Solved

Port binding in vmware

Posted on 2014-01-19
7
323 Views
Last Modified: 2014-02-03
I have done some reading about ports binding in vmware : Static,Dynamic,ephemeral, but since I have never had to use them in the past, I do not know what they mean, and when they come into play.



Any help on clearing this up, will be very much appreciated

Thanks
0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 25

Assisted Solution

by:Zephyr ICT
Zephyr ICT earned 125 total points
ID: 39793482
Hi,

This KB explains them better than I can write down: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1022312

What is it exactly that is not clear to you?
0
 
LVL 13

Assisted Solution

by:Abhilash
Abhilash earned 375 total points
ID: 39793523
Static is used for a secure environment. Where a switch reserves a port for a VM.
Dynamic is for an environment where over provisioning is okay. Imagine if you have 10 ports with you and you have 15 machines(of course you know only 10 will be powered on at any given time), then you can go with dynamic as the port association is removed when the machine is powered off.
Ephemeral port groups should be used only for recovery purposes when you want to provision ports directly on host bypassing vCenter Server, not for any other case.
0
 

Author Comment

by:jskfan
ID: 39794227
is port binding related to Virtual switches or Physical switches .?
I believe that Virtual switches can provide a huge number of ports, so I do not see where the port binding factors in.
I still can not understand where the concern about  the ports is, to the extent of implementing port binding.

Thanks
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 13

Assisted Solution

by:Abhilash
Abhilash earned 375 total points
ID: 39794247
Its on virtual switches. Yes they can provide around 4k ports. Imagine about a service provider or a big organization.
Ports are you main concern. Its about security. you cannot have a random unused ports in your network which can allow people from outside and create a VM on the hos and cause damage. For that issue you cannot have just Static binding as you will run out of ports. And if you don't have ephemeral when the vcenter is down then you will be in trouble.
The VMware hardening guide says you cannot have more number of unused ports on your switch as its a security concern. So you cannot create a switch with 4k odd ports and keep them open. You will need to create them when needed.
There are more use cases which all of us are not aware of. They would not have done it without a reason.
0
 

Author Comment

by:jskfan
ID: 39794263
they explain it here:
http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2038869

to my understanding if all Vmkernel interfaces (for iSCI) are in the same subnet, you should use port binding…else do not…
I cannot remember we had to configure port binding, when we configured vmkernel ports to use a different NIC than VM port group
0
 
LVL 13

Accepted Solution

by:
Abhilash earned 375 total points
ID: 39794281
Not just that. When you have a cloud environment and have no control over the network layer(per port) you will need these kind of bindings. Till 1.5 vCloud director used to create dv portgroups using ephemeral binding and now it creates it with static binding. You will need bindings as a measure of security when the ports are being bound to machines automatically when they are created.
0
 

Author Closing Comment

by:jskfan
ID: 39831172
Thank you
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

HOW TO: Upload an ISO image to a VMware datastore for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5) using the vSphere Host Client, and checking its MD5 checksum signature is correct.  It's a good idea to compare checksums, because many installat…
Giving access to ESXi shell console is always an issue for IT departments to other Teams, or Projects. We need to find a way so that teams can use ESXTOP for their POCs, or tests without giving them the access to ESXi host shell console with a root …
Teach the user how to delpoy the vCenter Server Appliance and how to configure its network settings Deploy OVF: Open VM console and configure networking:
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question