You can add a sub interface on a trunk vNIC, and use this sub interface in various NSX Edge services.
Trunk interfaces can be of the following types:
- VLAN trunk is standard and works with any version of ESXi. This type of interface is used to bring a tagged VLAN traffic into Edge.
- VXLAN trunk works with NSX version 6.1, and later. This type of interface is used to bring VXLAN traffic into Edge.
The following Edge services can use a sub interface:
- DHCP
- Routing (BGP and OSPF)
- Load Balancer
- IPSec VPN: You can configure IPSec VPN only as an uplink interface. Use sub interfaces when you want private traffic to traverse through the IPSec tunnel. If an IPSec policy is configured for private traffic, sub interface acts as a gateway for the private local subnet.
- L2 VPN
- NAT
. A sub interface cannot be used for HA or Logical Firewall. However, you can use the IP address of the sub interface in an edge firewall rule.
Procedure
Results
What to do next
Configure a VLAN trunk if the sub interface added to a trunk vNic is backed by a standard port group. See Configure VLAN Trunk.