VMWare Data Centre Design Question

Unanswered Question
Mar 10th, 2008


I have a question regarding VMWare in the data centre.

We currently have a two-site data centre configured as ne logical DC.

Within that DC, we run multiple VRF's to allow different companies to utilise the network infrastructure.

The VRF's are separated by firewalls (both FWSM and Checkpoint).

I am being pressed by our server guys who want to host a guest server from different companies (different VRF's) on the same VM Host server.

This approach bridges firewall DMZ interfaces and I do not want to do this.

However, VMWare claim that there virtual switch product provides an "air gap" between servers so there is no security risk.

Has anyone got an opinion on this?


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
scottpilkinton Mon, 03/10/2008 - 19:17

That is correct, your physical ports are mapped as uplink ports to different virtual switches. There can be multiple virtual switches as needed and each virtual switch uses separate uplink ports. Since there is no IP forwarding that goes on in the host operating system, I wouldn't think twice about doing it.



bhedlund Thu, 03/13/2008 - 08:05

No problem. This is a very common deployment. As you know VLANs are associated to VRF's and hosting multiple VMs each on different VLANs within a single ESX Server is no problem at all.

Read the section about Virtual Switch Tagging (VST) in this document as that will be the configuration that will support this kind of deployment:


Hope this helps. Please rate this post if helpful.




This Discussion