Solved

Disadvantage of having VMware hosts and guests on same Subnet (vLAN)

Posted on 2014-10-28
3
309 Views
Last Modified: 2014-10-28
What are the disadvantage(s) of having VMware hosts and guests (VMs) on the same vLAN?

(I had them on different vLANs but then there were communication issues between vCenter VM and the hosts, probably due to some UDP port.) Thanks.

AK
0
Comment
Question by:Akulsh
  • 2
3 Comments
 
LVL 119

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 40409431
You could suffer security attacks, if your hosts are exposed to your guest network. In the same way if your Management Network for your physical switches was also on the same vLAN as your guests.

A completely seperate vLAN for management, reduces the security risk to recent OpenSSL Heartbleed and Shellshock payloads.

If you had Servers and Guest on different vLANs, you would need to route, or have Inter vLAN routing between Hosts and Guests, for them to communicate.
0
 
LVL 3

Author Comment

by:Akulsh
ID: 40409454
Andrew,

The inter-vLAN routing was supposedly in place but heartbeat (UDP on 902 port) was often missed. (I did use VMKB# 1002719.)

About security, since vCenter server itself is normally on a VM and it manages the hosts, can't attack on VM subnet reach the hosts' subnet thru vCenter? Thanks.

AK
0
 
LVL 119

Accepted Solution

by:
Andrew Hancock (VMware vExpert / EE MVE^2) earned 500 total points
ID: 40409509
Yes, if vCenter Server was compromised, it could attack hosts.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
This article will show you how to create an ISO CD-ROM/DVD-ROM image (*.iso), and MD5 checksum signature, for use with VMware vSphere Hypervisor 6.5 (ESXi 6.5). It's a good idea to compare checksums, because many installations fail because of a corr…
Teach the user how to join ESXi hosts to Active Directory domains Open vSphere Client: Join ESXi host to AD domain: Verify ESXi computer account in AD: Configure permissions for domain user in ESXi: Test domain user login to ESXi host:
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question