VCF Lab Network Subnets: BGP, TEPs and VyOS
Explore a VCF lab BGP and TEP subnet plan covering UniFi routing, VyOS WAN and LAN links, NSX uplinks and physical and nested tunnel endpoints.
Overview
My VCF lab networking plan groups UniFi routing, VyOS links, BGP uplinks and NSX tunnel endpoints separately from host and virtual-machine networks. This post explains how that routing layer connects the physical and nested parts of my lab.
Version context: September 2025
This subnet plan was originally published on September 8, 2025. The version context below is reconstructed from that date and contemporary release information; it is not an inventory captured from the deployed routers.
- VyOS: the likely release family was VyOS 1.5 rolling (Circinus). The exact nightly build was not recorded. See the August 2025 development update and September 2025 VyOS 1.5 update for contemporary rolling-release context.
- Dream Machine Pro: contemporary Ubiquiti Community release discussions identify UniFi OS 4.4.0 as an Early Access release around this period. It is a possible firmware context for this lab, not a confirmed installed version. The exact UniFi OS and UniFi Network application versions were not recorded; those are separate version numbers.
The UDM BGP arrangement below describes the original lab plan. It should not be read as a verified limit of every UDM Pro release, or as confirmation that a particular beta caused the behavior. Check the capabilities of the firmware and Network application you actually run before reproducing the topology.
Routing and tunnel endpoint design
I have already discussed the infrastructure and nested subnets that I will be using in this lab, in order to get those subnets to talk with each other I need to have the networking backbone to support all those separate layer 3 networks. I have decided to include my physical Ubiquiti routing with the NSX tunnel endpoints, BGP routing and the VyOS virtual uplinks so that these will be isolated from any of the physical hosts or virtual machines I am running.
| /27 Unifi Routing | DHCP Pool hosted by Dream Machine Pro for Ubiquiti components |
| /30 Virtual Router WAN | This is going to be used for the VyOS uplink to the physical network |
| /30 Virtual Router LAN | This is for the virtual side of the VyOS router, not necessary but give me a connection on both the LAN and WAN side for troubleshooting |
| /29 BGP Uplink1 Ubiquiti | BGP subnet on the Dream Machine to connect to the NSX running on my physical VCF stack |
| /29 BGP Uplink2 Ubiquiti | Reserved second uplink subnet in the original September 2025 physical NSX plan. Only the first UDM BGP uplink was used in that lab arrangement; this second subnet was a placeholder, not an active redundant path. The earlier description of a one-subnet UDM limit was not verified against an exact firmware/application build. |
| /29 Virtual Router BGP Uplink1 | BGP subnet on the VyOS router to connect NSX running on nested VCF Stack |
| /29 Virtual Router BGP Uplink2 | Secondary BGP subnet on the VyOS router to connect NSX running on nested VCF Stack |
| /27 Physical Host TEP | This is for the physical host tunnel endpoints used by NSX |
| /27 Physical Edge TEP | This is for the physical host NSX Edge tunnel endpoints |
| /27 Nested Host TEP | This is for the nested host tunnel endpoints used by NSX |
| /27 Nested Edge TEP | This is for the nested host NSX Edge tunnel endpoints |
Next steps
This is the final subnet I need to start building my lab, I am not going to get into the Dream Machine pro configuration as everyone likes to setup their systems differently and I have my system supporting a lab and home internet together so I don’t want to change my current configurations.
I will post a build guide for the VyOS router in the future to help with building the nested environment.
