Solved

USing Separate VLANs for each Traffic in Vmware

Posted on 2014-03-31
10
1,006 Views
Last Modified: 2014-04-04
If we decide to create separate VLANs for each traffic type in Vmware, would that really possible. Knowing that the most common Traffic types are:

- VM Network
- Management Network (host to host communication and host to Vcenter) including Management Traffic Host VMHA

-Vmotion traffic
- ISCSi storage Traffic.

If my ESX hosts are in Vlan 10, then if I put each traffic type in separate VLAN how can that be fast if they are in different VLANs than ESX Hosts…knowing that pretty much every traffic involve ESX hosts.

I believe the purpose of Traffic type separation into different VLANs , is performance in addition to security (as claimed to be)

Any help will be very much appreciated.

Thank you
0
Comment
Question by:jskfan
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 12

Assisted Solution

by:Vaseem Mohammed
Vaseem Mohammed earned 100 total points
ID: 39968459
As per my knowledge I feel that Separation of traffic on vLANs will help in security and not performance if there is only a single uplink to host (single NIC or Single Team).
coz at the end the traffic is using the same pipe to come inside host. vLAN is a logical separation.
If we have go multiple path, for e.g., vMotion has separate NICs on different vLAN and Seperate NICs for VMNetwork on another vLAN, then there should be performance improvement along with security.

If ESX hosts are on vLAN 10, that means your "Management Network" is on vLAN 10 and you have single point of entry to Hosts, then I don't think you will find any improvement, and of course the UpLink will be a configured as Trunk on Switch as you will be using separate vLAN for other traffic.
0
 

Author Comment

by:jskfan
ID: 39968470
For Vmotion and iSCI storage traffic, if they are in different VLANs than ESX hosts, so they still have to talk to the Default Gateway (Router) each time they want to communicate with ESX Hosts.

I believe it is the same case for VM Network
0
 
LVL 118

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE)
Andrew Hancock (VMware vExpert / EE MVE) earned 300 total points
ID: 39968610
You should have completely different storage network (isolated) and vMotion network (isolated).

they do not have to reach the default gateway, and should not be able to reach the default gateway.

Think of the networks, as two completely different networks, with different IP Address Subnets.
0
 

Author Comment

by:jskfan
ID: 39969404
I am familiar with the Network Area…

If I am not wrong with physical switches L3 you can make make computers talk to each other without going through the router.

in Vmware :
You have one or many Virtual  Standard switches (we are not talking vDS yet..to keep it simple)…
The Virtual Switch is Connected to Physial NICs (Vmnics)…Those Vmnics are the Trunk to the physical Switch (Network Switch or Storage Switch)

on Virtual Switch, you can create Vlans, but those Vlans need to have ports created and and assigned to the same Vlans on the physical switch Layer 3… this layer 3 physical switch is the one that routes between Vlans , because the Virtual Switch to my knowledge does not have the capability of routing.

Now that each Traffic is separated either by Vlans or by adding physical Nics and Vmkernel ports assigned to physical Nics, it still has to reach the L3 switch in order to be routed to another Vlan…. I believe though Adding physical Nics and Vmkernels and leaving all traffic in the same Vlan, will at least be able to avoid the routing process at the L3 physical switch, which means better performance.

That's pretty much my overall picture about how traffic move around in the Vmware Network.

Though Actually the physical Storage Switch, I am not sure if it works like the Physical Network Switch L3 I indicated.
0
 
LVL 118

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE)
Andrew Hancock (VMware vExpert / EE MVE) earned 300 total points
ID: 39969441
Some Layer Three switches can provide routing between VLANs, or inter VLAN routing, if there is a need to provided routing between VLANs.

No routing between VLANs keeps traffic isolated and private.

VMware ESXi, just adds the VLAN 802.1Q TAG, the VLAN Tag is then picked up by the physical switch, which sends the traffic to the correct VLAN.

In this way traffic is "virtual isolated" just like different physical network cables and ports.
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 61

Assisted Solution

by:gheist
gheist earned 100 total points
ID: 39969899
According to vmware vlans offer logical separation, but does not solve traffic management problems.
0
 

Author Comment

by:jskfan
ID: 39972242
<<<According to vmware vlans offer logical separation, but does not solve traffic management problems.>>>

Maybe they mean, each traffic type ( Vmotion,VMHA,Management Network,VM Network) can travel on the same physical path, but in separated packets….. it is like shipping clothing,utensils,etc... through the same UPS cargo, but each item in separate box…
0
 
LVL 61

Expert Comment

by:gheist
ID: 39972274
No - it is more like pushing cartman and lenny through same door...
0
 
LVL 118

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE) earned 300 total points
ID: 39972286
It's common networking practice to isolate storage traffic for iSCSI, as to not affect a product network. (e.g. user network).
0
 

Author Closing Comment

by:jskfan
ID: 39978984
Thank you Guys
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this step by step tutorial with screenshots, we will show you HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 6.5 (ESXi 6.5). This is important if you need to enable SSH remote access for additional troubleshooting of the ESXi hos…
In this article, I will show you HOW TO: Suppress Configuration Issues and Warnings Alert displayed in Summary status for ESXi 6.5 after enabling SSH or ESXi Shell.
Teach the user how to use vSphere Update Manager to update the VMware Tools and virtual machine hardware version Open vSphere Client: Review manual processes for updating VMware Tools and virtual hardware versions: Create a new baseline group in vSp…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now