?
Solved

Adding a new VMware ESX host into VCentre within DMZ

Posted on 2014-02-02
13
Medium Priority
?
1,835 Views
Last Modified: 2014-03-08
Hi

I need to add a new VMware ESX host in an existing VCentre but needs to be configured within a DMZ architecture:-

So:-

1) What configurations do I need to do within VCentre, i.e network switches, etc..
2) The host be configured in its own DMZ but still needs to be available on the main internal network
3) What ports need to be enabled in firewall, to able to see DMZ servers and able to connect to these clients

Thanks
0
Comment
Question by:rakkad
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
13 Comments
 
LVL 123
ID: 39827545
1. Can be done in different ways depending upon policys in your organisation, either with:-

a). a dedicated vSwitch and at least two uplinks which connect to your DMZ, and then create a Virtual Machine Portgroup with a network label of DMZ.

b) it can be done with VLANs, and you would pass that VLAN to a vSwitch, and use VLAN tags on the Virtual Machine Portgroup

2. Do you really want to put the Host in the DMZ, we do not generally put hosts in the DMZ, we put Guests in the DMZ using the above, because you've got more network configuration, more ports to open, and the "surface area" is larger, e.g. because you've put the host in the DMZ.

3. There are many, many ports you would need to open, if you vCenter Server is in the Internal LAN

see here:-

Required ports for configuring an external firewall to allow ESX/ESXi and vCenter Server traffic

TCP and UDP Ports required to access vCenter Server, ESXi/ESX hosts, and other network components

So you need to think carefully about actually putty and install the HOST in the DMZ.
0
 

Author Comment

by:rakkad
ID: 39827610
Thanks for the comment !!

Is there a preferred recommendation and can you forward any possible design configurations ?

Thanks once again
0
 
LVL 123
ID: 39827627
Yes, it's in my first post.

Do not put the Host in the DMZ, and use 1a and 1b.
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 

Author Comment

by:rakkad
ID: 39827678
Thanks I'll keep you posted how I get on
0
 

Author Comment

by:rakkad
ID: 39828362
Will it possible to illustrate this in a form a pictorial representation of how It may hang together ?

Thanks
0
 
LVL 123
ID: 39828389
Yes, no problems, questions please ask....

ESXi Network
this assumes, placement of Host in Internal LAN, DMZ is connected to a vSwitch, and DMZ VMs will connect to this vSwitch only.

No traffic can pass between vSwitches, so is isolated in the switches in ESXi
0
 

Author Comment

by:rakkad
ID: 39843993
Hi

I have been going over this and still confused as it whether to put the host in the DMZ network (192.x.x.x) or in the internal VLAN 226 (VMware LAN) then connect to the DMZ.

If I we're to put the host in the DMZ straight, how difficult would this be for this host to connect to VCentre  ? What problems could run into ?  In your experience would organisations follow the rule to put the host in the internal LAN then connect to DMZ

Is this way, the DMZ host needs to see the VCentre, as apposed in the reverse way

Also, would you recommend DHCP or keep static IP addresses for VM guests

Thanks

I hope I am clear with the above
0
 
LVL 123
ID: 39844055
You will need to open many ports, between vCenter Server on production LAN and ESXi server in the DMZ.

Also your attack profile is higher, putting the entire HOST in the DMZ.

ALL our clients DO NOT put the Hosts in the DMZ, they connect network interfaces on the host to DMZ.

All servers, physical or virtual have Static IP Addresses.
0
 

Author Comment

by:rakkad
ID: 39844431
So to summarise, from your suggestions I put the new host in the existing Vcentre which is in the VLAN 226 - internal network, followed by Vswitches to connect to the DMZ 192.x.x.x

Thanks again for your speedy response
0
 
LVL 123
ID: 39844447
Correct, that's how it's done. Reduces attack footprint of not having management Interfaces in the DMZ for the Host Server.
0
 

Author Comment

by:rakkad
ID: 39878581
I have setup the DMZ VMware setup.  Can you verify the diagram and see if I have done it correctly.

Also, I have noticed that the vmnic0 is showing 10 instead of 1000

Also, vmnic1 to 3 is showing as standby and there is no actually connection, is there any reason for this ?

Can you assist, what can I do to check the above ?

Thanks
image.jpg
0
 
LVL 123

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 1500 total points
ID: 39879025
There is a network fault with vmnic0, e.g. cable is not correct, port is not correct, it should show 1000, not 10.

I would check the port, cable, physical network port.

It looks like you have configured 3 nics, as standby, you will need to edit the vSwitch and decide what to do with these nics?

and move them up into Active or Unused.

Make sure if using 2 or 4 nics, that you have the correct teaming policy and physical switch configuration in place.
0
 

Author Closing Comment

by:rakkad
ID: 39915083
Thanks forum help in this call your solutions helped alot
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
Teach the user how to install log collectors and how to configure ESXi 5.5 for remote logging Open console session and mount vCenter Server installer: Install vSphere Core Dump Collector: Install vSphere Syslog Collector: Open vSphere Client: Config…
This Micro Tutorial walks you through using a remote console to access a server and install ESXi 5.1. This example is showing remote access and installation using a Dell server. The hypervisor is the very first component of your virtual infrastructu…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question