How do you do....it? Thread, VMWare ESXi networking question in Technical; Going a bit cross eyed from reading manuals - so hopefully someone can short cut through my stupidity...
What I ...
15th March 2011, 11:54 AM #1
VMWare ESXi networking question
Going a bit cross eyed from reading manuals - so hopefully someone can short cut through my stupidity...
What I want to do - set up a 2008/W7 test bed on an old server under ESXi
What I'm worried about - presumably I need this test bed to be completely seperate from the existing network to avoid any problems with DHCP or DNS etc etc....but...I would like to get internet access through our broadband.
Any ideas on setting this up would be handy - I imagine VLANs might be needed - but at present I can't change what we have set up.
15th March 2011, 12:00 PM #2
Create two virtual switches, one called something like external and one called internal. On the external one you assign one of the physical nics, then build a vm using the firewall product of your choice, connecting the red side to external, green to internal and to use an upstream proxy/gateway pointing to your internet connection firewall.
You then build you test machines connecting to the internal network and pointing to the firewall for their gateway/proxy.
Edit: just to clarify, don't assign any physical nics to the internal switch.
15th March 2011, 04:48 PM #3
Thanks teejay - I'll try & get my head round that...
15th March 2011, 05:22 PM #4
A picture may help:
Thanks to teejay from:
SpuffMonkey (16th March 2011)
16th March 2011, 12:20 PM #5
16th March 2011, 10:18 PM #6
The other option is to send a trunk down to the vSwitch and then use VLANing as you proposed. This would also work, and will not require you to have an extra firewall device running.
16th March 2011, 10:40 PM #7
Ok, at some point you've got to connect to the internet, how do you propose to do that? Only way I can think of is to stick an extra nic in the internet firewall and run the test network in a DMZ.
Originally Posted by chrisbrown
Edit: you don't need a resource hog Firewall like Forefront TMG to do what I suggested, we use IPCop for this, uses hardly any memory or processor power.
Last edited by teejay; 16th March 2011 at 10:44 PM.
17th March 2011, 12:57 AM #8
I'm afraid I don't understand. You create a new VLAN that goes as far as your core routing devices
Originally Posted by teejay
VLAN 222, IP range 220.127.116.11/24. Have a route on your router that has a default route out of your network for that VLAN, but will not allow routing between the networks. Simple stuff, really. You don't need a firewall to segregate two LAN segments.
By iSteve in forum Thin Client and Virtual Machines
Last Post: 28th May 2010, 12:14 PM
By jreimer in forum Thin Client and Virtual Machines
Last Post: 27th May 2010, 10:19 AM
By albertwt in forum Thin Client and Virtual Machines
Last Post: 29th April 2010, 10:55 AM
By Hightower in forum Thin Client and Virtual Machines
Last Post: 18th December 2009, 03:31 PM
By jack0w in forum Thin Client and Virtual Machines
Last Post: 17th October 2008, 11:25 AM
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)