VMware NSX

  • 1.  Isolate vm inside the same subnet

    Posted Jan 07, 2016 11:58 AM

    Premise that I have never used air vCloud but used for years AWS.

    Before start to evaluate air VCloud for a test I need an answer to this question:

    SCENARIO: distribute tens of vm vm where each is isolated from the others, it shares the same gateway, and all reside on the same LAN.

    I read this document vchs_networking_guide.pdf and I don't find any solution for this problem.

    It's possible on air vCloud this architecture?



  • 2.  RE: Isolate vm inside the same subnet

    Posted Jan 07, 2016 01:32 PM

    Hi,

    You should use NSX instead of VCNS. NSX comes with DFW functionality and provide FW per virtual NIC !

    You should be able to isolate your VM, even in a single subnet as you need.

    Take a look at the NSX Network virtualization design guide (check this link out : VMware® NSX for vSphere Network Virtualization Design Guide ver 3.0)



  • 3.  RE: Isolate vm inside the same subnet

    Posted Jan 07, 2016 02:35 PM

    Thank  for your comment!!

    I can use NSX inside IaaS vmware air vCloud?

    In the DEDICATED CLOUD or in  the VIRTUAL PRIVATE CLOUD ?



  • 4.  RE: Isolate vm inside the same subnet

    Posted Jan 08, 2016 03:06 PM

    Hi,

    Actually i only work with vCloud Director and do not know vCloud Air.

    However, in my opinion with NSX Distributed FW functionality, only VM NIC matter. You can use DFW without any Cloud solution !

    Whatever product you will use (vCloud, vRA or any other) you will need to :

    • Prepare (install NSX vibs on) all hosts that will execute VM to isolate
    • Think about using Security group to make your administration easier
    • Of course, try to automate all that


  • 5.  RE: Isolate vm inside the same subnet

    Broadcom Employee
    Posted Jan 08, 2016 03:09 PM

    ‌NSX distributed firewall capabilities are available in vCliud Air Dedicated with Advanced Networking services add-on. 



  • 6.  RE: Isolate vm inside the same subnet

    Posted Jan 08, 2016 03:13 PM

    You should find other information by browsing vCloud Architecture Toolkit for vCAT-SP