Hello
Few things to consider:
1. With vSAN 2node cluster you can use direct connect - you connect servers back to back with 10g (like Server A NIC1 port1 to Server B NIC1 port2, Server A NIC1 port2 to Server B NIC1 port2). You need configure dedicated switch for this and connect there relevant uplinks. You can use this for VSAN and for vMotion, as these networks usually do not require L3 connectivity.
AFAIR recommended uplink policy is to configure those uplinks in the dual active - standby -> smthg like VSAN vmk uplink1 Active, uplink2 Standby; vMotion vmk uplink1 Standby, uplink2 Active
2. Generally you have 3 options for witness network:
a) in the same network as VSAN
b) in the same network as ESXi mgmt
c) in the separate network accessible via ESXi mgmt default gateway
3. In the direct connect VSAN you can put witness in the same network as the ESXi mgmt. You just need to reconfigure VSAN to use mgmt network for VSAN witness connectivity.
You just need to host witness outside those 2 nodes.
Unfortunately I cannot help you more.
I demoed such config like 1,5 year ago and it worked pretty well.
Hope that helps