VMware Cloud Community
stanj
Enthusiast
Enthusiast

Can vCenter Server and ESX be set up on different networks?

Our environment has recently changed in that we have relocated our virtual infrastructure to a new location.

We will be configuring vCenter Server 4.0 in a domain that we are not domain administrators.

The reason for connecting to this domain is it is the only way we can get access to our virtual infrastructure via a VPN connection.

We may be able to be assigned as an administrator, but that is not clear.

I was wondering if there is a way to have the below virtual configuration configured that would allow access to the infrastructure.

Note that we have a vSphere 4 Standard license.

VCenter Server 4.0 installed in a domain on 128.244.x.x.

The ESX 4.0 Servers are configured in a different network with the ip addresses of – 192.168.x.x.

Some of the VMs are in a 10.10.x.x network with their own VM as a domain.

In order to connect externally to the virtual infrastructure, we must use a VPN connection to 128.244.

We do have routers that are in place but I am not sure of the configuration – NAT, VLAN, etc.

Basically, we need to connect to vCenter via VPN and access the VMs that currently are on ESX Servers at 192.168.x.x.

An option may be to reconfigure the ESX Servers and put them on 128.244.x.x. but we would like to have them kept on our 192.168.x.x if possible.

Any ideas on this?

Anyone running vCenter on a separate network then the ESX Servers?

Thanks

Reply
0 Kudos
10 Replies
athlon_crazy
Virtuoso
Virtuoso

As long you use the gateway which can do routing between 128.xx.xx.xx and 192.xx.xx.xx network, I dont see why your vCenter cannot communicate with your ESX. To manage it from insecure network, just proceed with the VPN.

vcbMC-1.0.6 Beta

vcbMC-1.0.7 Lite

http://www.no-x.org
Reply
0 Kudos
Rajeev_S
Expert
Expert

Hi,

We do run VC and ESX in different subnets. Ensure you have the neccessary ports opened. Below are the list of ports for all vmware products

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=101238...

Hope this helps!

Reply
0 Kudos
stanj
Enthusiast
Enthusiast

thanks

Is the configuration for the subnet accomplished at the VMware level (network configuration / vSwitch) or at the router level?

Again, since I am not on the network side of the house, can anyone provide an example or possibly a screen shot of the config withing vCenter / router?

thanks

Reply
0 Kudos
Rajeev_S
Expert
Expert

- It should be done in network/vSwitch level.

- The Core switch port where the ESX is connected should be configured as trunk with the allowed vlan's ( In my case vlan 90, 53 & 40. I've erased the names off).

- on the vSwtich create virtual machine portgroups with individual vlan ID. Place the VM in it.

- I cant get you any snap on the switch/router.

Award points if useful!

stanj
Enthusiast
Enthusiast

thanks for this info..

I will forwad this to our network engineers

I assume that if we VPN into 128, we can access the VMs?

Reply
0 Kudos
stanj
Enthusiast
Enthusiast

attached is a high level design a few of the network engineers came up with..

can the seperate VLANS work in this set up or do we reconfigure?

thanks

Reply
0 Kudos
Rajeev_S
Expert
Expert

Hi,

Design looks good. Ensure you got all the required ports opened.

Reply
0 Kudos
stanj
Enthusiast
Enthusiast

ok thanks

I will see what the network folks and security say.

Can the Distribued Virtual Switch be used in this set up?

If so, what would be the best setup and use?

Reply
0 Kudos
stanj
Enthusiast
Enthusiast

also,

how does the drawing I posted fit in with your original post for using separate VLANs?

thanks

Reply
0 Kudos
Rajeev_S
Expert
Expert

Hi,

I got VC, vmotion interface, VM's and my VI client are in differnent DMZ. All traffic will cross the firewall.

Hope this helps!

Reply
0 Kudos