Edge Configuration in vCenter
This section describes the procedures for configuring NSX Edge Clusters and Nodes using the vSphere Client.
NSX Edge Nodes provide the centralized network services required for Centralized Transit Gateway (CTGW) designs within the VPC architecture.
Edge Cluster / Edge Nodes
Configuration
Deep Dive: Blogs & Video Demonstrations
- Video Walkthrough: Watch the step-by-step CTGW + Edge + T0 deployment on YouTube.
- Technical Blog: Read the detailed architectural breakdown on the VMware Cloud Foundation Blog.
-
-
Node Form Factor:
Select the appliance size (vCPU / Memory) of the Edge Nodes.
This determines the scale and performance limits for the logical routers (Tier-0, CTGW, and VPC) hosted on the node.
More information on VMware NSX Configmax. -
Auto generate passwords and manage them via SDDC Manager
Enabling this option automates password generation and allows SDDC Manager to handle credential lifecycle management.
-
-
Step3. Configure Edge Nodes Placement and Networking

-
vSphere Cluster / Resource Pool / Host Group Affinity / Data Store:
Defines the physical placement of the Edge Node VM.
You can optionally specify Resource Pools and Host Group Affinity to control where the VM resides within the cluster. -
Management Network Settings (IP Address Type / IP Assignment / Port Group)
Configures the IP assignment and Port Group for the Edge Node management interface. -
Uplinks (Edge Node Uplink Mapping / TEP VLAN)
Defines vNIC connectivity and Overlay TEP configuration.
Note: To share the same VLAN for both ESX TEPs and Edge Node TEPs, you must enable "Use the host overlay network configuration from the selected vSphere Cluster."In case "Use the host overlay network configuration from the selected vSphere Cluster" is greyed out
If this option is greyed out, follow these steps:
1. Go to NSX Manager.
2. Navigate to System > Fabric > Host > Clusters.
3. Activate NSX on DVPGs.

Security Consideration: Microsegmentation / DFW
Enabling "NSX on DVPG" activates the Distributed Firewall (DFW) for all VMs connected to VDS Port Groups. Critical: Ensure no "Deny All" rules are active in your DFW policy before enabling this, as it may immediately block traffic to existing workloads on those Port Groups.
-
VLAN MTU Check
(Optional) Validates the MTU settings on the selected VLAN to ensure overlay traffic is not fragmented.
-
Repeat these steps for the remaining Edge Nodes (2+ nodes recommended).




