VMware Cloud Community
EdRoper
Contributor
Contributor

iSCSI, VMotion, DMZ's, and a limited amount of NIC's

Hopefully I can find a solution to this problem that doesn't involve buying more networking hardware, as we are already at the limits of our budget.

We have two ESXi hosts, a MD3000i iSCSI storage array, and another server to act as the virtual center console.

The two ESXi hosts have a total of 4 pNICS each.

What were planned to do was run the iSCSI traffic on teamed on 2 nics, on one VLAN on our gigabit switches ( 2 LAG'ed together ) , and Vmotion & VM Traffic across the other 2 Nics on a seperate VLAN.

But then we realized, we have no space for allowing DMZ traffic to some of our VM's.

What are our options to run iSCSI, Vmotion, VM / Internal traffic , and DMZ traffic on only 4 nics?

0 Kudos
2 Replies
SkyC
Enthusiast
Enthusiast

Your obviously going to have to trade off between redundancy and security, just need to find whatever is comfortable for you. If you haven't read it yet, google cisco vmware networking bestpractices, it shows you a few options for using 4 NIC's.

You might look at doing one big vSwitch with all 4 NICs as uplinks, then do your segmentation with port groups and VLANs, for each port group, set one active uplink, and the remaining 3 as standby, so you could have one dedicated for VM traffic, VMotion, iSCSI, DMZ, and then just double up your service console with one of the lighter utilized uplinks. This gives you under normal circumstances, dedicated uplink for specific types of traffic, but in the case of a physical failure with one of the uplinks, you can still function.

0 Kudos
AndreTheGiant
Immortal
Immortal

In your case your DMZ is on separate physical swithes? Or is simple a VLAN into the same physical switches of LAN?

With a small number of NICs the only solution is use different VLANs and use VLAN tagging into portgroup.

I will need at least these VLANs:

- intranet

- DMZ

- management (optional)

- Vmotion

- iSCSI1 AND iSCSI2 (Dell ESX Storage Deployment Guide)

Andre

**if you found this or any other answer useful please consider allocating points for helpful or correct answers

Andrew | http://about.me/amauro | http://vinfrastructure.it/ | @Andrea_Mauro
0 Kudos