What Actually Changes About vDefend Licensing in 9.1
The 25-character license key you’ve been using since NSX won’t work on 9.1. Here’s what you need in place before you upgrade.
You’re planning the VCF 9.1 upgrade. The Connectivity Strategy feature is on the roadmap, the expanded IDS/IPS signatures are compelling, your DFW policy is as clean as it’s going to get before the migration. You’ve read the release notes. What you may have skimmed past is a section near the top of those notes that will stop the upgrade cold if you haven’t addressed it first: the licensing format changed.
Starting with vDefend 9.1, subscription-based license files replace the 25-character license keys that have been standard since the NSX era. If your environment is still running on those keys — and most environments that haven’t been through a recent licensing audit are — they need to be migrated to the new digitally-signed subscription format through the Broadcom Support Portal before you assign them to a 9.1 deployment. This isn’t a grace-period situation. The old key format doesn’t work on 9.1.
What actually changed
Three moving parts.
License format. The 25-character keys are out. You get a digitally-signed subscription license file instead. The migration runs through the Broadcom Support Portal — you convert your existing entitlements there before the upgrade. The new format carries cryptographic verification, which is why it’s not backward-compatible; it’s a different verification chain, not just a packaging change.
License Hub is now a required dependency. This is the part teams most often miss in the planning phase. vDefend 9.1 requires License Hub 5.1.2 to be installed and registered to VMware Avi Cloud Console before you can assign licenses. License Hub is the centralized license management and reporting layer — it’s where you assign capacity across vDefend and Avi Load Balancer deployments, and it’s what handles the compliance reporting cycle going forward. If you’re already running License Hub from the SSP 5.1.2 deployment (it shipped with that release), check the version. If not, it needs to go in as part of your 9.1 prep work, not as a follow-up task after the upgrade.
180-day usage reporting. Once you’re on 9.1, license usage must be submitted from License Hub every 180 days. In connected mode — where License Hub has outbound access to VMware Avi Cloud Console — this runs automatically. In air-gapped or restricted-connectivity environments, it’s a manual export-and-submit workflow that somebody needs to own. Add it to your compliance calendar now, because the 180-day clock starts at deployment, not at the next calendar quarter.
Why this is more than routine admin friction
Most license changes in enterprise software are administrative noise. Update a key, everything works the same. This one is different in two ways.
First, the License Hub requirement adds a net-new managed dependency to your vDefend deployment. It’s not a service you configure once and forget — it’s a component with its own version, its own registration state against Avi Cloud Console, and its own reporting cadence. If License Hub goes down or loses its registration, license reporting fails, and eventually your compliance posture does too. It needs to be in your monitoring, your backup procedures, and your runbooks. The time to discover that is not when you’re preparing for an audit.
Second, the format change has a sequencing implication for phased rollouts. If you’re upgrading some clusters to 9.1 while leaving others on 9.0, your license key migration and License Hub configuration need to be complete before the first 9.1 cluster comes up, not at the end of the rollout. Running the old format on 9.0 clusters and subscription files on 9.1 clusters in parallel is supported, but the 9.1 side has to be fully migrated before cutover. Don’t leave it as a post-upgrade cleanup item.
What to do before you upgrade
Pull your current vDefend license keys from NSX Manager and cross-reference them against what’s registered in the Broadcom Support Portal. If you see 25-character keys, start the migration now. The Support Portal conversion is not instant, and attempting it the morning of a maintenance window is the kind of thing that turns a two-hour upgrade into a five-hour outage bridge call.
Decide on your License Hub deployment posture. Connected mode with automated reporting to Avi Cloud Console is the right default for most environments. Air-gapped environments need a written procedure for the manual submission workflow before the upgrade happens.
Check your License Hub version. 5.1.2 is the minimum for 9.1. If you’re on an earlier version, that’s an upgrade that needs to land before or alongside vDefend 9.1 — not after.
Block time at the 180-day mark on your team’s calendar. The first reporting window isn’t a soft deadline.
The Connectivity Strategy feature and the expanded Distributed IDS/IPS signature library are worth the 9.1 upgrade. Getting there without a licensing surprise during the maintenance window requires roughly a half-day of prep work that doesn’t make it into the feature announcements.
Further reading
- VMware vDefend 9.1 Release Notes (Broadcom TechDocs)
- License Hub for vDefend and Avi — VCF 9.1 Design Blueprints (Broadcom TechDocs)
- VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale (VMware Cloud Foundation Blog)
- VCF 9.1 Licensing Model (Broadcom TechDocs)
- SSP 5.1.2 Release Notes — License Hub (Broadcom TechDocs)