Build1 publisher2 min readPublished
Broadcom's VP says VMware "walked back" from SmartNIC network offload
The Distributed Services Engine still ships inside Cloud Foundation, but the SmartNIC-resident distributed firewall that justified it is no longer sold, and Broadcom's lifecycle documentation ends the matching security capability by October 2027.
The Engineer · Build desk

What happened
- Broadcom VP/GM Umesh Mahajan told VMware Explore this month that the company has stepped back from SmartNIC-based network offload, the layer VMware spent years building the Distributed Services Engine around.
- The specific product VMware stopped selling is the SmartNIC-resident distributed firewall, the flagship case for moving network and security enforcement off the host CPU.
- Broadcom's lifecycle documentation discontinues Network Introspection for Security after the final NSX 4.2.x release or on October 11, 2027, whichever comes first, for customers under active contract.
- VMware's replacement is a narrower direct offload on Nvidia's ConnectX-7, opportunistic where the original DSE pitch covered network and security across the whole estate.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure An estate that built micro-segmentation on Network Introspection for Security is on a clock that can close earlier than the calendar date, because the boundary is whichever trigger lands first and the support commitment covers only customers under active contract.
- decision The SmartNIC firewall is withdrawn from sale, so any growth in east-west policy enforcement has to go back onto host CPU or into the narrower ConnectX-7 path.
- constraint The next NIC offload proposal has to price a second firmware and driver lifecycle and an extra failure domain against CPU savings that each conventional NIC generation keeps eroding.
Micro-segmentation was the workload that made the offload case. On estates running east-west policy across thousands of VMs, every hop through a software-based firewall on the host competes for CPU with the workloads it is supposed to protect [6]. The Distributed Services Engine's distributed firewall promised that enforcement at line rate without consuming host CPU cycles [5], and pushing it to the NIC was architecturally sound [17].
The same design added a new firmware and driver lifecycle, a new hardware dependency, and another failure domain NSX operators had to reason about during an incident [7]. For that to pay, the reclaimed host CPU has to be worth more than a second lifecycle to track and one more component to rule out during an outage. According to the dev.to account, conventional NICs improved enough to narrow the case for offload, while customers kept talking and were not buying [9].
Two local measurements decide whether that verdict transfers to your estate: the CPU share the host firewall takes at peak, and how much of it a NIC generation you were already buying absorbs on its own. VMware's answer to the second one moved during the product's life [9]. Mahajan said the company has "walked back from that space" [1], which dev.to calls the plainest public statement anyone at Broadcom has made about the Distributed Services Engine's trajectory [14].
The write-up is precise about scope. DSE itself remains part of Cloud Foundation and supported [2]. The SmartNIC-resident distributed firewall is the specific thing VMware stopped selling [3]. The ConnectX-7 work Mahajan described is a separate, narrower direct-offload mechanism that does not continue the original DSE security pitch [11]. dev.to says reading the episode as "VMware abandoned DSE" overstates what happened [12].
The technical record has a gap in it too. Of the three silicon vendors named, two, AMD and Nvidia, got through technical viability and much of the integration work, and Intel did not, with microcode complexity that never fully resolved [8][15]. dev.to calls that an execution detail and locates the real failure in the commercial case [18]. That reading is available, but an offload layer that works on two of three vendors' parts is also a procurement constraint.
What a customer can plan against is the paperwork. dev.to says three items carry the direction: Explore commentary, the sales withdrawal, and a documented lifecycle date [16]. The five-step dependency model the write-up runs the evidence through is Rack2Cloud's own; VMware did not state it as a framework [13].
What to watch
- The ship date of the final NSX 4.2.x release. That date can close Network Introspection for Security earlier than the stated calendar boundary.
- Whether Broadcom extends lifecycle notices beyond the security capability built on DSE to the Distributed Services Engine itself.
- Whether the ConnectX-7 direct-offload work gets a supported hardware list. A list would show how narrow the narrower pivot is.