Thursday, 10 September 2026

 

NSX Networking: What's New in VMware Cloud Foundation 9.1 (Part 1)

As VMware Cloud Foundation (VCF) continues to evolve into a fully integrated private cloud platform, networking remains one of the most significant areas of innovation. VCF 9.1 introduces major enhancements to NSX networking, with a strong focus on Virtual Private Clouds (VPCs), Transit Gateways, automation, simplified operations, and expanded multi-tenant capabilities.

In this first part of our VCF 9.1 networking series, we'll explore the key NSX networking innovations that help organizations build more scalable, flexible, and cloud-like networking environments.


Virtual Private Cloud (VPC) Takes Center Stage

Virtual Private Cloud (VPC) networking continues to be the cornerstone of modern networking within VMware Cloud Foundation. VCF 9.1 significantly expands VPC capabilities, making it easier for administrators and tenants to deploy, manage, and consume networking services while maintaining isolation and operational simplicity.

The enhancements introduced in this release focus on:

  • Improved VPC management experience
  • Enhanced connectivity options
  • Expanded networking services
  • Greater automation support
  • Simplified integration with existing data center networks

These updates bring the VCF networking experience closer to the public cloud operational model while maintaining the flexibility and control of private infrastructure.


AVI Load Balancer Integration for VPCs

One of the headline features in VCF 9.1 is the introduction of AVI Load Balancer integration with VPCs and Transit Gateways using Distributed VLAN Connections.

This enhancement enables organizations to deploy enterprise-grade load balancing services directly within VPC environments while maintaining the distributed networking architecture introduced in recent NSX releases.

Key benefits include:

  • Seamless integration with NSX VPC networking
  • Support for distributed Transit Gateway architectures
  • Simplified deployment of application delivery services
  • Improved scalability and operational consistency

This integration ensures that application workloads can leverage advanced load balancing services without requiring complex networking configurations.


Distributed VLAN Connectivity for Supervisor and VCF Automation

VCF 9.1 introduces an important enhancement for Kubernetes and infrastructure automation environments through the integration of the Virtual Network Appliance (VNA).

By introducing the VNA, VMware delivers the necessary networking services to support Distributed Transit Gateways within Supervisor environments. This allows VCF Automation deployments to connect directly to existing data center VLANs using simple VLAN-based connectivity.

Benefits include:

  • Reduced networking complexity
  • Faster onboarding of automation environments
  • Simplified connectivity requirements
  • Easier integration with existing network infrastructure

This feature significantly lowers the barrier to deploying cloud automation services in enterprise environments.


Enhanced NSX User Experience for VPC and IPAM

As VPC adoption grows, VMware has invested heavily in improving the NSX management experience.

Extended VPC Management Views

Administrators can now access dedicated views for specific VPC features, including:

  • Subnets
  • NAT services
  • Connectivity configurations
  • VPC-level resource management

This provides a more intuitive operational experience and makes troubleshooting easier.

Improved IP Address Management (IPAM)

VCF 9.1 delivers a complete IP allocation and management workflow, enabling:

  • Simplified IP provisioning
  • Faster address assignment
  • Direct integration with networking services
  • Easy allocation of External IPs
  • Streamlined NAT configuration

Networking Interface Reorganization

The NSX UI has also been reorganized to clearly distinguish between:

VPC Networking Components

  • Transit Gateways
  • VPC Services
  • Connectivity Policies

Traditional Segment Networking Components

  • Tier-1 Gateways
  • Segments
  • Legacy network constructs

The result is a cleaner and more logical navigation experience.


Extended VPC Management Directly from vCenter

VCF 9.1 continues the trend of surfacing NSX networking functionality directly within vCenter.

Administrators can now perform many VPC-related networking tasks without switching management interfaces.

New capabilities include:

  • Full Transit Gateway visibility and configuration
  • VPC subnet extension to VLAN networks
  • End-to-end IPAM visibility
  • Direct IP allocation workflows
  • Enhanced topology visualization
  • Traceflow support for VPC-based virtual machines
  • DHCP Server management
  • DHCP Relay configuration

This integrated experience helps reduce context switching and simplifies day-to-day operations.


Terraform Support Expands Further

Infrastructure as Code continues to be a critical requirement for modern private cloud deployments.

With VCF 9.1, the Terraform Provider has been expanded to support newly introduced VPC and Transit Gateway capabilities.

New automation coverage includes:

Transit Gateway Enhancements

  • Multiple Transit Gateways
  • Advanced connectivity configurations
  • Enhanced routing constructs

VPC Features

  • Improved IPAM support
  • VLAN Extension capabilities
  • Advanced VPC networking services

These additions make it easier for platform teams to standardize infrastructure deployments using automation pipelines.


Load Balancer Services Powered by Virtual Network Appliance

VCF 9.1 introduces VPC Load Balancer services running on the newly introduced Virtual Network Appliance (VNA).

The VNA hosts Layer 4 (L4) load balancing services and provides:

  • Service isolation
  • Improved scalability
  • Flexible deployment options
  • Distributed VPC support

By separating networking services from traditional centralized architectures, VMware is creating a more cloud-like networking experience that scales alongside workloads.


IPSec VPN Support for VPCs

Secure connectivity is another major area of improvement in VCF 9.1.

Organizations can now deploy IPSec VPN services for VPCs using centralized Transit Gateway connectivity.

Supported VPN modes include:

Policy-Based VPN

Ideal for simple site-to-site connectivity requirements.

Route-Based VPN

Supports static route configurations and provides greater flexibility in network design.

Benefits include:

  • Secure encrypted communication
  • Hybrid cloud connectivity
  • Branch office integration
  • Third-party network interoperability

1:N SNAT for Distributed Transit Gateways

VCF 9.1 introduces support for 1:N Source Network Address Translation (SNAT) within distributed Transit Gateway deployments.

This allows multiple internal workloads to share a single external IP address using Port Address Translation (PAT).

Advantages include:

  • Conservation of public IP addresses
  • Simplified outbound connectivity
  • Reduced operational overhead
  • Better public network resource utilization

This capability is particularly valuable for large-scale cloud-native environments.


Introducing the Virtual Network Appliance (VNA)

The Virtual Network Appliance is one of the most important architectural additions in VCF 9.1.

The VNA serves as a dedicated platform for hosting network services within distributed VPC environments.

The appliance provides:

  • Flexible service deployment
  • Scalable networking architecture
  • Support for advanced network services
  • Foundation for future service expansion

Several new networking capabilities in VCF 9.1 rely on this new architecture, making it a strategic component moving forward.


VLAN Extensions for VPC Subnets

A common challenge when adopting VPC networking is integrating existing virtual machine workloads.

VCF 9.1 addresses this with VLAN Extension for VPC Subnets.

This capability allows:

  • Existing VLAN-connected workloads to join VPC networks
  • Gradual migration strategies
  • Simplified workload onboarding
  • Distributed VLAN extensions through the fabric

Organizations can modernize networking without requiring disruptive infrastructure redesigns.


Advanced Connectivity for Centralized Transit Gateways

Transit Gateways receive several powerful enhancements in VCF 9.1.

Multiple External Connections

Transit Gateways can now support multiple gateway external connections, improving resiliency and design flexibility.

Multiple Transit Gateways Per Project

Projects can deploy more than one Transit Gateway, enabling segmentation and workload separation.

Independent High Availability Models

Each Transit Gateway can be configured with:

  • Independent HA modes
  • Custom edge node placements
  • Flexible deployment topologies

Proxy ARP Support

Proxy ARP can now be enabled on Tier-0 Gateways serving Transit Gateways and VPC subnets.

These enhancements deliver greater flexibility for complex enterprise networking environments.


Multiple Distributed Transit Gateways Per Project

VCF 9.1 also introduces support for multiple Distributed Transit Gateways within a single project.

This allows organizations to:

  • Separate application domains
  • Isolate departments or business units
  • Improve network segmentation
  • Scale networking independently

The result is a more flexible multi-tenant networking architecture.


Distributed EVPN-VXLAN Connectivity

One of the most technically significant additions is Distributed EVPN-VXLAN support.

This architecture enables direct integration between NSX workloads and modern EVPN-VXLAN network fabrics using:

  • BGP EVPN
  • VXLAN
  • Distributed forwarding

Unlike traditional centralized approaches, traffic forwarding occurs closer to workloads, improving performance and scalability.

The VCF Route Controller provides BGP EVPN control-plane connectivity by peering directly with fabric Border Gateway devices.

Benefits include:

  • Improved scale
  • Higher performance
  • Reduced traffic tromboning
  • Better alignment between physical and virtual networks

Enhanced Multi-Tenant Networking

VCF Automation Networking 9.1 delivers several new self-service capabilities for tenants, including:

  • Distributed VLAN connectivity
  • Multiple Transit Gateways
  • Multiple external connections
  • Self-service NAT
  • Self-service VPN
  • Network grouping
  • Gateway Firewall services
  • Distributed Firewall services (with vDefend Firewall licensing)
  • Shared subnet creation across namespaces

These enhancements significantly improve tenant autonomy while maintaining centralized governance.


Native Infoblox Integration

Enterprise IP management is further enhanced through native Infoblox integration.

VCF Networking IPAM can now:

  • Discover Infoblox Network Views
  • Discover DNS Views
  • Discover Network Containers
  • Create subnets using Infoblox containers
  • Synchronize VM IP and FQDN information

Administrators can also configure mappings between:

  • NSX External IP Blocks
  • Infoblox Network Containers

This creates a unified IP addressing workflow across networking and automation platforms.


VPC Span Control

VCF 9.1 introduces the ability to define the span of a VPC directly from either NSX or vCenter.

Administrators can choose whether VPCs:

  • Remain local to specific clusters
  • Span all vCenter instances within a networking domain

This flexibility allows infrastructure teams to align networking boundaries with operational or compliance requirements.


New VPC Connectivity Policies

Managing communication between large numbers of VPCs can quickly become complex.

VCF 9.1 addresses this through Connectivity Policies.

Connectivity Policies allow administrators to define communication behavior between VPCs connected to the same Transit Gateway.

Supported models include:

Community VPCs

Groups of VPCs that need to communicate with each other, such as connected application tiers.

Isolated VPCs

Workloads that require strong separation, such as DMZ environments.

Promiscuous VPCs

Shared services environments that must communicate with all connected VPCs.

These policy-driven models simplify network design and improve operational consistency.


Final Thoughts

VCF 9.1 represents one of the most significant networking releases for VMware Cloud Foundation in recent memory. The continued evolution of VPC networking, the introduction of the Virtual Network Appliance, enhanced Transit Gateway capabilities, EVPN-VXLAN integration, native Infoblox support, and expanded automation capabilities all point toward VMware's vision of delivering a true cloud operating model for the private data center.

For administrators, architects, and platform engineers, these enhancements provide greater scalability, simplified operations, and increased flexibility while preserving the enterprise-grade security and control that organizations expect from VMware Cloud Foundation.

Stay tuned for Part 2, where we'll explore additional NSX Networking innovations in VCF 9.1 and examine how they further enhance security, operations, and cloud consumption experiences.