In my design for a ESXi 3.5 on HP blades I have defined 2 pNICs for Management network and 2 pNICs for VMotion. These go to separate Cisco 3120 blade switches. Now I have stipulated an external switch stack to join switches up for VMotion. The management network switches then go to another management stack. Th customer wants to reduce costs by sharing the external stack for Management and Vmotion traffic and segregating via VLANs and making the VMotion VLAN non-routable. Are there any downfalls for this?
Bear in mind this is a secure environment. Iw as always told that VLANing should not be used as a security separation due to the possibility of VLAN hopping. What are the risks here? Bear in mind that this is a sensitive defence-biased network, so I'm attempting to segregate the networks as much as possible.
Your thoughts are welcome
Bear in mind this is a secure environment. Iw as always told that VLANing should not be used as a security separation due to the possibility of VLAN hopping. What are the risks here? Bear in mind that this is a sensitive defence-biased network, so I'm attempting to segregate the networks as much as possible.
Your thoughts are welcome