Ok, but if I create a new LUN will my physical Windows servers see it or is my SAN now dedicated to ESXi?
OK SAN is a device. That device has multiple purposes. The way you designate purpose is by setting up zones or masking (which is a type of security) and you divide up space and ASSIGN them to HBA by their WWN/WWP. so if you physical machine is attached via fiber than you need to configure A LUN that you give THAT HBA on that device access. So only that device (or many devices if you want to share it) can access that data.
By default most devices can ONLY have access to 1 LUN at a time, but ESX can share data, which is how you can have many ESX servers assigned to the same LUN by ID.
So you can still point your physical device to a LUN separate from LUNs assigned to ESX.