Solved

USing Separate VLANs for each Traffic in Vmware

Posted on 2014-03-31
10
1,034 Views
Last Modified: 2014-04-04
If we decide to create separate VLANs for each traffic type in Vmware, would that really possible. Knowing that the most common Traffic types are:

- VM Network
- Management Network (host to host communication and host to Vcenter) including Management Traffic Host VMHA

-Vmotion traffic
- ISCSi storage Traffic.

If my ESX hosts are in Vlan 10, then if I put each traffic type in separate VLAN how can that be fast if they are in different VLANs than ESX Hosts…knowing that pretty much every traffic involve ESX hosts.

I believe the purpose of Traffic type separation into different VLANs , is performance in addition to security (as claimed to be)

Any help will be very much appreciated.

Thank you
0
Comment
Question by:jskfan
  • 4
  • 3
  • 2
  • +1
10 Comments
 
LVL 12

Assisted Solution

by:Vaseem Mohammed
Vaseem Mohammed earned 100 total points
ID: 39968459
As per my knowledge I feel that Separation of traffic on vLANs will help in security and not performance if there is only a single uplink to host (single NIC or Single Team).
coz at the end the traffic is using the same pipe to come inside host. vLAN is a logical separation.
If we have go multiple path, for e.g., vMotion has separate NICs on different vLAN and Seperate NICs for VMNetwork on another vLAN, then there should be performance improvement along with security.

If ESX hosts are on vLAN 10, that means your "Management Network" is on vLAN 10 and you have single point of entry to Hosts, then I don't think you will find any improvement, and of course the UpLink will be a configured as Trunk on Switch as you will be using separate vLAN for other traffic.
0
 

Author Comment

by:jskfan
ID: 39968470
For Vmotion and iSCI storage traffic, if they are in different VLANs than ESX hosts, so they still have to talk to the Default Gateway (Router) each time they want to communicate with ESX Hosts.

I believe it is the same case for VM Network
0
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 300 total points
ID: 39968610
You should have completely different storage network (isolated) and vMotion network (isolated).

they do not have to reach the default gateway, and should not be able to reach the default gateway.

Think of the networks, as two completely different networks, with different IP Address Subnets.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:jskfan
ID: 39969404
I am familiar with the Network Area…

If I am not wrong with physical switches L3 you can make make computers talk to each other without going through the router.

in Vmware :
You have one or many Virtual  Standard switches (we are not talking vDS yet..to keep it simple)…
The Virtual Switch is Connected to Physial NICs (Vmnics)…Those Vmnics are the Trunk to the physical Switch (Network Switch or Storage Switch)

on Virtual Switch, you can create Vlans, but those Vlans need to have ports created and and assigned to the same Vlans on the physical switch Layer 3… this layer 3 physical switch is the one that routes between Vlans , because the Virtual Switch to my knowledge does not have the capability of routing.

Now that each Traffic is separated either by Vlans or by adding physical Nics and Vmkernel ports assigned to physical Nics, it still has to reach the L3 switch in order to be routed to another Vlan…. I believe though Adding physical Nics and Vmkernels and leaving all traffic in the same Vlan, will at least be able to avoid the routing process at the L3 physical switch, which means better performance.

That's pretty much my overall picture about how traffic move around in the Vmware Network.

Though Actually the physical Storage Switch, I am not sure if it works like the Physical Network Switch L3 I indicated.
0
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 300 total points
ID: 39969441
Some Layer Three switches can provide routing between VLANs, or inter VLAN routing, if there is a need to provided routing between VLANs.

No routing between VLANs keeps traffic isolated and private.

VMware ESXi, just adds the VLAN 802.1Q TAG, the VLAN Tag is then picked up by the physical switch, which sends the traffic to the correct VLAN.

In this way traffic is "virtual isolated" just like different physical network cables and ports.
0
 
LVL 62

Assisted Solution

by:gheist
gheist earned 100 total points
ID: 39969899
According to vmware vlans offer logical separation, but does not solve traffic management problems.
0
 

Author Comment

by:jskfan
ID: 39972242
<<<According to vmware vlans offer logical separation, but does not solve traffic management problems.>>>

Maybe they mean, each traffic type ( Vmotion,VMHA,Management Network,VM Network) can travel on the same physical path, but in separated packets….. it is like shipping clothing,utensils,etc... through the same UPS cargo, but each item in separate box…
0
 
LVL 62

Expert Comment

by:gheist
ID: 39972274
No - it is more like pushing cartman and lenny through same door...
0
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 300 total points
ID: 39972286
It's common networking practice to isolate storage traffic for iSCSI, as to not affect a product network. (e.g. user network).
0
 

Author Closing Comment

by:jskfan
ID: 39978984
Thank you Guys
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Last article we focus in how to VMware: How to create and use VMs TAGs – Part 1 so before follow this article and perform the next tasks, you should read the first article how to create the TAG before using them in Veeam Backup Jobs.
In this article, I show you step by step with screenshots to assist you - HOW TO: Deploy and Install the VMware vCenter Server Appliance 6.5 (VCSA 6.5), with some helpful tips along the way.
Teach the user how to rename, unmount, delete and upgrade VMFS datastores. Open vSphere Web Client: Rename VMFS and NFS datastores: Upgrade VMFS-3 volume to VMFS-5: Unmount VMFS datastore: Delete a VMFS datastore:
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question