Configure Pod Egress IPs in vSphere Tanzu Integrated with NSX-T + pfSense

Job ID: 39846742

Budget: $10 – $30 USD

We’re running a vSphere with Tanzu Integrated environment — one Supervisor Cluster managing a Kubernetes workload cluster that uses NSX-T with Antrea CNI.

Outbound traffic currently works but always exits through a single public IP. Our pfSense firewalls already hold multiple public IPs, and the goal is to build a repeatable way to assign specific egress IPs to subsets of pods, ensuring their outbound traffic exits via the designated public IP while all other pods continue using the default SNAT.

Scope:
Design and document the recommended approach for Tanzu + NSX-T + Antrea that cleanly integrates with pfSense (Antrea Egress, NSX-T NAT rules, pfSense IP aliases, or hybrid).

Provide the necessary YAML manifests / Antrea policies, NSX-T configuration steps, and any Tier-1 / Tier-0 edits required.

Show validation with simple tests (e.g. kubectl exec with curl) demonstrating that selected pods use the correct egress IP, while others are unaffected.

Provide clear rollback steps.

Notes:
I can assist with implementation, but direct access to the environment cannot be provided.

Required Skills:
VMware vSphere with Tanzu Integrated (Supervisor + Workload clusters)
NSX-T networking (NAT/SNAT, routing, Tier-0/Tier-1)
pfSense firewall administration (NAT, outbound rules, public IP mapping)
Kubernetes + Antrea CNI (egress policies, pod networking)
Related categories: Linux VMware Network Administration Kubernetes DevOps