VCF & VVF Add-On Services
Extend your platform.
On your terms.
VCF and VVF include a comprehensive base platform β add-ons layer in advanced security, AI infrastructure, disaster recovery, load balancing, and expanded storage exactly where your workloads demand it.
Add-ons are licensed separately from VCF and VVF subscriptions. 27 Virtual designs, deploys, and operates every add-on listed below β architecture, deployment, Day 2 operations, and knowledge transfer included in every engagement.
Security Add-Ons β VMware vDefend
VMware vDefend Distributed Firewall provides hypervisor-level east-west security β stateful L4βL7 firewalling that follows every workload regardless of where it moves. Gateway Firewall handles north-south controls at the NSX Tier-0/Tier-1 boundary.
- Distributed Firewall β stateful L4βL7 at every workload
- Gateway Firewall β north-south NSX tier boundary controls
- Identity-based access policies (Active Directory integration)
- Policy automation via VCF Operations console
- GenAI Assistant for firewall operations and troubleshooting
Multi-layered threat detection on top of the base firewall β IDS/IPS, Network Traffic Analysis (NTA), Network Detection and Response (NDR), and sandbox-based malware analysis. Designed to detect and stop lateral ransomware movement at the hypervisor level.
- IDS/IPS β signature and behavioral threat detection
- Network Traffic Analysis (NTA) for anomaly detection
- Network Detection and Response (NDR) sensor
- Sandbox malware analysis and fileless in-memory threat blocking
- AI-assisted threat correlation and automated response
Application Delivery Add-On β VMware Avi Load Balancer
The only load balancer with true plug-and-play integration with VCF through VCF Operations β including automated lifecycle management of the Avi controller cluster. Delivers L4βL7 load balancing for VMs and Kubernetes workloads (VKS). Default VCF includes only legacy NSX L4 load balancing; Avi Enterprise is required for production app delivery.
- L4βL7 application load balancing for VMs and containers
- Global Server Load Balancing (GSLB) across data centers
- Web Application Firewall (WAF) with OWASP Top 10 protection
- Post-Quantum Cryptography (PQC) support β NIST-approved
- AI-powered GenAI assistant for operations and troubleshooting
- Avi Quick Start Wizard β reduces Day 0 deployment time dramatically
Automated failover, non-disruptive DR testing, and workload recovery orchestration across VCF environments. Integrates with vSphere Replication and supports recovery to on-premises and cloud-validated recovery sites. VMware Live Cyber Recovery adds isolated data clean rooms for ransomware recovery scenarios.
- Automated failover and failback with recovery plans
- Non-disruptive DR testing without impacting production
- RPO as low as 5 minutes with vSphere Replication
- Multi-site recovery plan orchestration
- Live Cyber Recovery β isolated clean room for ransomware recovery
AI Infrastructure Add-On β Private AI Foundation with NVIDIA
Transforms your VCF environment into a fully operational on-premises AI platform, integrating NVIDIA AI Enterprise with VCF infrastructure to deliver GenAI inference, model training, and agentic AI without data leaving your perimeter.
Validated on NVIDIA-certified HGX servers (H100/H200 GPUs). Benchmarks show virtualized GPUs deliver 1β2% variance from bare metal for LLM inference workloads β near-bare-metal performance with full virtualization benefits.
PAIF Components
Add-On Compatibility
How 27 Virtual Helps You
The right add-ons,
deployed at the right time.
Add-ons are powerful β and easy to over-buy or under-deploy. We assess what your environment actually needs, integrate the right tools cleanly with your existing VCF or VVF, and make sure your team can operate them confidently from day one.
Phase 01
- Security posture & exposure review
- Performance & traffic baseline
- DR / RPO / RTO objectives
- AI workload readiness check
Phase 02
- Match add-ons to actual needs
- Right-sized licensing & sizing
- Business case & TCO modeling
- Phased adoption roadmap
Phase 03
- Existing VCF / VVF compatibility check
- Network & firewall change design
- Identity & RBAC mapping
- Change windows & rollback strategy
Phase 04
- Production deployment & configuration
- Policy authoring (vDefend, Avi)
- Replication & recovery testing
- Performance baseline & tuning
Phase 05
- Runbooks & response playbooks
- Monitoring & alerting integration
- Operator training & cert prep
- Quarterly tuning & policy review
The 27 Virtual Difference
Why teams choose us
over anyone else.
Add-ons are easy to over-buy and under-deploy. We have integrated every one in production β and we will tell you which you actually need.
Engagement Models
We meet you
where you are.
Pick the right add-ons. Deploy them cleanly. Operate them confidently. Three engagement types, one outcome β value from day one.
- Security and exposure review
- Performance and traffic baseline
- DR / RPO / RTO objectives modeling
- Right-sized recommendation set
- TCO and adoption roadmap
- Compatibility and pre-flight checks
- Production deployment and policy authoring
- Replication and DR testing
- Performance baseline and tuning
- Operator runbooks delivered
- Policy review and tuning
- Alert and monitoring integration
- Runbook authoring and response playbooks
- Operator training and certification prep
- Quarterly tuning cadence
"The organization and project management are top notch. One of the top, if not the top, long term technical engagement that I have ever been involved with. 27 Virtual brought VMware expertise we simply did not have in-house β and left our team better for it."
Are Add-Ons Right for You?
Our free Add-On Fit Assessment covers six dimensions in under an hour β no prep required.
Not sure which add-ons you need?
We assess your security posture, workload requirements, and DR objectives β then recommend only the add-ons that deliver real value.

