Solved

Disadvantage of having VMware hosts and guests on same Subnet (vLAN)

Posted on 2014-10-28
3
305 Views
Last Modified: 2014-10-28
What are the disadvantage(s) of having VMware hosts and guests (VMs) on the same vLAN?

(I had them on different vLANs but then there were communication issues between vCenter VM and the hosts, probably due to some UDP port.) Thanks.

AK
0
Comment
Question by:Akulsh
  • 2
3 Comments
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 40409431
You could suffer security attacks, if your hosts are exposed to your guest network. In the same way if your Management Network for your physical switches was also on the same vLAN as your guests.

A completely seperate vLAN for management, reduces the security risk to recent OpenSSL Heartbleed and Shellshock payloads.

If you had Servers and Guest on different vLANs, you would need to route, or have Inter vLAN routing between Hosts and Guests, for them to communicate.
0
 
LVL 3

Author Comment

by:Akulsh
ID: 40409454
Andrew,

The inter-vLAN routing was supposedly in place but heartbeat (UDP on 902 port) was often missed. (I did use VMKB# 1002719.)

About security, since vCenter server itself is normally on a VM and it manages the hosts, can't attack on VM subnet reach the hosts' subnet thru vCenter? Thanks.

AK
0
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 40409509
Yes, if vCenter Server was compromised, it could attack hosts.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Veeam Backup & Replication has added a new integration – Veeam Backup for Microsoft Office 365.  In this blog, we will discuss how you can benefit from Office 365 email backup with the Veeam’s new product and try to shed some light on the needs and …
Teach the user how to configure vSphere Replication and how to protect and recover VMs Open vSphere Web Client: Verify vsphere Replication is enabled: Enable vSphere Replication for a virtual machine: Verify replicated VM is created: Recover replica…
Teach the user how to use create log bundles for vCenter Server or ESXi hosts Open vSphere Web Client: Generate vCenter Server and ESXi host log bundle:  Open vCenter Server Appliance Web Management interface and generate log bundle: Open vCenter Se…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question