External only NAT for Vmware?

Posted on 2009-04-13
Last Modified: 2012-05-06
Hello and thank you for your time,

I have a host machine with 10 NICs and I am trying to set up a virtual Windows Domain (complete with DC, DNS, Exchange, workstations, etc) and I want it to be completely seperate from the rest of my network.  I am having some trouble figuring out how to make this happen.  

I have been able to make the VM's talk to eachother and the rest of the corporate network but, I want to cut off access to the corporate network.  My initial thought was to set vmnet9 to be bridged directly to one of the NICs (Intel 5) and have that NIC plugged into my external firewall.  However, I could not figure out what IP addresses to assign to the virtual network adapter and the physical network adapter.  Let's say I want to use as my virtual network address space, what IP do I assign to the physical network adapter?  What IP do I assign to the firewall port?  Keep in mind that there will be multiple VM's on this network, so do I need to setup NAT?  If I use vmnet8, then they will have access to the internal network (which is exactly what I don't want).  

 Any assistance you can provide would be greatly appreciated!
Question by:Scottbem
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4

Expert Comment

ID: 24131671
NAT sounds like the simplest solution to what you are doing.  We use Lab Manager from VMware which does all this for us, but essentially it is the same concept where your portgroup is using a private network but has in/out access to the physical nic.

If you are running managed switches, you could setup your corp network on its own VLan and setup a trunk port to Internet access essentially segmenting the traffic and any broadcasts from the other side of your network.

Author Comment

ID: 24131765
Ok, but how do I configure vmware to use this private network?  More importantly, how do i configure the physical NIC?  

I will check out Lab Manager and let you know what I find.  

Expert Comment

ID: 24131870
My apologies for any delays in responces, Mondays are hell days here.

What version of ESX you running?  VC?  
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

ID: 24131959
I am running VMware Server 1.0.4 build 56528

Accepted Solution

isiHelpDesk earned 500 total points
ID: 24131999
Ah!  The Freebie....ok. Let me pull this info from the back of my brain.  I havent used it in a long time.  I will install it on a server here and see if I can do a walk through for you.

Author Comment

ID: 24132047
I can't even get one machine to be able to get to the internet.  I can't even ping the default gateway.

Here's what I've done so far (which doesn't work, btw) -

On the VM Console:  I set VMnet9 bridged to Intel 5.  NAT is still set to VMnet8.  DHCP is not configured for VMnet9.

On the first VM pc:  I set a static IP to with gateway (dns  Ethernet configuration is set to vmnet9.

On Host:  Intel 5 is connected directly to the firewall and has the following IP info: gateway: (dns
On Firewall:  Cisco ASA port 4 has IP of
I cannot ping the DG from the VM.  What am I doing wrong?

Author Comment

ID: 24132171
OK, I made some progress!
I was checking my firewall config and found that the port was disabled, DUH!
I enabled it and can now get out to the internet from my VM.  I can't believe I missed that.

I am awarding points because you were willing to help!

Author Closing Comment

ID: 31569598
Thank you!

Expert Comment

ID: 24132693
Thanks :)  Sorry I couldnt be more help quicker :)

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Mount cloned RDM in Windows VM without formatting 6 111
VMWare ESXi Guest CPU 8 134
RDM/VMFS5  limitation in vSphere 6.0 1 89
Ping to management is timing out. 6 54
In this step by step tutorial with screenshots, we will show you HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 6.5 (ESXi 6.5). This is important if you need to enable SSH remote access for additional troubleshooting of the ESXi hos…
In this article, I show you step by step with screenshots to assist you - HOW TO: Deploy and Install the VMware vCenter Server Appliance 6.5 (VCSA 6.5), with some helpful tips along the way.
Teach the user how to use vSphere Update Manager to update the VMware Tools and virtual machine hardware version Open vSphere Client: Review manual processes for updating VMware Tools and virtual hardware versions: Create a new baseline group in vSp…
This Micro Tutorial walks you through using a remote console to access a server and install ESXi 5.1. This example is showing remote access and installation using a Dell server. The hypervisor is the very first component of your virtual infrastructu…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question