?
Solved

Disadvantage of having VMware hosts and guests on same Subnet (vLAN)

Posted on 2014-10-28
3
Medium Priority
?
318 Views
Last Modified: 2014-10-28
What are the disadvantage(s) of having VMware hosts and guests (VMs) on the same vLAN?

(I had them on different vLANs but then there were communication issues between vCenter VM and the hosts, probably due to some UDP port.) Thanks.

AK
0
Comment
Question by:Akulsh
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 122

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40409431
You could suffer security attacks, if your hosts are exposed to your guest network. In the same way if your Management Network for your physical switches was also on the same vLAN as your guests.

A completely seperate vLAN for management, reduces the security risk to recent OpenSSL Heartbleed and Shellshock payloads.

If you had Servers and Guest on different vLANs, you would need to route, or have Inter vLAN routing between Hosts and Guests, for them to communicate.
0
 
LVL 3

Author Comment

by:Akulsh
ID: 40409454
Andrew,

The inter-vLAN routing was supposedly in place but heartbeat (UDP on 902 port) was often missed. (I did use VMKB# 1002719.)

About security, since vCenter server itself is normally on a VM and it manages the hosts, can't attack on VM subnet reach the hosts' subnet thru vCenter? Thanks.

AK
0
 
LVL 122

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 2000 total points
ID: 40409509
Yes, if vCenter Server was compromised, it could attack hosts.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Will try to explain how to use the VMware feature TAGs in the VMs and create Veeam Backup Jobs using TAGs. Since this article is too long, I will create second article for the Veeam tasks.
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
Teach the user how to edit .vmx files to add advanced configuration options Open vSphere Web Client: Edit Settings for a VM: Choose VM Options -> Advanced: Add Configuration Parameters:
Advanced tutorial on how to run the esxtop command to capture a batch file in csv format in order to export the file and use it for performance analysis. He demonstrates how to download the file using a vSphere web client (or vSphere client) and exp…
Suggested Courses

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question