Solved

Disadvantage of having VMware hosts and guests on same Subnet (vLAN)

Posted on 2014-10-28
3
293 Views
Last Modified: 2014-10-28
What are the disadvantage(s) of having VMware hosts and guests (VMs) on the same vLAN?

(I had them on different vLANs but then there were communication issues between vCenter VM and the hosts, probably due to some UDP port.) Thanks.

AK
0
Comment
Question by:Akulsh
  • 2
3 Comments
 
LVL 117

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE)
Andrew Hancock (VMware vExpert / EE MVE) earned 500 total points
ID: 40409431
You could suffer security attacks, if your hosts are exposed to your guest network. In the same way if your Management Network for your physical switches was also on the same vLAN as your guests.

A completely seperate vLAN for management, reduces the security risk to recent OpenSSL Heartbleed and Shellshock payloads.

If you had Servers and Guest on different vLANs, you would need to route, or have Inter vLAN routing between Hosts and Guests, for them to communicate.
0
 
LVL 3

Author Comment

by:Akulsh
ID: 40409454
Andrew,

The inter-vLAN routing was supposedly in place but heartbeat (UDP on 902 port) was often missed. (I did use VMKB# 1002719.)

About security, since vCenter server itself is normally on a VM and it manages the hosts, can't attack on VM subnet reach the hosts' subnet thru vCenter? Thanks.

AK
0
 
LVL 117

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE) earned 500 total points
ID: 40409509
Yes, if vCenter Server was compromised, it could attack hosts.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
VM or Imaging options for a computer 4 69
Vsphere NIOC - Configuration 4 39
Virtual Box issue 6 52
Microsoft Lync 2013 4 42
It Is not possible to enable LLDP in vSwitch(at least is not supported by VMware), so in this article we will enable this, and also go trough how to enabled CDP and how to get this information in vSwitches and also in vDS.
In this article, I show you step by step with screenshots to assist you - HOW TO: Deploy and Install the VMware vCenter Server Appliance 6.5 (VCSA 6.5), with some helpful tips along the way.
Teach the user how to install ESXi 5.5 and configure the management network System Requirements: ESXi Installation:  Management Network Configuration: Management Network Testing:
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now