Solved

Vmware Ports Security and Performance

Posted on 2014-03-31
9
301 Views
Last Modified: 2014-03-31
If I will have to think about performance and security regarding :

- VM Network : Host to Host Communication including VMHA, and Host to Vcenter communication
- Vmtion traffic
- Storage traffic


Having 2 x10GB physical Nics,  will this allow us to separate traffic for security and performance purposes? if so , please explain how to separate traffic and which traffic should never go the same way with other traffic?

I have also heard of system traffic and user traffic.
if I understand System traffic is the same traffic I indicated above, however user traffic is the way workstations get into the VMs, the only way I know is through the Network switch that connects to the SAN….I could be wrong. Please explain




Thanks
0
Comment
Question by:jskfan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 120

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39966803
You will need to separate using VLANs, so create a trunk network using your two 2 x10GB physical Nics, and then have different VLANs for vMotion, Management Network, and Virtual Machines.

But you will need a switch capable of VLANs.

User Traffic is known as Virtual Machine Network Traffic.

System Traffic - Management Network, vMotion, iSCSI storage

Have a look here

Pages 13 - 73 Discuss Networking in Detail, iuncluding trunks, VLANs, switches, and load balancing

ESXi Configuration Guide ESXi 4.1

http://www.vmware.com/pdf/vsphere4/r41/vsp_41_esxi_server_config.pdf

Virtual Networking

http://www.vmware.com/technical-resources/virtual-networking/virtual-networks.html

Virtual Networking Concepts

http://www.vmware.com/files/pdf/virtual_networking_concepts.pdf

http://en.wikipedia.org/wiki/Virtual_LAN

http://en.wikipedia.org/wiki/IEEE_802.1Q
Sample configuration of virtual switch VLAN tagging (VST Mode)

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004074

http://blog.scottlowe.org/2006/04/17/vlans-and-port-groups/

How to Setup VLANs

http://www.vladan.fr/great-kb-on-how-to-configure-vlans-on-vswitches-pswitches-and-vms/

VMware ESX Server 3: 802.1Q VLAN Solutions

http://www.vmware.com/pdf/esx3_vlan_wp.pdf

http://kb.vmware.com/kb/1004127

http://kb.vmware.com/kb/1004074

http://kb.vmware.com/kb/1004252
0
 

Author Comment

by:jskfan
ID: 39966833
I see…
So, for instance , I can create vmkernel for vmtion and another vmkernel for VMHA and assign them to the same physical NIC (10GB), but to 2 different Vlans ...
0
 
LVL 120
ID: 39966839
That's correct, but you will have to ensure you configure and build you network design correctly.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:jskfan
ID: 39966841
<<User Traffic is known as Virtual Machine Network Traffic.>>

is it how VMs talk to each other
OR how ESX hosts talk to VMs and vice-versa
OR how physical workstations in the office talk to VMs and back
???
0
 
LVL 120
ID: 39966843
All of the above, is correct, via Virtual Machine network.
0
 

Author Comment

by:jskfan
ID: 39967010
<<which traffic should never go the same way with other traffic?>>
if we consider the following types of traffic:
- Management Network : Host to Host Communication including VMHA, and Host to Vcenter communication
-VM Network
- Vmotion traffic
- Storage traffic
0
 

Author Comment

by:jskfan
ID: 39967024
I also am not sure if the communication between Vcenter and VMs is part  VM Network or Management Network
0
 
LVL 120

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39967100
It's Best Practice and Recommended, to make sure the following traffic is isolated if possible.

But you DO NOT need to follow these recommendations, it's up to your network design and implementation.

Management Network

VM Network

Vmotion traffic

Storage traffic

Management and VM Network traffic could be on the same network, or you could have a special Management Network for all devices.

vCenter Traffic, is part of VM Network, which could also be Management Network.,

e.g. vCenter Server needs to commnicate with ESXi on the Management Network.

But your management network could also be your Server Network (VM Network)
0
 

Author Closing Comment

by:jskfan
ID: 39967201
Thank you!
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

HOW TO: Connect to the VMware vSphere Hypervisor 6.5 (ESXi 6.5) using the vSphere (HTML5 Web) Host Client 6.5, and perform a simple configuration task of adding a new VMFS 6 datastore.
In this article, I will show you HOW TO: Suppress Configuration Issues and Warnings Alert displayed in Summary status for ESXi 6.5 after enabling SSH or ESXi Shell.
Teach the user how to delpoy the vCenter Server Appliance and how to configure its network settings Deploy OVF: Open VM console and configure networking:
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question