Contents
Key takeawaysHow NSX is packagedWhat NSX costs per coreWhich hosts Broadcom countsRightsizing by clusterWhat we have seenNegotiating with VCFRenewal timelineWhat to do nextFAQNSX networking comes with VCF, while advanced security is a vDefend attach priced per host core, whatever the firewall policy. Licensing it only on clusters with a real security requirement lowers the bill more than any rate you can negotiate.
- Networking is included with VCF. Switching, routing, the manager plane and a load balancer limited on VCF 9.0 to infrastructure use come with the platform, while distributed firewall, gateway firewall and threat prevention are sold as vDefend per core.
- Cores set the price. A 64 core host pays the full attach even where its firewall policy is trivial, and every CPU below 16 cores is billed up to that minimum.
- Broadcom counts by cluster. Once policy beyond the default is realized on a cluster, all of its cores count, so broad Applied To fields and leftover IDS/IPS inflate the bill.
- Half were over scoped. In roughly half the files we reviewed, advanced security was licensed on clusters running only switching and routing, and scoping it back removed cost without removing a needed control.
- Evidence changes the quote. Flow level usage data from the NSX manager shifted Broadcom's position in 7 of 10 renewals where customers presented it.
- Negotiate inside VCF. Put the vDefend scope into the VCF renewal at quarter end, with the covered clusters named in the order form.
How is VMware NSX licensed under Broadcom in 2026?
NSX is now the networking layer of VMware Cloud Foundation (VCF), and advanced security is sold separately as vDefend attach SKUs priced per core. The freestanding NSX product line that existed before the acquisition has largely folded into the platform Broadcom describes on the Cloud Foundation page.
If you run VCF, you already own core NSX networking, and the open question is the security attach. If you run vSphere Foundation, NSX is an upgrade conversation, because vSphere Foundation does not include NSX networking and Broadcom sells vDefend only as an add on to a VCF purchase.
Which NSX capabilities sit in which package?
- Included with VCF. Virtual switching, routing, basic load balancing and the NSX manager plane. From VCF 9.0 the built in NSX load balancer is limited to VCF infrastructure components and Layer 4 balancing for vSphere Supervisor.
- vDefend attach. Distributed firewall, gateway firewall and advanced threat prevention (IDS/IPS, network sandboxing and network traffic analysis), priced per core.
- Avi Load Balancer. Advanced application delivery, and on VCF 9.0 or later any general purpose load balancing for your own applications, licensed separately from both.
The wider bundle rules are set out in our VCF licensing guide and in how core licensing works. If you are still weighing the two platform tiers, the VCF and vSphere Foundation comparison shows what each includes.
What happened to the separate vDefend Firewall and ATP SKUs?
Broadcom has consolidated them. Its current vDefend edition guide lists a single VMware vDefend add on that combines the stateful firewall with threat prevention, plus an Advanced Threat Prevention add on that upgrades existing vDefend Firewall entitlements. The older vDefend Firewall and vDefend Firewall with Advanced Threat Prevention editions are no longer sold.
Contracts signed before the change carry the older edition names, so check which ones sit on your renewal quote. The consolidation does not change the unit. Every version is counted in cores, which is why the rest of this guide is about which cores get counted.
What does NSX cost per core?
You pay VCF per core for the platform, then per core again for each vDefend attach on the clusters it covers, with a 16 core minimum per CPU. Broadcom publishes the product structure on its software portfolio pages, but street pricing is set deal by deal.
The compounding is what surprises buyers. A dense 64 core host pays the attach on all 64 cores even if the firewall policy on it is trivial. Firewall rule volume, traffic and the number of protected VMs do not enter the price.
| Cost driver | Effect on the bill | Your response |
|---|---|---|
| Host core density | Attach cost scales with cores, not usage | Scope attaches to security relevant clusters |
| 16 core minimum per CPU | Small hosts pay phantom cores | Consolidate hosts before renewal |
| Attach scope across every cluster | Pays for features most clusters never run | License by cluster and prove usage |
| Threat prevention tier | Highest rate in the attach family | Reserve for regulated or exposed segments |
| Renewal uplift | Compounds the whole stack every year | Cap increases in the order form |
Current platform pricing sits in our VCF pricing analysis for 2026.
How does vDefend count cores on hosts, edges and other deployments?
Each deployment type has its own ratio in Broadcom's program documentation, and each deployment on a shared host needs its own licenses.
- Distributed firewall on ESXi hosts. One vDefend core per physical host core, with the 16 core minimum per CPU.
- Gateway firewall on NSX Edge nodes. Each edge vCPU counts as one core, and the license terms require 3 vDefend cores per edge core. Broadcom's own counting script still calculates 4, and its core counting article says that will be corrected.
- Bare metal servers. One vDefend core for every 4 physical cores protected.
- DPU offload. 4 additional cores for each DPU.
- Virtual desktops. 2.5 concurrent users for each vDefend core.
Broadcom VMware Negotiation Guide
VCF bundle pricing benchmarks and renewal tactics, including how to handle the vDefend attach.
Get the white paper →Which hosts does Broadcom count for vDefend?
Broadcom counts every core in a cluster once a firewall policy beyond the default is realized on hosts in that cluster. Its core counting article (Broadcom KB 395111) applies the rule cluster by cluster, which is what makes cluster scoping possible in the first place.
Several configuration details can pull far more cores into the count than you intended. Each is easy to miss in a large policy set.
Which settings pull every host into the count?
- Rules applied to the whole distributed firewall. A rule with its Applied To field left at the default is pushed to every NSX prepared host, so under the cluster rule every cluster counts. Scope rules to security groups inside the clusters you license.
- IPFIX profiles with a broad Applied To. When the distributed firewall is on and an IPFIX profile has a non empty Applied To, the article counts the cores of all NSX prepared hosts.
- Malicious IP rules. With the distributed firewall on, enabling the Malicious IP feature with any of its rules active also counts the cores of all NSX prepared hosts.
- Leftover threat prevention. Activating distributed IDS/IPS or malware detection on a cluster counts all of that cluster's cores, so a finished pilot that was never switched off keeps billing.
For gateway firewall, edge cores count when stateful policies beyond the default exist or TLS inspection is enabled on a Tier 0 or Tier 1 gateway. The standby edge counts as well as the active one. An edge running routing alone does not add to the count.
How do you rightsize NSX licensing by cluster?
License the security attach only where the security requirement is real. Map which clusters carry regulated workloads, exposed services or real microsegmentation policy, and put vDefend on those clusters alone.
Treat the other clusters as candidates for native vSphere controls or third party tooling. The aim is to keep NSX and stop paying advanced security rates on clusters running basic switching.
A worked example with six clusters
Say a company runs six VCF clusters with 38 hosts and 1,984 billed cores, and the first vDefend quote covers all of them. The security review finds real policy on three.
| Cluster | Hosts and cores | Billed cores | Security requirement | vDefend after scoping |
|---|---|---|---|---|
| Payments | 6 hosts, 2 x 32 cores | 384 | Regulated, segmentation required | Yes, 384 |
| Internet facing | 4 hosts, 2 x 32 cores | 256 | Exposed services | Yes, 256 |
| Core business apps | 10 hosts, 2 x 32 cores | 640 | Application segmentation | Yes, 640 |
| Dev and test | 8 hosts, 2 x 24 cores | 384 | Default policy only | No |
| Management | 4 hosts, 2 x 16 cores | 128 | Default policy only | No |
| Remote sites | 6 hosts, 2 x 12 cores | 192 (144 physical) | Default policy only | No |
| Total | 38 hosts | 1,984 | 1,280 |
Removing the attach from three clusters takes 704 cores off the vDefend line, about 35 percent, and no control comes off a cluster that needed one. Whatever per core rate Broadcom quotes, the attach cost falls in the same proportion.
The remote sites also show the core minimum at work. Six hosts with two 12 core CPUs have 144 physical cores but are billed for 192, so 48 cores exist only on paper in both the VCF and any vDefend count.
How to verify what actually runs
Pull distributed firewall rule counts, flow statistics and feature flags from the NSX manager before any commercial conversation. The technical documentation describes the operational reporting available, and that output is your negotiation evidence.
The most useful single output is the Security Usage Report. NSX generates it weekly, and an Enterprise Admin or Auditor can export it through the GET /api/v1/licenses/security-usage?format=csv API call. It lists licensed cores per feature across hosts, edges and DPUs, with rule and group counts beside them.
Three steps, in the order they work
- Scope reduction. Present the cluster map and remove the attach from clusters without security policy.
- Core consolidation. Retire or merge low density hosts so the 16 core minimum stops manufacturing phantom cores.
- Alternative pressure. Price third party firewalls or native controls for the clusters Broadcom wants to defend.
Hold support commitments to written terms, whatever assurances come with the quote. The support portal is where Broadcom publishes those terms.
What have we seen in recent NSX renewals?
NSX was consistently over scoped. We reviewed roughly 20 to 30 Broadcom VMware files with material NSX usage between 2024 and 2025, and three patterns came up again and again.
- Security licensed where none ran. Roughly half the customers licensed advanced NSX security features on clusters where only basic switching and routing ran.
- Scoping paid. Scoping vDefend attach SKUs to security relevant clusters cut the attach bill 25 to 45 percent.
- Evidence changed the quote. Customers who produced flow level usage evidence at renewal moved Broadcom's NSX position in 7 of 10 files.
None of the three required a change to how the environment runs. All three relied on evidence the NSX manager was already producing, and most customers never pulled it before the commercial conversation started.
Why we advise against licensing vDefend on every cluster
The standard partner guidance is to license vDefend everywhere for consistency, on the theory that uniform coverage simplifies operations and audits. We disagree. In roughly 12 of the files we reviewed in 2024 to 2025, uniform coverage meant paying advanced security rates on a majority of cores that ran nothing beyond default policy.
Uniform coverage did not make those audits easier either. Cluster scoped licensing with documented flow evidence passed every true up we defended. Segment your clusters by security requirement, license the attach where the requirement is real, and let the usage evidence carry the audit conversation.
vDefend pricing follows host cores, not firewall policy, so the cluster list you license matters more than the rate you negotiate.
Common mistakes that inflate the vDefend count
- Cleaning up after the snapshot. Narrowing Applied To fields a week after Broadcom has pulled the usage report leaves the old count in the quote you are asked to sign.
- Accepting the script ratio for edges. Paying 4 cores per edge vCPU when your terms say 3 overstates gateway firewall by a third.
- Consolidating after signature. Retiring small hosts once the order is signed saves nothing until the next renewal.
- Sizing edges without the standby. Gateway firewall policy counts the standby edge too, so an active and standby pair of large edges doubles the edge line you expected.
Should NSX ride the VCF renewal or be negotiated on its own?
Ride the VCF renewal. Bundling the attach decision into the platform negotiation gives you a bigger number to trade against, and Broadcom's quarter end dynamics apply to the combined deal. A standalone attach conversation gives that advantage up entirely.
Our notes on Broadcom quarter end timing cover when that pressure peaks.
What the account team will say, and what to say back
| What you hear | What to say back |
|---|---|
| vDefend has to cover every core in your VCF deployment. | Show us the clause. Your own core counting article counts clusters where firewall policy is realized, and our Applied To scopes keep it to three clusters. |
| Threat prevention is bundled now, so there is nothing to scope. | The combined SKU is still priced per core. We are scoping cores. |
| Your usage report shows the firewall active on every host. | That report predates our rule cleanup. Here is this week's Security Usage Report with the corrected scope. |
| This per core rate only applies to full coverage. | Quote the same rate on the scoped count, and hold it for any cores we add during the term. |
Contract wording to ask for
- Named cluster scope. List the covered clusters in the order form, so a later usage report cannot widen the count by default.
- Price hold for additions. Additional vDefend cores during the term at the same per core rate.
- Uplift cap. A written ceiling on renewal increases for the whole stack. Our uplift cap benchmark shows where caps have landed.
- Edge ratio in writing. The vDefend to edge core ratio stated in the order form, so the counting script cannot override the terms.
- Reduction at renewal. The right to cut vDefend cores at renewal without repricing the VCF line.
- Measurement method. Agreement that any true up uses the Security Usage Report, with written notice before a claim.
Where does the wider negotiation sit?
The full approach is covered in negotiating with Broadcom, and the 2026 position in our 2026 Broadcom VMware negotiation guide. For firewall scope questions raised in an audit, see our Broadcom audit defense service.
When should you start preparing for an NSX renewal?
Start a year out. Cluster mapping, rule cleanup and host consolidation all take time, and all three have to land before Broadcom takes the core count.
| Before renewal | What to do | Output |
|---|---|---|
| 12 months | Export the Security Usage Report and list every cluster with its billed cores | Baseline vDefend count |
| 6 months | Map clusters to security requirements, narrow Applied To fields and switch off idle IDS/IPS | Cluster map and cut list |
| 3 months | Consolidate low density hosts, collect a month of flow data and price alternatives | Evidence pack and alternative quote |
| 1 month | Present the scoped count inside the VCF negotiation and aim to sign at quarter end | Signed order form with named scope |
What to do next
- Inventory usage. Pull NSX feature usage by cluster from the manager plane before anyone quotes anything.
- Map requirements. Match clusters to real security requirements and regulated workloads, then build the cut list from that map.
- Rescope the attach. Keep vDefend on the clusters that justify it and leave the rest on native controls.
- Consolidate hosts. Retire low density hosts ahead of the core count snapshot, so the 16 core minimum stops manufacturing phantom cores.
- Negotiate together. Fold the NSX position into the VCF renewal at quarter end, and avoid negotiating the attach on its own.
Deciding what to do about VMware? Our Broadcom VMware negotiation services cover renewal, exit and audit, and work only for buyers.
Frequently asked questions
How is NSX packaged under Broadcom now?
NSX Networking is part of VMware Cloud Foundation, and advanced security is sold as vDefend, an add on priced per core. vSphere Foundation does not include NSX, so a vSphere Foundation customer who wants the distributed firewall has to move to VCF first.
How over scoped were the NSX environments you reviewed?
About half of the 20 to 30 files licensed advanced NSX security on clusters where only basic switching and routing ran. On those clusters the attach paid for firewall and threat prevention features that carried nothing beyond default policy.
What does cluster scoping actually save?
Across the files we reviewed, scoping vDefend to security relevant clusters cut the attach bill 25 to 45 percent. Where you land depends on how many billed cores sit in clusters with default policy only, which your cluster map shows before you talk to Broadcom.
Why does host density matter so much for NSX costs?
The attach scales with cores rather than usage, so a dense host pays on every core even where its policy is trivial. Denser hosts lower the platform bill, but they make each unnecessary attach more expensive per host.
What is the 16 core minimum?
Broadcom bills every CPU as at least 16 cores, for VCF and for vDefend on ESXi hosts. A host with two 12 core CPUs is billed for 32 cores. Consolidating low density hosts before the core count snapshot removes those phantom cores.
Does usage evidence change the price Broadcom offers?
In most of the files where customers presented it, yes. What works is a cluster by cluster view of rules, flows and enabled features that matches Broadcom's own usage report, so the account team cannot dispute where the numbers came from.
Where do you pull that evidence from?
From the NSX manager: distributed firewall rule counts, flow statistics and feature flags, gathered before any commercial conversation opens. On current versions the weekly Security Usage Report adds licensed cores per feature, and only the Enterprise Admin, Auditor and Support Bundle Collector roles can export it.
Should vDefend cover every cluster?
Rarely. In roughly 12 of the files we reviewed, uniform coverage meant paying advanced rates on a majority of cores running nothing beyond default policy. Cover the clusters with regulated, exposed or segmented workloads, and review that list at every renewal.
Does cluster scoping survive a true up?
In our experience, yes. Cluster scoped licensing backed by documented flow evidence passed every true up we defended. Keep Applied To scopes tight between renewals, because one broad rule added mid term can pull another cluster into Broadcom's count.
Should NSX be negotiated separately from VCF?
No. Negotiate it inside the VCF renewal, where the combined deal gives you a bigger number to trade against and quarter end dynamics apply. Negotiating the attach after VCF is signed leaves you a small line item with little room to trade.