How to stretch a VLAN into an NSX overlay across two completely separate environments
When you’re dealing with brownfield environments, legacy VLAN‑connected workloads, or a site that has no NSX footprint at all, we can migrate VLAN based workloads to NSX overlay so in this walkthrough, I’ll show you how to use NSX L2VPN + IPSec with an NSX Autonomous Edge to stretch a Layer‑2 segment from an NSX environment (Site 1) into a completely separate site (Site 2).
The result is a single broadcast domain spanning both locations — perfect for workload migration, IP preservation, and phased cutovers. You could also use the HCX peering too but this write up covers just the IPsec VPN.
Scenario Overview
- Site 1
- Full NSX deployment
- T1 VPN Gateway available
- Overlay segments already in use
- Goal: stretch an NSX overlay segment to Site 2
- Site 2
- No NSX
- A standalone ESXi host (vvf‑esx02.ash.local)
- VLAN‑connected workloads
- Goal: connect to Site 1 using an NSX Autonomous Edge appliance
The Autonomous Edge acts as a lightweight NSX endpoint capable of L2VPN and IPSec — ideal for brownfield sites, labs, or isolated environments

Create Port Groups
To mimic a site that has no NSX i am using a spare esx host vvf-esx02.ash.local and i’ve added the following port groups
On the ESXi host, create the port groups you need:
- Management
- Outside‑net (public or NAT’d IP)
- Trunk (VLAN 50 in your example)
- Important: VPN does not support Active/Active uplinks. Use Active/Standby.

Deploying the NSX Autonomous Edge (Site 2)
You deploy the Autonomous Edge OVF with the following typical interfaces:
| OVF Template Name | Port Group | Edge UI Name | IP Address |
|---|---|---|---|
| Mgmt | Management | Management (eth0) | 172.16.11.0/24 |
| Outside-net | Uplink | eth1 | 172.16.22.0/24 |
| Network 2 | Trunk | eth2 | vlan 50 |
| Network 3 | – (HA, not used here) | eth3 | – |
The deployment of this OVA is similar to teh regular NSX appliance until it gets to teh networking section, Provide the networking as above.

We arent using NSX manager here so just scroll to the last section.

We are configyring an NSX autonomous edge so click the option

The rest is all standard config such as hostname, ip, etc.

Enable the root acess as well at this stage if required.

This is the most umportant section in the NSX automonius egge config. The external port is actualy the wan port that leads to the outside so we need to put the config in a specific way as shown

Skip all the HA bits if not required

Review and continue

Review and hit finish


Power on the VM

The NSX autonomous edge will show its L2 vpn link as down ands thast fine.

The main config is In the l2 vpn section, the local IP is the uplink ip of this autonmous edge to outside world, the rmeote ip will be ip of the NSX at our main site and the peer code is something we get from the main NSX vpn config so lets begin the config at the NSX manager end.

Configure IPSec on NSX (Site 1)
We will create a new T1 GW, this step is actually optional, you can just create it on your original T1 or T0 gW

Ensure that you enable route advertisement for IPSec endpoints, and connect the T1-GW to the T0

The T1 gw is now ready and we will attach our overlay segments later to this gateway.

First we need to add an IPSec Service, which is the underlying protocol for the L2 VPN connection
In the NSX UI: Networking → VPN → Add Service → IPsec

Provide:
- Name: Something meaningful
- Gateway: T1
This creates the container for all IPsec sessions.

Create the L2VPN Server (Site 1)
Next we need to add an L2 VPN Server. We click on Add Service > L2 VPN Server:

This is the NSX side of the stretched segment.
- Name –
- Service Type – L2 VPN Server
- Gateway:
t1-vpn-gw
The b


Create the Local Endpoint
A local VPN endpoint is required and must be advertised throughout the network. Click on Local Endpoints > Add Local Endpoint:
The Local Endpoint is the IP address NSX uses for the VPN. Networking → VPN → Local Endpoints

- Name
- IPsec Service: The one created earlier
- IP Address: A public IP or NAT’d IP
- Local ID: Usually the same as the public IP
This is the IP your upstream firewall must forward traffic to.

Local endpoint is ready and this the IP we will be connecting into

Choose to add a new L2 VPN Server

We enter a name, select the L2 VPN service, and the local endpoint. We must also specify the remote IP address which is the IP address that we configured on the uplink interface of the customer’s NSX Autonomous Edge (10.203.226.254). A valid CIDR for the tunnel interface is required as well:

Download the vpn config file


Open the VPN config file and copy the peer code

Add L2 VPN Session on NSX Autonomous Edge UI
At peer site, after logging in to the NSX Autonomous Edge UI we click L2VPN > Add Session

Give session a name, local ip is the wan ip of nsx autonomous edge and remote ip is the ip of the nsx manager l2 vpn endpoint, and then copy the peer code the nsx l2 vpn server session

Session is established and the link shows its UP so this shows we will now be able to move traffic over segments.

Go to L2 VPN Port – Give port name as the portgroup name and vlan id and ensure to pick eth3.. eth3 is the interface we trunked.

On the port section, i’ve added few more portgroups

Finally, we will go to L2VPN to attach port

Give a session name , choose all the ports we wish to be encapsulted over vpn, give tunnel id as any

vlan 10, vlan 20 , 30 is now ready

The vpn tunnel is ready so the final task is going back to NSX manager VPN session and adding these tunnel ID’s to the VPN session to establish the connection.

