<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="30765" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/vmware-nsxicm4" lastchanged="2026-03-19T09:08:28+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>VMware NSX: Install, Configure, Manage [V4.0]</title><productcode>NSXICM4</productcode><vendorcode>VM</vendorcode><vendorname>VMware</vendorname><fullproductcode>VM-NSXICM4</fullproductcode><version>4.0</version><objective>&lt;p&gt;By the end of the course, you should be able to meet the following objectives:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the architecture and main components of NSX&lt;/li&gt;&lt;li&gt;Explain the features and benefits of NSX&lt;/li&gt;&lt;li&gt;Deploy the NSX Management cluster and VMware NSX&amp;reg; Edge&amp;trade; nodes&lt;/li&gt;&lt;li&gt;Prepare VMware ESXi&amp;trade; hosts to participate in NSX networking&lt;/li&gt;&lt;li&gt;Create and configure segments for layer 2 forwarding&lt;/li&gt;&lt;li&gt;Create and configure Tier-0 and Tier-1 gateways for logical routing&lt;/li&gt;&lt;li&gt;Use distributed and gateway firewall policies to filter east-west and north-south traffic in NSX&lt;/li&gt;&lt;li&gt;Configure Advanced Threat Prevention features&lt;/li&gt;&lt;li&gt;Configure network services on NSX Edge nodes&lt;/li&gt;&lt;li&gt;Use VMware Identity Manager&amp;trade; and LDAP to manage users and access&lt;/li&gt;&lt;li&gt;Explain the use cases, importance, and architecture of Federation&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;ul&gt;
&lt;li&gt;Good understanding of TCP/IP services and protocols&lt;/li&gt;&lt;li&gt;Knowledge and working experience of computer networking, including switching and routing technologies (L2 through L3) and L2 through L7 firewall&lt;/li&gt;&lt;li&gt;Knowledge and working experience with VMware vSphere&amp;reg; environments&lt;/li&gt;&lt;li&gt;Knowledge and working experience with Kubernetes or VMware vSphere&amp;reg; with VMware Tanzu&amp;reg; environments&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;Experienced security administrators or network administrators&lt;/p&gt;</audience><outline>&lt;h5&gt;Course Introduction&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Introductions and course logistics&lt;/li&gt;&lt;li&gt;Course objectives&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;VMware Virtual Cloud Network and VMware NSX&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Introduce the VMware Virtual Cloud Network vision&lt;/li&gt;&lt;li&gt;Describe the NSX product portfolio&lt;/li&gt;&lt;li&gt;Discuss NSX features, use cases, and benefits&lt;/li&gt;&lt;li&gt;Explain NSX architecture and components&lt;/li&gt;&lt;li&gt;Explain the management, control, data, and consumption planes and their functions.&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Preparing the NSX Infrastructure&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Deploy VMware NSX&amp;reg; ManagerTM nodes on ESXi hypervisors&lt;/li&gt;&lt;li&gt;Navigate through the NSX UI&lt;/li&gt;&lt;li&gt;Explain data plane components such as N-VDS/VDS, transport nodes, transport zones, profiles, and more&lt;/li&gt;&lt;li&gt;Perform transport node preparation and configure the data plane infrastructure&lt;/li&gt;&lt;li&gt;Verify transport node status and connectivity&lt;/li&gt;&lt;li&gt;Explain DPU-based acceleration in NSX&lt;/li&gt;&lt;li&gt;Install NSX using DPUs&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Logical Switching&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Introduce key components and terminology in logical switching&lt;/li&gt;&lt;li&gt;Describe the function and types of L2 segments&lt;/li&gt;&lt;li&gt;Explain tunneling and the Geneve encapsulation&lt;/li&gt;&lt;li&gt;Configure logical segments and attach hosts using NSX UI&lt;/li&gt;&lt;li&gt;Describe the function and types of segment profiles&lt;/li&gt;&lt;li&gt;Create segment profiles and apply them to segments and ports&lt;/li&gt;&lt;li&gt;Explain the function of MAC, ARP, and TEP tables used in packet forwarding&lt;/li&gt;&lt;li&gt;Demonstrate L2 unicast packet flow&lt;/li&gt;&lt;li&gt;Explain ARP suppression and BUM traffic handling&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Logical Routing&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the logical routing function and use cases&lt;/li&gt;&lt;li&gt;Introduce the two-tier routing architecture, topologies, and components&lt;/li&gt;&lt;li&gt;Explain the Tier-0 and Tier-1 gateway functions&lt;/li&gt;&lt;li&gt;Describe the logical router components: Service Router and Distributed Router&lt;/li&gt;&lt;li&gt;Discuss the architecture and function of NSX Edge nodes&lt;/li&gt;&lt;li&gt;Discuss deployment options of NSX Edge nodes&lt;/li&gt;&lt;li&gt;Configure NSX Edge nodes and create NSX Edge clusters&lt;/li&gt;&lt;li&gt;Configure Tier-0 and Tier-1 gateways&lt;/li&gt;&lt;li&gt;Examine single-tier and multitier packet flows&lt;/li&gt;&lt;li&gt;Configure static routing and dynamic routing, including BGP and OSPF&lt;/li&gt;&lt;li&gt;Enable ECMP on a Tier-0 gateway&lt;/li&gt;&lt;li&gt;Describe NSX Edge HA, failure detection, and failback modes&lt;/li&gt;&lt;li&gt;Configure VRF Lite&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Bridging&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the function of logical bridging&lt;/li&gt;&lt;li&gt;Discuss the logical bridging use cases&lt;/li&gt;&lt;li&gt;Compare routing and bridging solutions&lt;/li&gt;&lt;li&gt;Explain the components of logical bridging&lt;/li&gt;&lt;li&gt;Create bridge clusters and bridge profiles&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Firewalls&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe NSX segmentation&lt;/li&gt;&lt;li&gt;Identify the steps to enforce Zero-Trust with NSX segmentation&lt;/li&gt;&lt;li&gt;Describe the Distributed Firewall architecture, components, and function&lt;/li&gt;&lt;li&gt;Configure Distributed Firewall sections and rules&lt;/li&gt;&lt;li&gt;Configure the Distributed Firewall on VDS&lt;/li&gt;&lt;li&gt;Describe the Gateway Firewall architecture, components, and function&lt;/li&gt;&lt;li&gt;Configure Gateway Firewall sections and rules&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Advanced Threat Prevention&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain NSX IDS/IPS and its use cases&lt;/li&gt;&lt;li&gt;Configure NSX IDS/IPS&lt;/li&gt;&lt;li&gt;Deploy NSX Application Platform&lt;/li&gt;&lt;li&gt;Identify the components and architecture of NSX Malware Prevention&lt;/li&gt;&lt;li&gt;Configure NSX Malware Prevention for east-west and north-south traffic&lt;/li&gt;&lt;li&gt;Describe the use cases and architecture of VMware NSX&amp;reg; Intelligence&amp;trade;&lt;/li&gt;&lt;li&gt;Identify the components and architecture of VMware NSX&amp;reg; Network Detection and Response&amp;trade;&lt;/li&gt;&lt;li&gt;Use NSX Network Detection and Response to analyze network traffic events.&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Services&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Explain and configure Network Address Translation (NAT)&lt;/li&gt;&lt;li&gt;Explain and configure DNS and DHCP services&lt;/li&gt;&lt;li&gt;Describe VMware NSX&amp;reg; Advanced Load Balancer&amp;trade; architecture, components, topologies, and use cases.&lt;/li&gt;&lt;li&gt;Configure NSX Advanced Load Balancer&lt;/li&gt;&lt;li&gt;Discuss the IPSec VPN and L2 VPN function and use cases&lt;/li&gt;&lt;li&gt;Configure IPSec VPN and L2 VPN using the NSX UI&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX User and Role Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Describe the function and benefits of VMware Identity Manager&amp;trade; in NSX&lt;/li&gt;&lt;li&gt;Integrate VMware Identity Manager with NSX&lt;/li&gt;&lt;li&gt;Integrate LDAP with NSX&lt;/li&gt;&lt;li&gt;Identify the various types of users, authentication policies, and permissions&lt;/li&gt;&lt;li&gt;Use role-based access control to restrict user access&lt;/li&gt;&lt;li&gt;Explain object-based access control in NSX&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;NSX Federation&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Introduce the NSX Federation key concepts, terminology, and use cases.&lt;/li&gt;&lt;li&gt;Explain the onboarding process of NSX Federation&lt;/li&gt;&lt;li&gt;Describe the NSX Federation switching and routing functions.&lt;/li&gt;&lt;li&gt;Describe the NSX Federation security concepts.&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>By the end of the course, you should be able to meet the following objectives:


- Describe the architecture and main components of NSX
- Explain the features and benefits of NSX
- Deploy the NSX Management cluster and VMware NSX® Edge™ nodes
- Prepare VMware ESXi™ hosts to participate in NSX networking
- Create and configure segments for layer 2 forwarding
- Create and configure Tier-0 and Tier-1 gateways for logical routing
- Use distributed and gateway firewall policies to filter east-west and north-south traffic in NSX
- Configure Advanced Threat Prevention features
- Configure network services on NSX Edge nodes
- Use VMware Identity Manager™ and LDAP to manage users and access
- Explain the use cases, importance, and architecture of Federation</objective_plain><essentials_plain>- Good understanding of TCP/IP services and protocols
- Knowledge and working experience of computer networking, including switching and routing technologies (L2 through L3) and L2 through L7 firewall
- Knowledge and working experience with VMware vSphere® environments
- Knowledge and working experience with Kubernetes or VMware vSphere® with VMware Tanzu® environments</essentials_plain><audience_plain>Experienced security administrators or network administrators</audience_plain><outline_plain>Course Introduction


- Introductions and course logistics
- Course objectives
VMware Virtual Cloud Network and VMware NSX


- Introduce the VMware Virtual Cloud Network vision
- Describe the NSX product portfolio
- Discuss NSX features, use cases, and benefits
- Explain NSX architecture and components
- Explain the management, control, data, and consumption planes and their functions.
Preparing the NSX Infrastructure


- Deploy VMware NSX® ManagerTM nodes on ESXi hypervisors
- Navigate through the NSX UI
- Explain data plane components such as N-VDS/VDS, transport nodes, transport zones, profiles, and more
- Perform transport node preparation and configure the data plane infrastructure
- Verify transport node status and connectivity
- Explain DPU-based acceleration in NSX
- Install NSX using DPUs
NSX Logical Switching


- Introduce key components and terminology in logical switching
- Describe the function and types of L2 segments
- Explain tunneling and the Geneve encapsulation
- Configure logical segments and attach hosts using NSX UI
- Describe the function and types of segment profiles
- Create segment profiles and apply them to segments and ports
- Explain the function of MAC, ARP, and TEP tables used in packet forwarding
- Demonstrate L2 unicast packet flow
- Explain ARP suppression and BUM traffic handling
NSX Logical Routing


- Describe the logical routing function and use cases
- Introduce the two-tier routing architecture, topologies, and components
- Explain the Tier-0 and Tier-1 gateway functions
- Describe the logical router components: Service Router and Distributed Router
- Discuss the architecture and function of NSX Edge nodes
- Discuss deployment options of NSX Edge nodes
- Configure NSX Edge nodes and create NSX Edge clusters
- Configure Tier-0 and Tier-1 gateways
- Examine single-tier and multitier packet flows
- Configure static routing and dynamic routing, including BGP and OSPF
- Enable ECMP on a Tier-0 gateway
- Describe NSX Edge HA, failure detection, and failback modes
- Configure VRF Lite
NSX Bridging


- Describe the function of logical bridging
- Discuss the logical bridging use cases
- Compare routing and bridging solutions
- Explain the components of logical bridging
- Create bridge clusters and bridge profiles
NSX Firewalls


- Describe NSX segmentation
- Identify the steps to enforce Zero-Trust with NSX segmentation
- Describe the Distributed Firewall architecture, components, and function
- Configure Distributed Firewall sections and rules
- Configure the Distributed Firewall on VDS
- Describe the Gateway Firewall architecture, components, and function
- Configure Gateway Firewall sections and rules
NSX Advanced Threat Prevention


- Explain NSX IDS/IPS and its use cases
- Configure NSX IDS/IPS
- Deploy NSX Application Platform
- Identify the components and architecture of NSX Malware Prevention
- Configure NSX Malware Prevention for east-west and north-south traffic
- Describe the use cases and architecture of VMware NSX® Intelligence™
- Identify the components and architecture of VMware NSX® Network Detection and Response™
- Use NSX Network Detection and Response to analyze network traffic events.
NSX Services


- Explain and configure Network Address Translation (NAT)
- Explain and configure DNS and DHCP services
- Describe VMware NSX® Advanced Load Balancer™ architecture, components, topologies, and use cases.
- Configure NSX Advanced Load Balancer
- Discuss the IPSec VPN and L2 VPN function and use cases
- Configure IPSec VPN and L2 VPN using the NSX UI
NSX User and Role Management


- Describe the function and benefits of VMware Identity Manager™ in NSX
- Integrate VMware Identity Manager with NSX
- Integrate LDAP with NSX
- Identify the various types of users, authentication policies, and permissions
- Use role-based access control to restrict user access
- Explain object-based access control in NSX
NSX Federation


- Introduce the NSX Federation key concepts, terminology, and use cases.
- Explain the onboarding process of NSX Federation
- Describe the NSX Federation switching and routing functions.
- Describe the NSX Federation security concepts.</outline_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="DE" currency="EUR">3750.00</price><price country="PL" currency="EUR">1880.00</price><price country="NL" currency="EUR">3750.00</price><price country="BE" currency="EUR">3750.00</price><price country="AE" currency="USD">3350.00</price><price country="AT" currency="EUR">3750.00</price><price country="CH" currency="CHF">4300.00</price><price country="IT" currency="EUR">2950.00</price><price country="GB" currency="GBP">3555.00</price><price country="UA" currency="EUR">3750.00</price><price country="RU" currency="RUB">205300.00</price><price country="SI" currency="EUR">2750.00</price></pricelist><miles><milesvalue country="SI" vendorcurrency="PSO" vendorcurrencyname="VMware PSO Credits">23.00</milesvalue><milesvalue country="PL" vendorcurrency="PSO" vendorcurrencyname="VMware PSO Credits">23.00</milesvalue><milesvalue country="DE" vendorcurrency="PSO" vendorcurrencyname="VMware PSO Credits">43.00</milesvalue><milesvalue country="AT" vendorcurrency="PSO" vendorcurrencyname="VMware PSO Credits">45.00</milesvalue></miles></course>