VMware Cloud Community
scrivnet78
Contributor
Contributor

NAT and ESXi

Hello,

This is my first experience with Esxi after working with Workstation for so long. I noticed that there is a large difference between the virtual switch in both products. I need some guidance on how to achieve the following.

Our ESXi server has 1 nic with a subnet of  192.168.0.0. I really need to create another subnet of 192.168.42.0 to isolate domain controllers for testing. I see no way to NAT or create a secondary virtual switch. Do I need to have a physical NIC for each virt switch or is there another way this can be achieved?

0 Kudos
4 Replies
a_p_
Leadership
Leadership

Welcome to the Community,

ESXi does not offer NAT. If you want to have a functionality equal to this, you can create a second vSwitch (without any uplinks) which you are going to use for the separate domain. Then install a Router VM with two virtual NICs, one attached to the test network and one to the production network.

André

0 Kudos
Josh26
Virtuoso
Virtuoso

Think of VMware's networking as offering a "virtual switch" (as the name implies) rather than a virtual router/firewall, which you appear to require.

0 Kudos
DSTAVERT
Immortal
Immortal

This may help

http://www.vmware.com/technical-resources/virtual-networking/

-- David -- VMware Communities Moderator
0 Kudos
scrivnet78
Contributor
Contributor

I installed Vyatta and set eth0 to my 192.68.0.254/24 and can ping it from the native network.
I set the second interface to 192.168.42.254 and can ping that from the second network.

It's the NAT rule that's tripping me up now. Just so I understand,

I now have a virtual network setup with two swiches. The first switch, eth0 is connected to my physical network directly. The second switch which has no physical NIC is eth1.

I have virtual machines on both segments. From the 192.168.0.0 I can ping IP resources on 192.168.42.0 and vice versa. If I want to get internet flowing to the .42 segment I belive I have to use NAT, is that correct? Do I also need a static route?

0 Kudos