VCF Extension Network Insight: Introduction

Version: 2026.1.1.0

What it is

VCF Extension Network Insight is a complete microsegmentation solution for VMware NSX. It has two parts that work as one product: a browser tool, VCF Extension Network Insight GUI, that builds the NSX Distributed Firewall (DFW) policy for an application, and a VMware Aria Operations Management Pack that then monitors that policy and tells who each rule affects.

The GUI reads the tags set on the machines in vCenter and the real traffic seen in Aria Operations for Networks, and turns them into NSX groups, services, policies and ALLOW rules. It always shows a plan before it writes anything, and it never creates blocking rules. The Management Pack watches the result in Aria Operations: it attributes every dropped and observed connection to the rule that produced it, so it can be seen when it is safe to move from observing to enforcing.

How does it work?

  1. Tagging: each machine in vCenter is tagged with its application and its tier.
  2. Discovery: the GUI reads the machines, tags and addresses from vCenter, and the real flows between them from Aria Operations for Networks.
  3. Planning: it proposes the NSX groups, services and ALLOW rules for the application, and shows them as a plan before writing.
  4. Apply: after the plan is reviewed, the policy, groups and rules are written to NSX, plus three catch-all rules that allow and log whatever the detailed rules did not match.
  5. Monitoring: the Management Pack reads the DFW logs through Aria Operations for Logs and attributes every dropped and observed connection to the rule that produced it.
  6. Readiness: while the catch-all counters keep rising there is still traffic no rule describes; when they stop, the application is ready to switch to blocking.

Benefits

  • One workflow from tagging to enforcement: build the policy and watch it from the same solution.
  • Based on real traffic, not guesswork: rules come from observed flows, and the GUI answers who a rule blocks from the logs, not from configuration.
  • Safe by design: it only ever creates ALLOW rules and always shows a plan first, so nothing is blocked by surprise.
  • Centralized visibility in Aria Operations: DFW rules, policies and applications monitored through a single adapter instance, with alerts on newly blocked traffic.
  • Clear readiness signal: the catch-all counters show, per application, when it is safe to move from observing to enforcing.