We are finalizing our vSphere setup. The current enviroment consists of 4 vlans on different subnets. 192.168.1.x is our production, including Active Directory. When vshpere was setup it was split into the other vlans for segregation. vCenter, including the management network is on 192.168.11.x (vlan11). There is trunking and acls to allow mgmt access to vlan 11. We now would like to join the vCenter server to AD, however, it is on a different vlan and subnet than AD and cannot join without making changes. Should the vCenter server be in the production network? Is it better to leave vCenter in the current vlan and open access for AD or to place it in the production network and maintain the management vlan for the vSphere mgmt network? Many thanks in advance for any assistance.
Its really based on how you require it to be. Most of the customers have a requirement of strict rule that vCenter should be on a particular VLAN. But that's something that they decide based on some rules. As far as vcenter can talk to AD there's is no particular rule. In your case if production vlan and vlan11 are trunked you can have AD integrated with vCenter.
It all depends. Personally I would just open the firewall and allow access for AD. I am sure you have other machines that already have to do it if you run much of a Windows environment. Of course with AD it's a lot of ports so be prepared to open it all the way. If security requirements don't allow for this then move it into the lan.
Just my two cents.
please see this
As we’ve moved more and more of our critical infrastructure at The Chapel to the virtual world, I’ve struggled on occasion with the issue of setting up network cards in VM’s to work on different subnets.
This became a real issue when we migrated from our Cisco phone system to our virtualized MiTel phone system. All was good until I needed to setup the “MiTel Boarder Gateway” which acts as a firewall and SIP gateway for the phone system. Since I had to get this up and running quickly I just installed another network card then mapped it to a virtual switch in VMware and mapped the second NIC in the VM to that virtual switch.
This approach however is not very efficient or redundant. It also takes up valuable NIC’s and switch ports. My plan is to update this configuration with what I’ve learned when setting up our print server to work with FingerPrint which I’m going to detail below.
How to setup Vlan tagging in VMware ESXi