VMware Cloud Community
Prost
Contributor
Contributor
Jump to solution

Dissimilar network segments

I am not sure if this is the right community

I am not sure this is going to work; I created a drone VM on each blade then created DRS rules for each VM that will not allow my drones and the VMs on Networks 4, 5&6 to be on the same host.

Will this work? Is there a better way?

0 Kudos
1 Solution

Accepted Solutions
rogard
Expert
Expert
Jump to solution

Behind a firewall or any layer 3+ device should not really affect your ability to trunk the vlan.

I would try very hard to try and get those vlans trunked so that you have a constant network layer across your ESX boxes.

As for multiple nics for your storage network, your storage network is (probably) your most important network if someone/something unplugs your vmnetwork nic you lose access to the virtual machine.

If someone unplugs you storage network, your machine will most probably BSOD/Dump and you may lose data.

(This is all assuming you are pushing iscsi datastores to your esx hosts)

View solution in original post

0 Kudos
7 Replies
rogard
Expert
Expert
Jump to solution

hmm bit concerned as you only have 1 nic for iscsi/storage traffic.

Here is what I suggest:

Blades:

VMnetwork (trunk carrying N1,N5,N6) + service console

2 pNics

Storage Network (vmotion etc)

2pNics

G6:

VMnetwork (trunk carrying N1,N5,N6)

4pNics

Storage Network:

4pNics

VMotion+FT:

2pnics

Management:

2pNics

You have a lot of network ports on the G6's perhaps you may want to drop one and use it for port mirroring/sniffing/monitoring?

0 Kudos
Prost
Contributor
Contributor
Jump to solution

Hello rogard,

Thanks for the help.

I noticed a mistake in my question though it looks like you figured it out but this line “Network 4 redundant connections to our DMZ segment.” Should be Network 6 redundant connections to our DMZ segment.”

So N4, N5, and N6 are all physically separate networks behind firewalls and I am unable to trunk these network segments.

You also said you were concerned about” only having 1 nic for iscsi/storage traffic” . Why? All I use this for is vMotion which doesn’t affect my VMs. Or does it?

port mirroring/sniffing/monitoring this is managed by our network team and they have there own physical boxes.

0 Kudos
rogard
Expert
Expert
Jump to solution

Behind a firewall or any layer 3+ device should not really affect your ability to trunk the vlan.

I would try very hard to try and get those vlans trunked so that you have a constant network layer across your ESX boxes.

As for multiple nics for your storage network, your storage network is (probably) your most important network if someone/something unplugs your vmnetwork nic you lose access to the virtual machine.

If someone unplugs you storage network, your machine will most probably BSOD/Dump and you may lose data.

(This is all assuming you are pushing iscsi datastores to your esx hosts)

0 Kudos
Prost
Contributor
Contributor
Jump to solution

These are 3 physically separate networks.

The option to Trunk is not available.

Storage is Fiber channel using redundant fabric on a EMC SAN.

No iSCSI is used.

N2 is vMotion only.

0 Kudos
Prost
Contributor
Contributor
Jump to solution

Does anyone have any comments on my configuration? Did I misunderstand rogard and that is the only option? Will what I have work?

Thanks,

0 Kudos
Prost
Contributor
Contributor
Jump to solution

I have set up the DRS rules as stated above and things seem to be working at the moment. However I have not been able to test this in a failure situation. I have observed that when powering on the guest that have the network limitations they will only power boot to the host with the correct rules.

I have heard a rumor that ESX 4.1 will have the ability to group guests and hosts together to eliminate some guests booting on particular hosts. Has anyone heard of this feature? Does anyone have a link to a white paper of the new features of ESX 4.1?

0 Kudos
Prost
Contributor
Contributor
Jump to solution

Rogard, I was talking further with my network team and showed them your post. You were correct with your answer. I am able to trunk these networks together. Due to security I can not trunk them all but this will allow me to free up enough connections to get all of my host on a constant network.

Thank you for your help with this.

I have also found this article that helped me understand trunking and vSwitch tagging better.

http://searchnetworking.techtarget.com/tip/0,289483,sid7_gci1515654,00.html?track=NL-79&ad=777845&as...

0 Kudos