vSphere Supervisor Networking with NSX and AVI – Part 1 – Architecture and Topologies

  • A single load balancing platform to manage all K8S L4 and L7 ingress VIPs
  • Benefit from advanced load balancing and security features like WAF and GSLB
  • Rich analytics and enhanced visibility to the application traffic
  • Tight integration with NSX for security automation
  • NSX version 4.1.1 or later
  • AVI version 22.1.4 or later

4 thoughts on “vSphere Supervisor Networking with NSX and AVI – Part 1 – Architecture and Topologies

  1. Hello,

    Thank you very much for this series of articles.

    Could you please clarify the following statement from the “Considerations for Supervisor Networking with NSX and AVI” section:
    “If the T0 gateway (Provider) is provisioned as stateful A/A, then a dedicated edge cluster needs to be available to host the T1 gateways created by NCP.”

    From the articles, I can see that the “T0 gateway (Provider)” is provisioned as stateful A/A, and you keep both T0s and T1s on the same Edge cluster.

    So, is this statement still relevant? Maybe I misunderstood or missed something…

    And one more question: if we are going to have a dedicated vSphere namespace with a dedicated T0 per tenant, would you recommend deploying the T0s in A/A mode or A/S mode, considering that the maximum expected throughput is less than 1 Gbps?

    Thank you in advance.

    1. Hi Serhii

      Regarding the first question, T0 gateway can be deployed either in stateless A/A or stateful A/A (beginning NSX 4.0.1 version). If the T0 gateway is in stateless A/A mode, having a dedicated edge cluster for the T1 gateways is optional. However if the T0 deployment mode is stateful A/A, we require a dedicated edge cluster for T1 gateways. This is because the T1 gateways provisioned by the supervisor are in A/S mode which cannot be co-located on the edge cluster used by a stateful A/A T0 gateway. This T1s can only be placed on a separate A/S edge cluster, upstreamed to the T0 gateway.

      For the second question, it’s recommended to have T0s in A/A mode for this use case, as the workflow only provisions stateful services on the T1 gateway. So i dont see a real benefit of having an A/S T0 gateway, except if you plan to put Gateway firewall or other stateful services on it.

      Thanks

  2. Hi HariKrishnan,

    Thank you very much for the prompt reply.

    Do you know if Broadcom is planning to release a tool for migrating to “Supervisor Networking with NSX and Avi Load Balancer” from Supervisors that were initially deployed with “Supervisor Networking with NSX”?

    Thank you in advance.

Leave a Reply to Serhii KompanetsCancel reply