is it safe to virtualize my DMZ network on an ESXi 5.0 host, with internal networks also virtualized on the host?

currently i have 3 ESXi hosts
2 have management IPs that are in my internal network
1 has management IPs that are in my DMZ network

currently the 2 ESXi hosts on the internal network only host VMs that have internal network IPs, and the 1 ESXi host that are in my DMZ network only host VMs that lay in the DMZ

i want to enable HA or FT on the servers, so i need to put all 3 servers in the same cluster,
i would like to manage the 3 ESXi hosts with internal IPs,

in the event that i need to fail a VM over, the DMZ guest machines might need to run on a host that has internal network VMs running on it.
would this be OK from a security standpoint, if i have guest VMs running on both my DMZ and my internal network?
LVL 1
jsctechyInfrastructure Team LeadAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
Yes, we do and our clients do, the virtual switches are not connected.
0
Joseph DalyCommented:
Yes this can be done. You would need to configure a seperate network in VMware on all three of your hosts. This way you can specify which network each of your hosts will run on, either internal or DMZ.

I would suggest removing the management IP from the DMZ and only have the management go through internal.

As long as all three of your hosts can access both the internal and DMZ LAN you should be able to run HA failover without issue. The maps feature will help you determine if you have connections to these networks.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Joseph DalyCommented:
The first sentence should read.

"Yes this can be done. You would need to configure a seperate network in VMware on all three of your hosts. This way you can specify which network each of your VIRTUAL MACHINES will run on, either internal or DMZ. "
0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
perfectly safe, there is no communicatin between virtual switches.
0
jsctechyInfrastructure Team LeadAuthor Commented:
what if we only had 2 NICs per ESXi host?
all the servers are part of a HP c-class blade chassis, and the chassis has 2 switches in it, which is the equivalent of 2 physical NICs when presented to the blade servers
would vlans create the same security when dealing with the 10gb uplinks?
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
Use VLANs and Trunk network to host server
0
jsctechyInfrastructure Team LeadAuthor Commented:
would vlans provide the same security as the vswitches?
0
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
Yes, only VMs connected in the portgroup will be able to communicate with DMZ, this is what we do here, and on client sites, to reduce physical networking.
0
vmwarun - ArunCommented:
As long as the hosts see the same IP subnets, internal or DMZ would be easy to host. Make sure that you consider case sensitivity for port groups if you are going for Standard vSwitches.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
VMware

From novice to tech pro — start learning today.