Migration & Modernization
Amazon EVS with NSX Federation for Disaster Recovery and Multi-site Networking
Introduction
Amazon Elastic VMware Service (Amazon EVS) now supports NSX Federation, giving you a powerful new option for enterprise-scale networking, disaster recovery, and multi-site networking when running VMware workloads on AWS.
NSX Federation is a VMware networking capability that connects multiple NSX environments under a single Global Manager control plane. It extends overlay networking, security policies, and gateway services across locations, so you can manage networking for multiple sites as one unified fabric rather than configuring each site independently.
VMware Cloud Foundation Operations HCX (HCX) is VMware’s solution for migrations and network extension during migrations. NSX Federation complements HCX by addressing scenarios that require larger-scale Layer 2 extension, unified security policy across locations, multi-site mesh connectivity, and native disaster recovery with sub-minute failover.
In this post, we explain why this matters, how NSX Federation extends your networking capabilities beyond what HCX provides alone, and how it enables true multi-site networking for your workloads.
The challenge: When enterprise networking outgrows a single solution
VMware HCX Network Extension (NE) is a proven, purpose-built technology for stretching Layer 2 segments between sites during migrations. It’s effective and fast to deploy for migration workflows and small-scale DR scenarios. However, as enterprises scale, they often need additional capabilities alongside HCX:
- Large VLAN counts – Environments with hundreds of VLANs benefit from a fabric-level approach rather than per-appliance-pair extension.
- Unified security policy – Distributed Firewall (DFW) rules that apply consistently across all locations, not just within a single site.
- Multi-site mesh networking – Native support for three or more locations without complex hub-and-spoke topologies. Federation lets you add a new site as a configuration step rather than re-architecting your entire network.
- Stateful DR failover – Sub-minute network connection recovery with full stateful services preserved during failover.
This is where NSX Federation comes in: not as a replacement for HCX, but as a complement that addresses these enterprise-scale requirements.
The solution: NSX Federation on Amazon EVS
NSX Federation creates a unified overlay networking fabric managed by a single Global Manager that spans all participating locations. It works alongside HCX, with each technology serving its strength.
What NSX Federation provides
| Capability | What it means for you |
|---|---|
| Thousands of segments | Global Segments scale to thousands across the federated fabric |
| Unified Distributed Firewall | DFW rules are defined once on the Global Manager and enforced consistently at all locations |
| Multi-site mesh | Federation natively supports multiple locations. Adding a third or fourth site is a configuration step, giving you true multi-site connectivity without building complex point-to-point links |
| Stateful gateway failover | Active-Standby Tier-0 gateways provide sub-minute failover with full stateful services (NAT, Gateway Firewall) |
| Single pane of glass | Global Manager provides centralized management across all federated locations |
Multi-site networking in practice
One major advantage of Federation is how it handles multi-site connectivity. In traditional approaches, connecting three or more sites requires building individual point-to-point links and managing routing between each pair. Federation eliminates this complexity by treating all locations as members of a single fabric:
- A workload at Site A can communicate with Site B or Site C over the same Global Segment with no additional configuration.
- DFW policies follow the workload regardless of which site it runs on within the fabric.
- Adding a new site means registering it with the Global Manager and deploying local edge nodes. The existing networking objects (segments, firewall rules, gateways) automatically extend to the new location.
This makes Federation particularly valuable for organizations operating across multiple AWS Regions or Availability Zones, or maintaining hybrid connectivity with on-premises data centers.
Business value: Why this matters for enterprise cloud adoption
1. Unblocks stalled migrations
Multiple enterprises were blocked on Amazon EVS adoption because their requirements for multi-site DR and IP-preserving connectivity across hundreds of network segments were achievable through migration tooling, but only at a resource cost that made it impractical at scale. NSX Federation directly unblocks these organizations, enabling production deployments to proceed.
2. Reduced operational complexity
Federation consolidates large-scale L2 extension into a single managed fabric. The operational burden drops significantly:
- One Global Manager provides centralized control across all locations
- One set of DFW policies applies consistently everywhere
- One failover mechanism (Active-Standby T0) handles network failover natively
3. True business continuity
NSX Federation on Amazon EVS delivers:
- Networking RTO: less than 1 minute with Active-Standby Tier-0 gateway failover. Achieving this requires automation in place for NSX failover and AWS-side networking changes such as route table updates.
- RPO: approximately 5 minutes with Amazon FSx for NetApp ONTAP SnapMirror replication (or 0 RPO with Multi-AZ deployment)
- Consistent security posture with DFW rules active at both sites before, during, and after failover
HCX and NSX Federation: Better together
HCX and NSX Federation serve complementary purposes and work well together. Here’s how to think about when each shines:
| Use Case | Recommended Approach |
|---|---|
| Migration (bulk vMotion/replication) | HCX, purpose-built for migration workflows |
| L2 extension with a small number of VLANs across two sites | HCX Network Extension, straightforward and fast to deploy |
| L2 extension at scale (large VLAN counts or three+ sites) | NSX Federation, fabric-level approach without per-appliance caps |
| Multi-site DR with stateful failover | NSX Federation, Active-Standby T0 with less than 1 min RTO |
| Consistent DFW policy across sites | NSX Federation, unified security from Global Manager |
| Three or more sites | NSX Federation, native multi-location mesh |
| Migration + DR (combined) | Both: HCX for migration mechanics, Federation for permanent networking and DR |
Enterprises can use both: HCX handles the migration journey, and NSX Federation provides the long-term networking and DR foundation once workloads are in place.
Conclusion
In this post, we showed how NSX Federation on Amazon EVS expands what’s possible for enterprise VMware networking on AWS. It complements HCX with fabric-level L2 extension, unified security policy, native multi-site mesh connectivity, and sub-minute DR failover. Together, these capabilities give you the tools to address enterprise-scale requirements that go beyond migration.
You might be planning a large-scale migration, building a multi-site DR architecture, or connecting workloads across multiple AWS locations and on-premises data centers. Whatever the scenario, the combination of HCX and NSX Federation on Amazon EVS provides the networking foundation to do it right.
Ready to get started? Contact your AWS account team to discuss NSX Federation deployment for your environment, or explore the Amazon EVS documentation for more details.