Configure 2 networks on VMWare 4.1 ESXi

Posted on 2013-05-21
Last Modified: 2013-05-22
I have built a VMWare server using ESXi 4.1 and installed 4 hosts on it. One of the hosts is a web server that gets traffic from internal users as well as external users. (At one time I had this host configured on an infrastructure 3.5 server, but it had hardware problems so I had to get a replacement server)

The 4 hosts that are accessed by internal users are connected to the same Nic (vswitch0).  The web server is connected to a 2nd nic (vswitch1). The internal connections work fine, but I can't get access to the web server thru the 2nd nic.

My mgmt network is connected to vswitch0 and is a 10.0.0.x address. I can access it with vspere client from the 10.0.0.x subnet.

The 2nd nic (vswitch1) is connected directly to a DMZ in one of my firewalls. This firewall has port 80 traffic directed to the IP address of the 2nd nic in the webserver (this used to work in the 3.5 setup). However, when I look at the settings of the 2nd nic from VMWare, the observed Ip range it shows is the single public ip address of my firewall.

I am using an IP range of 10.10.10.x on the DMZ and as the hard coded IP on the 2nd nic of the web server (no dhcp on this subnet).

But since the observed range is the external IP of the firewall, then it doesn't work, so I am really confused as to what to do to fix it.

Any help would be greatly appreciated.
Question by:ricklr
  • 5
  • 4
  • 3
LVL 119
ID: 39186573
if you put a device on the DMZ network can you ping the interface

can you also upload screenshot of your networking

(also small thing, we refer to VMs as Guests, Hosts are the actual physical server that ESXi 4.1 is installed on).
LVL 11

Expert Comment

ID: 39187909
When you say you cannot get access through the 2nd NIC, do you mean access from outside, or inside? Also, what sort of access - management or www/http access? Does it look to you as a L3 or above problem - for instance, can you ping the server? Can you telnet on port 80?

Could you provide a little diagram?


Author Comment

ID: 39188258
Vsphere networking screenshotHey thanks guys for getting back quickly.  I would've been here earlier, but I'm a one man IT shop, so things got in the way.....nobody here ever experiences, that right??? ;-)
I cannot ping from the DMZ. This web server cannot browse to the internet, as this is the gateway for that host (win2k3 server). If I switch the gateway to the 10.0.0.x network, it can browse the internet. The other 3 hosts can browse because they're on the 10.0.0.x subnet. If I put another device on the 10.10.10.x dmz and hard code the ip, I can browse the internet.
I'm not running any vLans or anything complicated. The DMZ is a physical network on a separate firewall with a separate public IP from my 10.0.0.x network.

I will try to post a pic with this of the networking setup from my vSphere screenshot. I will see if I can draw a pic of the connections to this server and post that.
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

LVL 119

Accepted Solution

Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39188307
I cannot see a VM currently connected to vSwitch1?

You have 4 VMs connected to vSwitch0?

Author Comment

ID: 39188330
That may be part of my problem.  I assigned the vmnic to the host and it has 2 nics shown active. Where do I look to make sure it's assigned?

Author Comment

ID: 39188345
ok, that was a dumb question on my part.  I see that and I'm changing it and restarting the host
LVL 11

Expert Comment

ID: 39188380
You say you are not running any vlans ... are you actually saying both physical NICs of you ESXi host are connected to a switch which by default would have all ports in vlan 1?? Not very good practice!

Also, hanccocka did make a good point! You are suppose to be able to ping once you connect another device to the same DMZ network! Though make sure you are setting up the same ip/mask on that device! On the same network, there is no gateways involved ... so you should really just get connectivity. Since you are not, you may have a misconfiguration on the vSwitch.

When you say the server cannot access the Internet, do you actually mean it is not meant to access the internet?

Regardless you do or do not access the Internet from that server, it doesn't really matter in terms of IP connectivity - say for example you use ping to test; when you ping your server, the reply will have to come back from that server! Firewalls normally dont' like asymetric traffic either ...

To be honest, quite a few things could be wrong here ... and you haven't yet provided enough info. You could have gateways wrong, or missing; or maybe windows firewall has got a funky config, is it even enabled; or maybe your firewall is lacking a policy, maybe it lost config, maybe your vSwitch has got something wrongly configured.

I could gamble through solutions but that's not the point for it might confuse things even more.

From my understanding based on details you provided, I've put together a lil' diagram. Does this match your setup at all??

Attaching ... give me a minute ...
LVL 11

Expert Comment

ID: 39188385
And yes ...  hanccocka made again a good point which I actually missed. The VM is not even attached to that 2nd network - I may not have to add a diagram after all... will wait for now!

And you shouldn't need to restart the host really!


Author Comment

ID: 39188503
hancocka hit the nail on the head.  I thought I had assigned the 2nd nic in the guest to the 2nd nic in the VMWare server, but they were both assigned to the same one.  I missed that.  I should've remembered that from the v3.5 setup I had.  argh.

Anyway, by assigning the 2nd nic in the guest, I can access it from outside and browse like it was before my reinstall.  YAY!!!!  I'll have a few happy least until something else annoys them!
LVL 11

Expert Comment

ID: 39188529
lol. Well done mate!
Happy employees is always good news!
LVL 119
ID: 39188604
it always helps to have a second pair of eyes!

Good Luck!

Author Comment

ID: 39188742
hey thanks again fellas!  Have a great day!

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Internet Protocol Security question 3 94
Remove Disconnected ESX Hosts 3 53
Restore VM Creates MAC Conflict. 6 42
Find the Size of the Folders in VM and Templates. 11 37
If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
In this article, I show you step by step with screenshots to assist you - HOW TO: Deploy and Install the VMware vCenter Server Appliance 6.5 (VCSA 6.5), with some helpful tips along the way.
Teach the user how to install and configure the vCenter Orchestrator virtual appliance Open vSphere Web Client: Deploy vCenter Orchestrator virtual appliance OVA file: Verify vCenter Orchestrator virtual appliance boots successfully: Connect to the …
Teach the user how to use create log bundles for vCenter Server or ESXi hosts Open vSphere Web Client: Generate vCenter Server and ESXi host log bundle:  Open vCenter Server Appliance Web Management interface and generate log bundle: Open vCenter Se…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question