VMware Cloud Community
StoneEdge
Contributor
Contributor

free ESXi DMZ for WebServer and eMail Server

Hi

I need to build a free ESXi for some webserver and one eMail Server(maybe Exchange)

My question  and doubts is first, is there any problem using free ESXi to build this? I think not, but need to clarify this.

Second I like to put a ISA Server on that DMZ for protection and also to publish the webserver and mailserver(like OWA if needed). Because I don’t have any physical firewall.

Is this OK?

I will use one nic connected to the router. Create a vSwitch that is connected to the ISA Firewall. In the ISA I will use 2 nics(one for the DMZ vSwitch and the other for the vSwitch internal LAN)

What is the best way to implement this?

Thank You

0 Kudos
5 Replies
jamesbowling
VMware Employee
VMware Employee

There is nothing wrong with using VMware Hypervisor to build this out.  You idea for design is good minus the redundancy.  You may want to think about configuring a few pNICs for your connection for redundancy sake.  Other than that, it seems that your idea will work just fine.

James B. | Blog: http://www.vSential.com | Twitter: @vSential --- If you found this helpful then please awards helpful or correct points accordingly. Thanks!
0 Kudos
dquintana
Virtuoso
Virtuoso

Good, Esxi works fine for that proposes.

I recommend you to create two vswitches, one for LAN and other for DMZ, in each place the adequate nics cards to each physical switch

The isa should have 2 nics like you say, place your exchange in the lan vSwitch, dont forget to protect your exchange with a relay server too.

Diego

Ing. Diego Quintana - VMware Communities Moderator - Co Founder & CEO at Wetcom Group - vEXPERT From 2010 to 2020- VCP, VSP, VTSP, VAC - Twitter: @daquintana - Blog: http://www.wetcom.com-blog & http://www.diegoquintana.net - Enjoy the vmware communities !!!

0 Kudos
StoneEdge
Contributor
Contributor

Hi  My question and doubts about ESXi is that this a free edition, not a license version. I will not use HA, DRS or vMotion, so I think is ok, but need a second opinion on this.

Regarding my DMZ and connections.  This ESXi will have 4 or 5 VMs and one VM that is the ISA Server. And the host will have 8 pNICs ports(2 quad port PCIe Adapter).

This is what I think needs to be done.

I will create one vSwitch(lets named Internet) and add 1/2 pNICs into this vSwitch and connect into the router.  Then in the ISA VM I will add one virtual adapter into this vSwitch that I will use as the External.

Until here I think is ok, next step is my doubts.

I will have a VM Webserver that will receive the connections and will be publish to Internet from the ISA Server.  Do I need to create another vSwitch call DMZ and put this sever on it, and also create another adapter on the ISA VM and connect into this vSwitch?

And with this I can add all the Servers that I need to put in the DMZ? If yes, ok this is fix it.

Now I have my Internal LAN.  I will create another vSwitch call VM Network. In this vSwitch I will use all my internal VMs(DCs, Exchange, SQL, etc.). I think I need to create another Virtual Adapter in the ISA VM and connect into this vSwitch, that will be used as the Internal.

Question.

In this design, how can I connect the VM webserver into the SQL? Do I need to create another Virtual Adapter in the VM WebServer and connect into the vSwitch VM Network? Is this correct? Is this ok?

How can the Internal Network connect to this Server safely?

I know I can use VLAN(I do not know how to set, but I know that we can do this), but for VLANs do I need to have a physical Switch config with VLANs also?? On the ports where this NICs connect?

Or I can use the ESXi and the vSwitch to create this VLAN(internally) without have any Switch for this?

Sorry all the questions, but this is the part I still not understand.

Thank You

0 Kudos
idle-jam
Immortal
Immortal

if you need the VM to have traffic gone thru ISA before going to the internet then it would be

Local VM x 1vNIC (Local LAN) then ISA VM x 2 vNIC (Local LAN & DMZ). Request will go from Local LAN to Local LAN and then via DMZ to go to internet. this is provided your ISA is configure properly. you may need NAT setup i think it's called NAT in the ISA server. but this is more purely on the OS level.

0 Kudos
StoneEdge
Contributor
Contributor

Hi

Yes that is correct.

That is the normal configuration for a physical ISA implementation.

Since this a virtual environment I have some doubts. But the VM ISA, need 3 virtual adapters(one forLAN, one for DMZ, one for Internet)

I need to migrate this idea into virtual, using vSwitchs configuration.

Thank You

0 Kudos