VMware Cloud Community
TryllZ
Expert
Expert

Network Segmentation with VLANs, VMware Best Practices and Recommendations?!

Hi,

Is there a best practices/recommendations from VMware regarding network segmentation with VLANS.

Thank You

0 Kudos
4 Replies
TryllZ
Expert
Expert

I found this document which states to segregate networks for Traffic and Secutiry, which I understood.

What I did not understand is that on page 68 there is a VLAN segmentation which shows all the VLANs, but also shows 2 uplinks (uplink01 and uplink02) in their own VLANs, which does not make sense to me, and is not explained in the PDF either.

Could someone kindly explain.

Thank You

0 Kudos
Tibmeister
Expert
Expert

I remember that document in regards to micro-segmentation, what memories it brings back.

I'm not sure what you are after.  VMware recommends following the industry best practices and your physical switch vendors best practices.

Generally, you will take one or more physical interfaces, add them to a vSwitch on a host or hosts, then create a portgroup for each VLAN.  The physical interfaces will have to be trunk ports, and wither or not to use a native VLAN is up to you, but I generally don't like to do that because the management console can use VLAN tagging so no need to allow untagged traffic at all.

Now, this is just a general suggestion, only add the VLANs to the physical interface trunk that you will actually use.  You can add all VLANs, but every VLAN is a L2 segment, and every L2 segment your host sees from the physical interface, wither you have a portgroup or not, will receive the broadcast traffic of that L2 segment.  So by adding all VLANs, and if you have a lot, and only need a few, you can flood the hosts interfaces with unnecessary broadcast traffic.

0 Kudos
Tibmeister
Expert
Expert

Both are very solid examples.

0 Kudos