VMware Cloud Community
LorenHudson
Contributor
Contributor
Jump to solution

How best to solve this problem (Internal vCenter, External ESX host)

The issue is we have our virtual center and our production ESX hosts on our internal network. We have an additional emergency site in a distant network but hosted with a public address with out a firewall in front of it. When I add the host to my vCenter it in fact does add just fine and works for 1 minute then disconnects. This is because the heart beat cannot reply back to the virtual center. The emergency server will host 3 virtual machines, 1 email box, 1 web site, and 1 backup domain controller. I only know the basics of networking so i dont know what would be thest best idea.

I will submit a request to the network engineers after i know which would work best.

Should I create a nat for the vCenter server and will that resolve the heart beat issue

Should I have a reverse proxy set up and then edit the esx host and change the vCenter's internal address to the public address with the reverse proxy?

Should I make the address pool that the esx host is using (about 10 external but public addresses) available to route between our internal vlans?

Is there a different sugguestion with a better description that you would recommend to resolve this issue and better position my future goals with the 3 virtual machines I plan to host on that server.

Any advice is welcome.

Thanks

0 Kudos
1 Solution

Accepted Solutions
idle-jam
Immortal
Immortal
Jump to solution

Is Site 2 Site VPN possible? if so then it would make things much less complicated. Putting ESX in DMZ with Public IPs is not a good idea in terms of security.


iDLE-jAM | VCP 2, VCP 3 & VCP 4

If you found this or any other answer useful please consider the use of the Helpful or correct buttons to award points.

View solution in original post

0 Kudos
1 Reply
idle-jam
Immortal
Immortal
Jump to solution

Is Site 2 Site VPN possible? if so then it would make things much less complicated. Putting ESX in DMZ with Public IPs is not a good idea in terms of security.


iDLE-jAM | VCP 2, VCP 3 & VCP 4

If you found this or any other answer useful please consider the use of the Helpful or correct buttons to award points.

0 Kudos