The following tables outline specific functions available by edition. VMware NSX+ is available as a single download image and cloud connectivity is required to enable specific functionality.
NSX+ Multi-Cloud Services |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Policy Management for On-Premises Sites |
Yes |
Yes |
Yes |
Yes |
Yes |
On-Premises Sites |
2 |
4 |
Configuration Maximum |
Configuration Maximum |
Configuration Maximum |
Upgrade Recommendations |
Yes |
Yes |
Yes |
Yes |
Yes |
Keyless Activation |
Yes |
Yes |
Yes |
Yes |
Yes |
Cloud Based NSX Infrastructure Monitoring |
Yes |
Yes |
Yes |
Yes |
Yes |
Distributed Security |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Firewall for NSX Switch Ports |
Yes |
Yes |
Yes |
Yes |
Yes |
Distributed Firewall for VDS Switch Ports |
Yes |
Yes |
Yes |
Yes |
Yes |
Stateful L2 and L3 Rules |
Yes |
Yes |
Yes |
Yes |
Yes |
Stateless L2 and L3 Rules |
Yes |
Yes |
Yes |
Yes |
Yes |
Distributed FQDN Filtering |
No |
Yes |
Yes |
Yes |
Yes |
Basic L7 Application Identification Rules |
No |
Yes |
Yes |
Yes |
Yes |
Advanced L7 Application Identification Rules |
No |
No |
No |
Yes |
Yes |
Malicious IP Filtering |
No |
Yes |
Yes |
Yes |
Yes |
Distributed Flood Protection |
Yes |
Yes |
Yes |
Yes |
Yes |
Agent-Based Enforcement for Physical Servers |
Yes |
Yes |
Yes |
Yes |
Yes |
Stateful L2 and L3 Rules with DPU Support |
No |
No |
Yes |
No |
No |
Stateless L2 and L3 Rules with DPU Support |
No |
No |
Yes |
No |
No |
Distributed User Identity Firewall |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Identity Firewall using Guest Introspection |
No |
Yes |
Yes |
Yes |
Yes |
Distributed Identity Firewall using Active Directory Event Server |
No |
Yes |
Yes |
Yes |
Yes |
Distributed Identity Firewall using third-party log sources |
No |
No |
No |
Yes |
Yes |
Distributed Threat Prevention |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Intrusion Detection Service (IDS) |
No |
No |
No |
No |
Yes |
Distributed Behavioral IDS |
No |
No |
No |
No |
Yes |
Distributed Intrusion Prevention Service (IPS) |
No |
No |
No |
No |
Yes |
Distributed Advanced Threat Prevention |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Malware Detection and Prevention |
No |
No |
No |
No |
No |
Cloud Sandboxing and Artifact Analysis |
No |
No |
No |
No |
No |
Distributed IDS Event Forwarding to NDR |
No |
No |
No |
No |
Yes |
Network Detection and Response (NDR) |
No |
No |
No |
No |
No |
Network Traffic Analytics (on-premises) |
No |
No |
No |
No |
No |
Distributed Service Insertion Integrations |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Endpoint Protection |
Yes |
Yes |
Yes |
No |
No |
Distributed Network Introspection |
No |
No |
No |
No |
No |
Policy, Tagging and Grouping |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Object Tagging / Security Tags |
Yes |
Yes |
Yes |
Yes |
Yes |
Network Centric Grouping |
Yes |
Yes |
Yes |
Yes |
Yes |
Workload Centric Grouping |
Yes |
Yes |
Yes |
Yes |
Yes |
IP Based Groups |
Yes |
Yes |
Yes |
Yes |
Yes |
MAC Based Groups |
Yes |
Yes |
Yes |
Yes |
Yes |
Tag Based Rules |
Yes |
Yes |
Yes |
Yes |
Yes |
Firewall Operations |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Firewall Logging |
Yes |
Yes |
Yes |
Yes |
Yes |
Distributed Firewall based IPFIX |
Yes |
Yes |
Yes |
Yes |
Yes |
Rule Hit Count, Popularity Index, Flow Statistics |
Yes |
Yes |
Yes |
Yes |
Yes |
Firewall Drafts |
Yes |
Yes |
Yes |
Yes |
Yes |
Gateway Security |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Stateful L3 Rules |
Yes |
Yes |
Yes |
No |
No |
Stateless L3 Rules |
Yes |
Yes |
Yes |
No |
No |
Basic L7 Application Identification Rules |
Yes |
Yes |
Yes |
No |
No |
Advanced L7 Application Identification Rules |
No |
No |
No |
No |
No |
URL Filtering |
No |
No |
No |
No |
No |
Gateway Flood Protection |
Yes |
Yes |
Yes |
No |
No |
Gateway User Identity Firewall |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Gateway Identity Firewall using Active Directory Event Server |
No |
No |
No |
No |
No |
Gateway Identity Firewall using third-party log sources |
No |
No |
No |
No |
No |
Gateway Threat Prevention |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Gateway TLS Inspection |
No |
No |
No |
No |
No |
Gateway Intrusion Detection Service (IDS) - Behavioral |
No |
No |
No |
No |
No |
Gateway Intrusion Prevention Service (IPS) |
No |
No |
No |
No |
No |
Gateway Advanced Threat Prevention |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Malware Detection |
No |
No |
No |
No |
No |
Cloud Sandboxing and Artifact Analysis |
No |
No |
No |
No |
No |
Malware / File Event Forwarding to NDR |
No |
No |
No |
No |
No |
Gateway Service Insertion Integrations |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Gateway Network Introspection |
Yes |
Yes |
Yes |
No |
No |
Gateway Firewall High Availability |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Active/Standby Gateway Firewall Services |
Yes |
Yes |
Yes |
No |
No |
Active/Active Gateway Firewall Services |
No |
No |
Yes |
No |
No |
NAT |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
NAT on North/South and East/West Logical Routers |
Yes |
Yes |
Yes |
No |
No |
Source NAT |
Yes |
Yes |
Yes |
No |
No |
Destination NAT |
Yes |
Yes |
Yes |
No |
No |
NAT N:N |
Yes |
Yes |
Yes |
No |
No |
Stateless NAT |
Yes |
Yes |
Yes |
No |
No |
NAT Logging |
Yes |
Yes |
Yes |
No |
No |
NAT64 |
No |
Yes |
Yes |
No |
No |
Active / Active NAT Services |
No |
No |
Yes |
No |
No |
VPN |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
L2 VPN |
Yes |
Yes |
Yes |
No |
No |
IPv4 L3 VPN |
Yes |
Yes |
Yes |
No |
No |
IPv6 L3 VPN |
No |
Yes |
Yes |
No |
No |
Switching |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
vSphere Distributed Switch |
Yes |
Yes |
Yes |
Yes |
Yes |
VLAN Backed Logical Switching |
Yes |
Yes |
Yes |
Yes |
Yes |
Overlay Backed Logical Switching |
Yes |
Yes |
Yes |
No |
No |
Multiple TEP Support |
Yes |
Yes |
Yes |
No |
No |
Spoofguard |
Yes |
Yes |
Yes |
Yes |
Yes |
LACP (Edge and Host) |
Yes |
Yes |
Yes |
Yes |
Yes |
L2 Multicast |
Yes |
Yes |
Yes |
No |
No |
L3 Multicast |
No |
Yes |
Yes |
No |
No |
Enhanced Datapath - Standard |
No |
Yes |
Yes |
No |
No |
Enhanced Datapath - Performance |
No |
Yes |
Yes |
No |
No |
Enhanced Datapath - Standard for DPUs8 |
No |
Yes |
Yes |
No |
No |
Enhanced Datapath - Performance for DPUs |
No |
No |
Yes |
No |
No |
Uniform Passthrough for DPUs |
No |
No |
Yes |
No |
No |
Quality of Service (QoS) |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
QoS Marking |
Yes |
Yes |
Yes |
No |
No |
QoS DSCP Trust Boundary |
Yes |
Yes |
Yes |
No |
No |
QoS Rate-Limit Northbound Traffic on Tier-1 Gateway |
No |
Yes |
Yes |
No |
No |
L2 Bridging to Physical Environment |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Software Based L2 Bridge to Physical Environments |
Yes |
Yes |
Yes |
No |
No |
Routing |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Distributed Routing |
Yes |
Yes |
Yes |
No |
No |
Multi-Tier Routing |
Yes |
Yes |
Yes |
No |
No |
Active / Active Dynamic Routing with ECMP |
Yes |
Yes |
Yes |
No |
No |
Active / Standby Redundancy for Routing |
Yes |
Yes |
Yes |
No |
No |
Virtual Routing and Forwarding (Tier-0 Gateway VRFs) |
No |
Yes |
Yes |
No |
No |
EVPN |
No |
No |
Yes |
No |
No |
OSPF v2 |
Yes |
Yes |
Yes |
No |
No |
Static Routing - IPv4 |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Static Routing |
Yes |
Yes |
Yes |
No |
No |
BFD |
Yes |
Yes |
Yes |
No |
No |
Null Routes |
Yes |
Yes |
Yes |
No |
No |
Device Routes |
Yes |
Yes |
Yes |
No |
No |
Static Routing - IPv6 |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Static Routing |
Yes |
Yes |
Yes |
No |
No |
BFD |
Yes |
Yes |
Yes |
No |
No |
Null Routes |
Yes |
Yes |
Yes |
No |
No |
Device Routes |
Yes |
Yes |
Yes |
No |
No |
BGP - IPv4 Unicast |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
eBGP |
Yes |
Yes |
Yes |
No |
No |
eBGP Multihop |
Yes |
Yes |
Yes |
No |
No |
iBGP |
Yes |
Yes |
Yes |
No |
No |
Graceful Restart |
Yes |
Yes |
Yes |
No |
No |
4-byte ASN |
Yes |
Yes |
Yes |
No |
No |
BFD |
Yes |
Yes |
Yes |
No |
No |
BGP - IPv6 Unicast |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
eBGP |
No |
Yes |
Yes |
No |
No |
eBGP Multihop |
No |
Yes |
Yes |
No |
No |
iBGP |
No |
Yes |
Yes |
No |
No |
Graceful Restart |
No |
Yes |
Yes |
No |
No |
4-byte ASN |
No |
Yes |
Yes |
No |
No |
BFD |
No |
Yes |
Yes |
No |
No |
Route Maps |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Match on Prefix-List and Community-List |
Yes |
Yes |
Yes |
No |
No |
Set Weight, MED, AS Path, Prepending, Local Preference, and Community |
Yes |
Yes |
Yes |
No |
No |
Other Routing |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
High Availability Virtual IP (HA VIP) |
Yes |
Yes |
Yes |
No |
No |
Route Redistribution |
Yes |
Yes |
Yes |
No |
No |
IP Prefix-Lists |
Yes |
Yes |
Yes |
No |
No |
Per Interface RPF Check |
Yes |
Yes |
Yes |
No |
No |
DNS, DHCP and IPAM (DDI) |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
IPAM |
Yes |
Yes |
Yes |
No |
No |
IP Blocks |
Yes |
Yes |
Yes |
No |
No |
IP Subnets |
Yes |
Yes |
Yes |
No |
No |
IP Pools |
Yes |
Yes |
Yes |
No |
No |
IPv4 DHCP Server |
Yes |
Yes |
Yes |
No |
No |
IPv6 DHCP Server |
No |
Yes |
Yes |
No |
No |
IPv4 DHCP Relay |
Yes |
Yes |
Yes |
No |
No |
IPv6 DHCP Relay |
No |
Yes |
Yes |
No |
No |
IPv4 DHCP Static Bindings / Fixed Addresses |
Yes |
Yes |
Yes |
No |
No |
IPv6 DHCP Static Bindings / Fixed Addresses |
No |
Yes |
Yes |
No |
No |
IPv4 DNS Relay / DNS Proxy |
Yes |
Yes |
Yes |
No |
No |
Load Balancing |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Protocols |
|||||
TCP (L4-L7) |
No |
No |
No |
No |
No |
UDP |
No |
No |
No |
No |
No |
HTTP |
No |
No |
No |
No |
No |
Load Balancing Methods |
|||||
Round Robin |
No |
No |
No |
No |
No |
Source IP Hash |
No |
No |
No |
No |
No |
Least Connections |
No |
No |
No |
No |
No |
L7 Application Rules with RegEx Support |
No |
No |
No |
No |
No |
Heath Checks |
No |
No |
|||
TCP |
No |
No |
No |
No |
No |
ICMP |
No |
No |
No |
No |
No |
UDP |
No |
No |
No |
No |
No |
HTTP |
No |
No |
No |
No |
No |
HTTPS |
No |
No |
No |
No |
No |
Monitoring |
|||||
View VIP / Pool / Server Objects |
No |
No |
No |
No |
No |
View VIP / Pool / Server Statistics |
No |
No |
No |
No |
No |
View Global Statistics VIP Sessions |
No |
No |
No |
No |
No |
Load Balancing Automation |
|||||
Pool Members Based on vCenter Context or IP Addresses |
No |
No |
No |
No |
No |
Other |
|||||
Connection Throttling |
No |
No |
No |
No |
No |
High-Availability |
No |
No |
No |
No |
No |
Modern Apps |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Container Networking and Security |
No |
Yes |
Yes |
No |
No |
VMware Container Networking with Project Antrea Enterprise |
No |
Yes |
Yes |
No |
No |
Distributed Load Balancing |
No |
Yes |
Yes |
No |
No |
Automation |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
REST API |
Yes |
Yes |
Yes |
Yes |
Yes |
Hierarchical Policy API |
Yes |
Yes |
Yes |
Yes |
Yes |
JSON Support |
Yes |
Yes |
Yes |
Yes |
Yes |
OpenAPI / Swagger Spec |
Yes |
Yes |
Yes |
Yes |
Yes |
Java SDK |
Yes |
Yes |
Yes |
Yes |
Yes |
Python SDK |
Yes |
Yes |
Yes |
Yes |
Yes |
Terraform Provider5 |
Yes |
Yes |
Yes |
Yes |
Yes |
Ansible Modules5 |
Yes |
Yes |
Yes |
Yes |
Yes |
Integration with Aria Automation1,5 |
Yes |
Yes |
Yes |
Yes |
Yes |
Integration with vCloud Director1,5 |
Yes |
Yes |
Yes |
Yes |
Yes |
Integration with VMware Integrated OpenStack1,5 |
Yes |
Yes |
Yes |
Yes |
Yes |
Multi-Tenancy |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Projects (User Defined) |
1 |
1 |
Configuration Maximum |
No |
No |
NSX VPCs |
8 |
8 |
Configuration Maximum |
No |
No |
Platform |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
ESXi Support |
Yes |
Yes |
Yes |
Yes |
Yes |
Manager / Controller Clustering |
Yes |
Yes |
Yes |
Yes |
Yes |
vCenter Integration |
Yes |
Yes |
Yes |
Yes |
Yes |
Multi-vCenter® Networking and Security |
No |
Yes |
Yes |
Yes |
Yes |
Federation |
No |
No |
No |
No |
No |
Edge in VM Form Factor |
Yes |
Yes |
Yes |
No |
No |
Edge in Bare-Metal Form Factor for Routing |
Yes |
Yes |
Yes |
No |
No |
Edge in Bare-Metal Form Factor for Gateway Firewall |
No |
No |
No |
No |
No |
DPDK Optimized Forwarding |
Yes |
Yes |
Yes |
No |
No |
Dual Stack (IPv4/IPv6) External Management |
Yes |
Yes |
Yes |
No |
No |
Authentication and Authorization |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Authentication using Workspace ONE Access1,4 |
Yes |
Yes |
Yes |
Yes |
Yes |
Direct Active Directory Integration via LDAP |
Yes |
Yes |
Yes |
Yes |
Yes |
Authentication via OpenLDAP |
Yes |
Yes |
Yes |
Yes |
Yes |
Session Based Authentication |
Yes |
Yes |
Yes |
Yes |
Yes |
Certificate Based Authentication (Principle Identity) |
Yes |
Yes |
Yes |
Yes |
Yes |
Role Based Access Control |
Yes |
Yes |
Yes |
Yes |
Yes |
Log Management |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Aria Operations for Logs Integration (Plugin)2 |
Yes |
Yes |
Yes |
Yes |
Yes |
Splunk Integration (Plugin)3 |
Yes |
Yes |
Yes |
Yes |
Yes |
Installation |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Automated Manager Deployment |
Yes |
Yes |
Yes |
Yes |
Yes |
Manual Manager Deployment |
Yes |
Yes |
Yes |
Yes |
Yes |
Automated Edge Deployment |
Yes |
Yes |
Yes |
No |
No |
Manual Edge Deployment |
Yes |
Yes |
Yes |
No |
No |
Automated Host Preparation by Cluster |
Yes |
Yes |
Yes |
Yes |
Yes |
Operations |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Port Mirroring |
Yes |
Yes |
Yes |
Yes |
Yes |
Traceflow |
Yes |
Yes |
Yes |
Yes |
Yes |
NSX Live Traffic Analysis |
Yes |
Yes |
Yes |
Yes |
Yes |
Tunnel Health Monitoring |
Yes |
Yes |
Yes |
No |
No |
Port Connectivity Tool |
Yes |
Yes |
Yes |
No |
No |
Switch Based IPFIX |
Yes |
Yes |
Yes |
Yes |
Yes |
LLDP |
Yes |
Yes |
Yes |
Yes |
Yes |
Automated Technical Support Bundles |
Yes |
Yes |
Yes |
Yes |
Yes |
Packet Capture |
Yes |
Yes |
Yes |
Yes |
Yes |
Backup and Restore |
Yes |
Yes |
Yes |
Yes |
Yes |
SNMP v1/v2/v3 with Traps |
Yes |
Yes |
Yes |
Yes |
Yes |
Time-Series Metrics |
No |
No |
No |
No |
No |
Upgrade and Migration |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Upgrade Coordinator |
Yes |
Yes |
Yes |
Yes |
Yes |
NSX for vSphere to NSX-T Migration Coordinator |
Yes |
Yes |
Yes |
Yes |
Yes |
NSX Manager to Policy Promotion |
Yes |
Yes |
Yes |
Yes |
Yes |
Included Product Entitlement |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
Aria Operations for Logs for NSX (SaaS) |
No2 |
No2 |
No2 |
No2 |
No2 |
Aria Operations for Logs for NSX (on-premises) |
No2 |
No2 |
No2 |
No2 |
No2 |
Aria Operations for Networks Advanced |
No |
No |
No |
No |
No |
Aria Operations for Networks Enterprise |
No |
No |
No |
No |
No |
Aria Operations for Networks Universal |
No |
No |
No |
No |
No |
HCX Advanced |
No |
No |
No |
No |
No |
HCX Enterprise |
No |
No |
No |
No |
No |
HCX+ |
No |
No |
No |
No |
No |
Workspace One Access |
Yes |
Yes |
Yes |
Yes |
Yes |
NSX Advanced Load Balancer Enterprise |
No |
No |
No |
No |
No |
NSX+ Advanced Load Balancer Cloud Services |
No |
One (1) Service Unit per 250 NSX CPU Cores |
One (1) Service Unit per 250 NSX CPU Cores |
No |
No |
NSX+ Intelligence |
No |
No |
No |
No |
No |
NSX+ Network Detection and Response (NDR) |
No |
No |
No |
No |
No |
NSX Intelligence |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
VM-to-VM Traffic Flow Analysis |
No |
No |
No |
No |
No |
Firewall Visibility |
No |
No |
No |
No |
No |
Automated Security Policy |
No |
No |
No |
No |
No |
Rule and Group Recommendation Analytics |
No |
No |
No |
No |
No |
Network Traffic Analytics |
No |
No |
No |
No |
No |
NSX+ Intelligence |
NSX+ Standard |
NSX+ Advanced |
NSX+ Enterprise |
NSX+ Distributed Firewall |
NSX+ Distributed Firewall with Threat Prevention |
---|---|---|---|---|---|
VM-to-VM Traffic Flow Analysis |
No |
No |
No |
No |
No |
Firewall Visibility |
No |
No |
No |
No |
No |
Automated Security Policy |
No |
No |
No |
No |
No |
Rule and Group Recommendation Analytics |
No |
No |
No |
No |
No |
Footnotes
Please refer to the VMware Product Interoperability Matrices for specific versions supported with VMware NSX.
VMware NSX+ provides a Aria Operations for Logs plugin for optimized use of NSX+ with Aria Operations for Logs.
Please refer to the NSX partner website for specific versions.
VMware Workspace ONE Access - A license to use VMware NSX includes an entitlement to use the VMware Workspace ONE Access feature, but only for the following functionalities:
Directory integration functionality of VMware Workspace ONE Access to authenticate users in a user directory such as Microsoft Active Directory or LDAP.
Conditional access policy.
Single-sign-on integration functionality with third party Identity providers to allow third party identity providers’ users to single-sign-on into NSX.
Two-factor authentication solution through integration with third party systems. VMware Verify, VMware’s multi-factor authentication solution, received as part of VMware Workspace ONE Access may not be used as part of NSX.
Single-sign-on functionality to access VMware products that support single-sign-on capabilities.
Integration with automation tools such as VMware Aria Automation, vCloud Director, VMware Integrated OpenStack, Ansible, and Terraform is available for all editions of NSX, however, you must have the appropriate NSX edition for the feature which is automated by these tools. For example automation of load balancing from Terraform or OpenStack requires NSX Advanced, Enterprise Plus, or ROBO.
VMware recommends that NSX+ customers requiring load balancing features use NSX Advanced Load Balancer (Avi). See the table titled "Included Product Entitlement" for details on NSX Advanced Load Balancer entitlements.
Requires VDS 7.0 or higher
Customers who have purchased vSphere Enterprise Plus are also entitled to use the Enhanced Datapath – Standard for DPUs feature. This feature requires the installation of the NSX Manager.