VMware Cloud Community
Gonzouk
Enthusiast
Enthusiast

Add DMZ to EXS 4.1 hosts

Hello,

We have a Cisco firewall which has a 3 x DMZ/VLAN for our web servers and some other servers (see image).  We also have 2 hosts which have 2 spare Nic ports and I was wondering how I can add a VM guest server to those 3 different vlans?

1.) Can I create a vSwitch on each host and to connect to the Cisco switch?

2.) Will it need to be a trunk on the Cisco end to allow all 3 VLANs to be "seen" on the vSwitch port?

3.) Will I need to use MTU 9000

vmdmz.JPG

Thanks

0 Kudos
10 Replies
Virtugirl
Enthusiast
Enthusiast

Hey Gonzo,

Just had a look at the diagram.  Are the ESX hosts already operating with VM's on them or is this a new setup ?

0 Kudos
mittim12
Immortal
Immortal

1:   yes

2:  Yes if you set them to trunk and setup a portgroup on that particular vSwitch for each VLAN it should work.

3:  If you want to utilize jumbo frames  you would.  I only used jumbo frames on my storage networks and have never placed it on a vSwitch. for guest

I think when you start mixing internal production guest with dmz guest you have to be really careful.  If one person accidentally mis configures something you could end up with internal machines hooked up to a DMZ port. 

0 Kudos
Gonzouk
Enthusiast
Enthusiast

Hi,

They have lots of vm servers running on them. I'm currently adding 2 more hosts too.

Thanks

0 Kudos
Gonzouk
Enthusiast
Enthusiast

1.) Are there other ways to achieve this?

2.) If I'm only using one network cable from each host to the Cisco switch, do I need to create a port group?

3.) If it is a trunk I guess all 3 vlans will be seen on the vSwitch, how will I assign the VM guest servers to either of the 3 vlans?

Thanks

0 Kudos
mittim12
Immortal
Immortal

2:   The multipe portgroups will allow you to do vlan tagging at the vSwitch level.

3:  Assign a portgroup to a VM and they should have access to that particular VLAN.

Check out this KB for some more information on VLANs,  http://kb.vmware.com/kb/1004074

0 Kudos
Virtugirl
Enthusiast
Enthusiast

Reason I asked is that if you want to setup a true DMZ I wouldnt use the ESX virtual switch as a means to do that.  I would keep these hosts and hosted VM;s seperate to the rest of your estate as a previous poster has stated.  VLAN's and Virtual Switches are not a good security boundary.

0 Kudos
Gonzouk
Enthusiast
Enthusiast

Yeah it seems I need to create a virtual switch on each host and connect a network cable from each host to the physical Cisco DMZ switch and set it as a trunk to send the VLAN tags down to the hosts.

Does that sound about right to you?

0 Kudos
Virtugirl
Enthusiast
Enthusiast

yes it does.  Jst make sure you set the speed and duplex the same at both ends too.

0 Kudos
Gonzouk
Enthusiast
Enthusiast

If I have the 3 VLAN tags coming down to the vSwitch on each host fromt he physical Cisco switch how will I tell a VM host to only connect to a particular VLAN?  I will I need to create 3 vSwitches on each host?

0 Kudos
Virtugirl
Enthusiast
Enthusiast

When you create your Vswitch and attach your physical NICS which are attached to the cisco DMZ switch, you will create a port group for each VLAN that you want - so in your case 3.  Then when you build your VM you will select your network adapter and from the drop down list select which port group (VLAN) you want to assign to the VM.

0 Kudos