How to "share" a public IP to a guest machine in VMware ESXi 4.1

I am helping a fellow classmate with a lab project that involves VMware ESXi ver4.1, and his project is a little different than normal because he chose to setup his installation on a personal physical box and use a personal IP address that he has purchased from an ISP.

Usually we are working with private IP addresses, and we do not worry about making efficient use of this resource because they are free.

Overall, the big picture assignment is to create a firewall in the vm with 2 nics, that connects Vswitch0 to Vswitch1, and on Vswitch1, setup a Web Server and a Client Machine (xp, Fedora, or Chef's Suprise).

We need to be able to serve out a web page that our classmates can reach from the client machines on their VM (the Client previously mentioned on Vswitch1 behind the firewall).

Not worried about the routing issues, or the network for communication of our individual esx servers for the class. But this one student who has separated himself from the group has created an interesting challenge to solve. I see it as a very good opportunity to learn more about networking, and solve a very real world problem.

Sorry about all the extra info.............  anyway.....

This one particular esx server, which has been assigned the public ip, which is up, running, has vms created on it, and can be reached across the internet with vsphere.

The network card for the esx server is assigned the public IP address.

The vm firewall WAN interface running on that esx also needs to be assigned to the same public IP.

Is this possible through some kind of bridging? Or am I looking at this the wrong way?

Thank you very much in advance - Smizz.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Install m0n0wall virtual appliance and publish web serwer through NAT.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Kent WSr. Network / Systems AdminCommented:
That's really going to depend on a lot of things.  Number one, what kind of connection is this, is it actually connected to his ISPs network, and is there anything other than, say, a cable modem in between the I'net and your ESXi?
If the ESXi box's main IP s the same as your Guest OS, you would have to use bridging.  The other choice is to use NAT.  Normally, you would setup a static, real-word IP inside the Guest OS, as you would a physical box.  You just assign a NIC to the guest OS, but set the IP parameters from within that install (ifconfig on Linux, Network Connections on Windows.  You also have virtual switch support...this post may help:
If ESXi has the public IP, I don't think you can share that with a VM.  The easiest solution would be to put an inexpensive hardware router in front of the ESXi host and assign it the public IP, then use a private IP for the ESXi host.
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Danny McDanielClinical Systems AnalystCommented:
If you only have one public IP and the single nic that management and the VM Network have to go through, you're gonna have to do something like jimmyray7 suggested.  

If you've got a second nic, then you could keep the mgmt network on the private network and connect the VM network to the public side.

The only other thing I can think of, and it's not pretty, is to have the mgmt and vm network on the same vswitch, but...
-set the option for the VM to startup/shutdown with the host
-install the vsphere client inside of your webserver (it'll have to be running windows)
-assign a 2nd vmnic to the vm
-give the nic on the 2nd vmnic a private IP
-change the mgmt IP to an IP on the same private network.

Now, to manage the host, you're gonna have to log into the VM with RDP or VNC and run the vsphere client.

I've never tried anything like this but I think it will work.
Danny McDanielClinical Systems AnalystCommented:
another option, if you have a second computer and a simple switch...

plug the public side and both computers into the switch.  use private static IP's on the 2nd computer and the ESXi mgmt network, leave the VM with the public IP or set to DHCP if that's how it's getting the public IP currently.  The 2nd computer won't be able to get to the internet unless you set up the 2nd nic on the web VM and do some kind of NAT or Internet Connection Sharing.  The 2nd computer is only there for mgmt of ESXi so it doesn't have to always be connected.
SmizzongAuthor Commented:
All of these helpful solutions have merit, and have good points or ideas to consider......

It seems that ESX was designed to have a "management interface" - that must have it's own independent IP address, and then the vm's on the first/default vSwitch "0" will also be able to communicate on the same network segment (same network address range) as the the "real" physical network adapter of the host server (bare metal box).

In this case, the student decided to leave the public IP address assigned to the management interface, and used a "home based router/switch" which was assigned another separate public IP address. From this device, they served out an IP address to the virtual machine firewall WAN interface.

I guess the IP addresses that he has reserved from the ISP are just end of the line IP addresses. He does not actually have access to a default gateway address within his range of five IP's.

block of 5 ip's. eg.
All are valid public IP's that he accesses from a modem in a "pass through mode" with multiple ports, acting like a switch. He cannot actually set one statically as the IP on a router, and then specify a default gateway. He says he must setup the interface to accept DHCP to pull the IP address, and the DNS and DG are automatically set)

Thank you to all of you for your help and ideas. I am sure that it is obvious that I still have much to learn, but that is exactly what I intend to do.

Thanks again, and if you have any other ideas, or questions about all this stuff I just typed up, please post it. I will be back to check and follow up.
Hello I have the same problem almost.

I have a dedicated server at kimsufi running esxi 5.0 with one ipv4 assigned to the management and I also have 1 public ipv6

I only have one physic nic

So im trying to get my VM's to access the internet

What is the solution here?
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.