Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How do I set up two gateways on a single esx box

Status
Not open for further replies.

mrgulic

Technical User
Sep 18, 2001
248
US
I have 2 gb nics installed on an ESX 3.5 box. 1 nic is plugged into my LAN and the other nic is plugged into the WAN (a router outside the LAN)

LAN Gateway 192.168.10.1
WAN Gateway 192.168.3.1

I can't see anyway to specify another gateway for the second nic.

Thanks in advance for you assistance.
 
Hi

Setup your Service console on the Lan address and then just setup the other WAN IP to a vswitch and port in network setup.
When you create a VM on your ESX box you will have two nics to choose from and you setup the nic as per normal inside the VM. ie IP,Mask and Gateway.
Just a word of warning, be careful sharing a ESX box which hosts VM's which are on your lan and in the DMZ - this is not a recommded practise. Idealy you should have dedicated ESX servers inside your DMZ which hosts DMZ VM's or aleast firewalls in place to only allow a few open ports.

Hope it helps


Dave


 
You don't need an IP address on a physical NIC for a VM to access it.

Remember, the Service Console is basicly a VM running on top of the VmKernel. ESX is not a linux product, it is a proprientry kernel. The Service Console sits on top of this. VM's do not run on the service console, they run on the VMKernel, the Service Console just has more hooks into the VMKernel. So if you configure a vSwitch with access to a NIC, the VMKernel will basically bridge the physical NIC to the virtual NIC.

So you setup NIC1 with your internal VM Network, and the Service Console on their own vSwitch.

Then setup NIC2 with just a VM Network attached to a vSwitch . Build you WAN VM here.

The two vSwitches will not route traffic between each other, so in essence, they are isolated (plenty of white papers on this prooving the security). So if you needed to route traffic between the two, you would need to either setup an external router to do so, or setup something in side ESX to do so.

If the WAN link is actually an Internet line, then there are security conserns you would need to follow, yet it is still do able. You can do some neat things putting a DMZ inside of an ESX server. Yes, some companies do choose to dedicate an ESX server to a DMZ, this is just a choice, not a required setup, nor even a best practice recomendation.

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
Brent Schmidt SPOOOOON!!!!! [hippy]
Senior Network Engineer
Keep IT Simple
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top