How Can I Segment My Lan Using VMWare Standard Switches


I would like to be able to segment my flat LAN network into multiple segments mostly for security reasons. My current setup has two VMware 5.5 hosts connected to a couple managed Cisco switches. My goal is to be able to segment my VM's onto different networks. My license is Vmware Standard (which precludes the use of the Cisco 1000v).

Are there any solutions out there (perhaps a virtual router) that can let me do this? Or can I do this using the standard vSwitch technology included in Vmware?
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
You could do this with vLANS, e.g. create two vLANS, and then present a trunk to a single vSwitch, and then use two VLANS and tags.

or create two vSwitches, different physical networks connected to different vSwitches, with different virtual machine network portgroups.

That's the network's created, but to route between the networks, you will need a virtual router.

Which could be Freesco or Monowall.
Bryant SchaperCommented:
just beware, you need a layer 3 or router to do intervlan routing, which also means all traffic has to go out the physical unless you do that in a virtual router
spinoza156Author Commented:
Thanks Andrew.

Going with the first option I have created my switch with two port groups. How would the virtual router look in this simple scenario?
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

spinoza156Author Commented:
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
The virtual router, will have to have two nics, connected to Network Test1 and Test2.

using different IP Addresses, it will route traffic between the networks, no need to use VLAN Tags.
spinoza156Author Commented:
Thank you for the clarification.
Network isolation is paramount as I will be cloning my production network into the test networks. Is this achievable using the above configuration AND never connecting the physical adapter?
Andrew Hancock (VMware vExpert / EE MVE^2)VMware and Virtualization ConsultantCommented:
You don't even need the router.

Just create a vSwitch with no physical uplinks, label the virtual machine portgroup Test Network.

Create a vSwitch connected to physical uplinks, with a virtual machine portgroup Production Network.

CLONE the VM, call it VM-B, change the virtual machine network in Network under VM Settings to Test Network

and your done.

All VMs on the Test Network will be able to communicate in isolation, and never reach Production Network, via the isolated vSwitch1.

Production Network is on vSwitch0.

No traffic can pass between vSwitch0 and vSwitch1 - isolated.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
spinoza156Author Commented:
This is the most elegant solution. The information regarding virtual routing was also very helpful.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.