problem from a segment problem.5.3›
- 166Diagnose a workload that reaches other workloads but not the outside world, and list the possible causes in order.5.3›
- 167Write the one question that most quickly narrows any connectivity fault: how far does it get.5.3›
Objective 5.4. A describe objective, so make sure you can describe it precisely.
- 168Write what Equal Cost Multi-Path is and the problem it solves.5.4›
- 169Write what ECMP requires: the mode, the number of uplinks, and what the upstream must do.5.4›
- 170Configure ECMP on a Tier-0 and confirm traffic uses more than one path.5.4›
- 171Write how a flow is pinned to a path, and why that matters for stateful services.5.4›
- 172Write the high availability model for each Tier-0 mode and what failover looks like in each.5.4›
- 173Fail one edge node and measure how long traffic takes to recover.5.4›
- 174Write the difference between ECMP for throughput and high availability for resilience, since they are often confused.5.4›
- 175Record the maximum number of ECMP paths and what sets it.5.4›
Objective 5.5. Be able to narrate this out loud, hop by hop.
- 176Walk a packet between two virtual machines on the same segment, same host.5.5›
- 177Walk a packet between two virtual machines on the same segment, different hosts.5.5›
- 178Walk a packet between two segments on the same Tier-1, same host.5.5›
- 179Walk a packet between two segments on the same Tier-1, different hosts, and show where the distributed router acts.5.5›
- 180Walk a packet from a workload to the outside world, through Tier-1 and Tier-0 to the uplink.5.5›
- 181Walk the return packet and show where NAT, if present, reverses.5.5›
- 182Walk a packet between two Tier-1 gateways under the same Tier-0.5.5›
- 183Walk a packet across a Federation stretched segment between two sites.5.5›
- 184For each walk, mark where the distributed firewall is evaluated.5.5›
- 185Narrate the north-south walk out loud in under two minutes, with no notes.5.5›
Do this section twice in the final week, from a clean start, timing yourself.
- 186Deploy an edge cluster, a Tier-0 with BGP, a Tier-1 and a segment, and get a workload talking to the outside. 45 minutes.4.3›
- 187Create a Project, a VPC, two subnets, and publish one workload externally. 30 minutes.4.7›
- 188Configure SNAT, DNAT, a gateway firewall rule and DHCP on one Tier-1. 25 minutes.4.8›
- 189Write the Federation deployment order and object span rules from memory. 10 minutes.4.1›
- 190Create three faults for a colleague, swap, and diagnose theirs. 30 minutes.5.2›
- 191Diagnose a broken BGP session and a dropped flow, start to finish. 20 minutes.5.3›
- 192Narrate the full north-south packet walk, then the Federation one. 10 minutes.5.5›
- 193Write the centralised against distributed decision table from memory. 10 minutes.3.3›
- 194Design a two-site solution from a one-page brief and justify every decision. 35 minutes.3.4›
- 195Configure a Manager backup, run it, and write the restore order from memory. 15 minutes.4.11›
How to use itFour weeks, if that is what you have
| Week | Sections | Focus |
|---|---|---|
| 1 | A to E | Architecture, centralised against distributed, multisite, fleet and acceleration design |
| 2 | F to J | Edge clusters, Tier-0, Tier-1 and segments, stateful services, VPCs |
| 3 | K to P | Tenancy, Federation, component configuration, integrations, operations, monitoring |
| 4 | Q to V | Troubleshooting tools, faults you create yourself, ECMP, packet walks, then section V twice |
Two pieces of advice. The centralised against distributed table in section B resolves more design questions than anything else in this blueprint, so learn it until you can write it from memory. And objective 5.5 is a describe objective: be able to narrate the north-south packet walk out loud, in under two minutes, with no notes. If you can do that, you understand NSX routing.
Work through it online: the interactive workbook. All 195 tasks with what they need first, the steps, what you end up with, and a diagram, searchable and filterable by section or objective.
Or take it with you: download the PDF (195 tasks, 10 pages). Print it, tick tasks off on paper, and bring the gaps back to the online version.
Ten objectives here are shared word for word with the Administrator exam. Practise the rest with the VCAP-VCF Administrator lab tasks.
Networking is one of the five technology VCAPs. See where it sits in the complete VCF certification roadmap: all thirteen certifications with their codes and blueprints, the three year validity, and the order worth taking them in.
Exam details are from the published Broadcom exam guide for 3V0-25.25, last updated 30 December 2025, and are accurate at the time of writing. Broadcom revises blueprints regularly, so confirm the current version before you book. Practice tasks here are my own, written from the published objectives; they are not exam content.








DrJha