Solved

Vmware Isolate VM's but allow access to servers

Posted on 2012-03-19
8
396 Views
Last Modified: 2016-11-23
Hello Experts,

I'm trying to accomplish a task in my lab where a number of VM's cannot communicate with each other but can talk to a group of servers and access the internet.

Currently I have 2 physical servers running ESXI 5 with Vsphere essentials (Standard vswitch).

I'm curious to see if anyone has some ideas how to accomplish this without doing the following:

1: Dedicating physical nics to VM's
2: Purchasing a license to support Vmware Distributed Switch

The firewall I have available is a Sonicwall NSA2400 and I have a Dell Powerconnect managed switch.

Each physical server has 4 available nic ports.

I've attached a PDF to show a basic example of what I'm trying to accomplish.

Thanks!
vlan.pdf
0
Comment
Question by:kinetik20
8 Comments
 
LVL 120
ID: 37739383
why not use a virtual router?
0
 
LVL 4

Author Comment

by:kinetik20
ID: 37739463
Hanccocka,

I was just reading about that!

Can you give any suggestions as to which to try and are there any adverse effects?
0
 
LVL 120

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 250 total points
ID: 37739505
Monowall, Freesco and Vyatta.

They all work very well.
0
Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

 
LVL 4

Expert Comment

by:R3C0N
ID: 37739528
I used this link quite a bit when setting up my lab. May not fit your requirements in whole but may spark an idea, for you to try.

http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/vmware/VMware.html

-R3con
0
 
LVL 4

Author Comment

by:kinetik20
ID: 37739586
Thanks so much for the information. I'll check everything out and see what I come up with.

How does using a virtual router stack up in a production environment? I can't think of any issues it would cause off hand?
0
 
LVL 120
ID: 37739597
I would select Vyatta for production, its a commercial product, with support rather than freeware
0
 
LVL 10

Accepted Solution

by:
172pilotSteve earned 250 total points
ID: 37739767
Also, if the four machines on the right side of your picture can't talk to each other, then you'll need to setup a separate port group for each of the servers...  Likely that these can be on separate standard switches with no uplink, and then whatever virtual router you will use should have one of it's "LAN" side ports connected into that port group.
0
 
LVL 4

Author Comment

by:kinetik20
ID: 37739827
Thanks 172pilotsteve.

I'm not sure this lab environment is going to translate into a working production environment.

I should have been more detailed in the Drawing I attached. I'm not seeing how VM's could on one physical host could be connected to a standard vswitch on another host.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article outlines why you need to choose a backup solution that protects your entire environment – including your VMware ESXi and Microsoft Hyper-V virtualization hosts – not just your virtual machines.
Teach the user how to install log collectors and how to configure ESXi 5.5 for remote logging Open console session and mount vCenter Server installer: Install vSphere Core Dump Collector: Install vSphere Syslog Collector: Open vSphere Client: Config…
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question