Vmware Machines in a DMZ

jskfan
jskfan used Ask the Experts™
on
I would like to know if I need to put some VM machines in a DMZ (between 2 physical firewall appliances), then do I need to put a physical ESX server in the DMZ , or there is another way  to do that ?

Thank you
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Seth SimmonsSr. Systems Administrator
Commented:
one place where i was recently, we had the dmz vlan accessible from the esx host and whatever guests we were putting there, just selected the adapter for that vlan
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017
Commented:
I would never put a ESXi Host Management Network on a DMZ.

But ESXi hosts can Host VMs, in a DMZ, with correct networking.

Author

Commented:
Just run the Cat5/6 cable to the switch in DMZ on one end and the Nic of ESX server on the other end ?
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
Correct, make sure it's a different vSwitch with different Virtual Machine Portgroup and label DMZ

Author

Commented:
If My ESX host has 2 or more physical Nics, can I plug one of them to the switch in DMZ and leave others plugged to the switch inside the Network ?
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017
Commented:
Yes, but then, you have instroduced a single point of failure, with only a nic per vSwitch, you should have at least two!

Author

Commented:
so what do you suggest if I need to have VMs in the DMZ ?

an ESX host with 4 Nics?

Author

Commented:
I meant an ESX server with 2 Nics inside the network and 2 Nics in the DMZ ?
VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017
Commented:
Well you can have a ESXi host with two nics, since vSwitch, and VLANs.

if you do not use VLANs, then ESXI host with four nics, two nics per vSwitch.

Author

Commented:
Thank you

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial