[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

best practice for vswitches in VMWARE

Posted on 2014-08-26
29
Medium Priority
?
318 Views
Last Modified: 2014-08-28
Hi Experts,

I have just one vswitch configured yet , the VM Network is running over it, the VMOTION and MANAGEMENT.
And I just have one NIC for this vSwitch0.


When I remeber, I think I had an extra vSwitch for VMOTION and MANAGEMENT.
But I am not sure.

What do you think, and what is recommended ?
Can you give me some hints here ?
0
Comment
Question by:Eprs_Admin
  • 19
  • 10
29 Comments
 
LVL 124
ID: 40285472
It's Best Practice and Recommended to ISOLATE ALL traffic e.g.

Management
vMotion
Virtual Machines
Storage (iSCSI and NFS).

So that's a vSwitch per each, in an ideal world, with at least two physical nic uplinks per vSwitch.

If you are short on physical nics, VLANs can help, and if you have 10GBe nics, then two 10GBe nics per vSwitch and use of VLANs

example
0
 

Author Comment

by:Eprs_Admin
ID: 40285490
ok I see,
Which one is your vmotion network ?
0
 
LVL 124
ID: 40285506
vMotion can only operate on a VMKernel......

so the one labelled VMKernel, vMotion is a TCP/IP network function, so it MUST have an IP Address to be able to communicate with other ESXi hosts.
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 

Author Comment

by:Eprs_Admin
ID: 40285535
ok I see,
on my end my vm network and the management is on one vswitch.
How to seperate it ? I cannot delete the management network on it.
0
 
LVL 124
ID: 40285541
How many physical nics, do you have to spare?

create a new virtual switch, with a virtual machine network.
0
 

Author Comment

by:Eprs_Admin
ID: 40285544
I have 12 nics for all and 2 10G nics for my storage
0
 

Author Comment

by:Eprs_Admin
ID: 40285547
The uplinks must be trunks right ?
The management and Data links ?
0
 
LVL 124

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40285609
The uplinks do not have to be trunks....

but for teaming and resilience purposes, ESXi Teaming policy only controls OUTBOUND traffic, inbound traffic is configured on your physical switches......

so, if you require resilience, and throughput STATIC TRUNKS are best! (LACP is not supported).

Okay, so lets exclude the 10GBe for storage only!

This leaves 12 nics.....

do you use VLANs ?

without VLANs, you could configure...

2 x NICs - Management (trunk)
2 x NICs - vMotion
4 x NICs - Virtual Machines (trunk)
0
 

Author Comment

by:Eprs_Admin
ID: 40285631
I have no vlans.

ok this is a good plan.
when you say 4x NICS for Virtual Machines in a trunk, do I have then 4x 1Gbps , so 4Gbps ?
And the trunk I have to create on the physical switch right ?
I have ESXi 5.5, can I use LACP with it ?
0
 

Author Comment

by:Eprs_Admin
ID: 40285929
Now I have setup a new vswitch for vmotion but it is not working.
Maybe the HP switch port settings are wrong ?
0
 
LVL 124
ID: 40285943
make sure, that each server, can ping each other's vMotion interface IP Address.
0
 

Author Comment

by:Eprs_Admin
ID: 40286194
ok let me check this later
0
 

Author Comment

by:Eprs_Admin
ID: 40287288
Ok now I decided to put the vmotion network also on the 10G nics together with the Storage vswitch.
0
 

Author Comment

by:Eprs_Admin
ID: 40287294
Hi Andrew,

regarding this solution from you:
2 x NICs - Management (trunk)
2 x NICs - vMotion
4 x NICs - Virtual Machines (trunk)

How to setup the nics as trunks ?
In vcenter I add the nics and put them all to active.
But on the HP side what do I have to configure ? Which trunks ? LACP ?
0
 
LVL 124

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40287401
You must configure Static Trunks on the physical switch, and set Teaming to IP HASH. (on ESXI)

LACP is not supported.
0
 

Author Comment

by:Eprs_Admin
ID: 40287509
ok now I have configured the redundant nics for Management and VM´s.
But on the HP switch it is yet not configured.
I made a test and disconnected vmnic0 and I was able to connect to the host.
So this works also without having trunks.

Can you show me how to configure the trunks on the HP side ?
0
 

Author Comment

by:Eprs_Admin
ID: 40287514
now my setup is like this:
See the picture.

host1 networking
Is it ok to put the vmotion network on the 10G storage network, because it is faster ?
0
 

Author Comment

by:Eprs_Admin
ID: 40287517
On this host, see the picture before,I still have a warning that no redundancy is given on the management network. But when you see the picture before I have added 2 nics, vmnic 0 and 4.
What else can be the problem here ?

no redundancy
0
 
LVL 124

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40287596
Yes, you could add a VMKernel to vSwitch with the 10Gbe for vMotion.

It's possible that the nics cannot reach the default gateway.

What physical switch do you have ?
0
 

Author Comment

by:Eprs_Admin
ID: 40287708
I have a HP Procurve 4208vl J8773a
0
 
LVL 124

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40287723
with a HP switch

To configure a static portchannel in an HP switch using ports 1, 2, 3, and 4, run this command:

conf
trunk 1-4 Trk1 Trunk

or do you use a GUI ?
0
 

Author Comment

by:Eprs_Admin
ID: 40287776
I have both, do have also the solution for the GUI ?
0
 

Author Comment

by:Eprs_Admin
ID: 40287791
...and why I cannot use LACP, because my switch can use it.
0
 
LVL 124

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40287793
I don't use a GUI.

But you would start the GUI, find the two ports you need to trunk and select trunk, to add them to the same trunk number.

..and why I cannot use LACP, because my switch can use it.

Because ITS NOT SUPPORTED! on Standard vSwitches, only on Distributed Switches, in Enterprise PLus version.

see here

http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=1004048
0
 

Author Comment

by:Eprs_Admin
ID: 40289678
Great article and the configuration works fine.
Just two small things left.

One vmnic of a trunk just has 100Mbit FULL DUPLEX, all other have 1000Mbit FULL DUPLEX.
See the picture:

not 1000Mbit
From where it comes ?
On the HP switch I cannot change it because of the trunk or ?
0
 

Author Comment

by:Eprs_Admin
ID: 40289683
...and when I check my network adapters I see different networks observed.
See the picture:

observed networks
What does it mean, is it important ?
Why it sees different networks ?
0
 
LVL 124
ID: 40289747
It appears there must be a speed mismatch on the physical network port.

try reconnecting, or changing the cable.
0
 

Author Comment

by:Eprs_Admin
ID: 40289756
ok, and what about the different observed networks ?
From where it comes ?
0
 

Author Comment

by:Eprs_Admin
ID: 40290063
ok this will work great with the trunks and vswitches.
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question