Solved

Vmware Ports Security and Performance

Posted on 2014-03-31
9
300 Views
Last Modified: 2014-03-31
If I will have to think about performance and security regarding :

- VM Network : Host to Host Communication including VMHA, and Host to Vcenter communication
- Vmtion traffic
- Storage traffic


Having 2 x10GB physical Nics,  will this allow us to separate traffic for security and performance purposes? if so , please explain how to separate traffic and which traffic should never go the same way with other traffic?

I have also heard of system traffic and user traffic.
if I understand System traffic is the same traffic I indicated above, however user traffic is the way workstations get into the VMs, the only way I know is through the Network switch that connects to the SAN….I could be wrong. Please explain




Thanks
0
Comment
Question by:jskfan
  • 5
  • 4
9 Comments
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39966803
You will need to separate using VLANs, so create a trunk network using your two 2 x10GB physical Nics, and then have different VLANs for vMotion, Management Network, and Virtual Machines.

But you will need a switch capable of VLANs.

User Traffic is known as Virtual Machine Network Traffic.

System Traffic - Management Network, vMotion, iSCSI storage

Have a look here

Pages 13 - 73 Discuss Networking in Detail, iuncluding trunks, VLANs, switches, and load balancing

ESXi Configuration Guide ESXi 4.1

http://www.vmware.com/pdf/vsphere4/r41/vsp_41_esxi_server_config.pdf

Virtual Networking

http://www.vmware.com/technical-resources/virtual-networking/virtual-networks.html

Virtual Networking Concepts

http://www.vmware.com/files/pdf/virtual_networking_concepts.pdf

http://en.wikipedia.org/wiki/Virtual_LAN

http://en.wikipedia.org/wiki/IEEE_802.1Q
Sample configuration of virtual switch VLAN tagging (VST Mode)

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004074

http://blog.scottlowe.org/2006/04/17/vlans-and-port-groups/

How to Setup VLANs

http://www.vladan.fr/great-kb-on-how-to-configure-vlans-on-vswitches-pswitches-and-vms/

VMware ESX Server 3: 802.1Q VLAN Solutions

http://www.vmware.com/pdf/esx3_vlan_wp.pdf

http://kb.vmware.com/kb/1004127

http://kb.vmware.com/kb/1004074

http://kb.vmware.com/kb/1004252
0
 

Author Comment

by:jskfan
ID: 39966833
I see…
So, for instance , I can create vmkernel for vmtion and another vmkernel for VMHA and assign them to the same physical NIC (10GB), but to 2 different Vlans ...
0
 
LVL 119
ID: 39966839
That's correct, but you will have to ensure you configure and build you network design correctly.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Author Comment

by:jskfan
ID: 39966841
<<User Traffic is known as Virtual Machine Network Traffic.>>

is it how VMs talk to each other
OR how ESX hosts talk to VMs and vice-versa
OR how physical workstations in the office talk to VMs and back
???
0
 
LVL 119
ID: 39966843
All of the above, is correct, via Virtual Machine network.
0
 

Author Comment

by:jskfan
ID: 39967010
<<which traffic should never go the same way with other traffic?>>
if we consider the following types of traffic:
- Management Network : Host to Host Communication including VMHA, and Host to Vcenter communication
-VM Network
- Vmotion traffic
- Storage traffic
0
 

Author Comment

by:jskfan
ID: 39967024
I also am not sure if the communication between Vcenter and VMs is part  VM Network or Management Network
0
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 39967100
It's Best Practice and Recommended, to make sure the following traffic is isolated if possible.

But you DO NOT need to follow these recommendations, it's up to your network design and implementation.

Management Network

VM Network

Vmotion traffic

Storage traffic

Management and VM Network traffic could be on the same network, or you could have a special Management Network for all devices.

vCenter Traffic, is part of VM Network, which could also be Management Network.,

e.g. vCenter Server needs to commnicate with ESXi on the Management Network.

But your management network could also be your Server Network (VM Network)
0
 

Author Closing Comment

by:jskfan
ID: 39967201
Thank you!
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I will show you HOW TO: Perform a Physical to Virtual (P2V) Conversion the easy way from a computer backup (image).
Giving access to ESXi shell console is always an issue for IT departments to other Teams, or Projects. We need to find a way so that teams can use ESXTOP for their POCs, or tests without giving them the access to ESXi host shell console with a root …
Teach the user how to delpoy the vCenter Server Appliance and how to configure its network settings Deploy OVF: Open VM console and configure networking:
This video shows you how to use a vSphere client to connect to your ESX host as the root user. Demonstrates the basic connection of bypassing certification set up. Demonstrates how to access the traditional view to begin managing your virtual mac…

791 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question