Simplify VMware vSphere* 4 Networking with Intel Ethernet 10 Gigabit Server Adapters
To enhance redundancy further, a second
option is to move to a four 10GbE port
congurationthatprovidesthetwo
primary ports a dedicated backup or
redundant port on separate adapters.
The same practice of immediately moving
VMs to a new host in case of failure
(and lost redundancy) should be used.
Thiscongurationcanprovidegreater
bandwidthtotheVMsandtheVMKernel
trafctypesorphysicalseparationof
trafctypesifrequired.
Customer Concerns: Security, Traffic
Segmentation, and Bandwidth
Concerns reported by customers
regarding consolidation of connections
onto10GbEincludesecurityandtrafc
segregation with dedicated bandwidth for
critical networking functions.
When GbE server connections are
consolidated, a way to isolate connections
in the absence of dedicated physical
connections is still necessary. This
requirementreectstheneedfor
security between different types and
classesoftrafc,aswellastheabilityto
ensureadequatebandwidthforspecic
applications within the shared connection.
Security Considerations: Isolating Data
among Traffic Streams
In our 10GbE model, VLANS provide
some of the basic security features
required in the installation. Security of
VLANs has been debated, tested, and
written about extensively. A review of
the documentation suggests strongly
that when properly implemented, VLANs
provide a viable option for network
isolation. For further inquiry on this
subject, see the VLAN Security White
Paper
4
from Cisco Systems or vSphere
Hardening Guide: ESX and Virtual
Networking
5
from VMware. In particular,
note the following safeguards that help to
protect data:
group, additional server adapters must
be added (assuming additional PCI* slots
are available). Additionally, the bandwidth
allocated in the example cannot be used
byanyothertrafc;itsimplygoestowaste.
On the other hand, handling the port
group with bandwidth from a shared
10GbE server adapter allows additional
bandwidthtobeallocatedfortrafc
spikes more seamlessly. Furthermore,
multiple port groups can share the
bandwidth headroom provided by the
server adapter. The resource can be
automatically and dynamically reallocated
as various port groups are accessed
by their associated VMs. Dedicated
bandwidth is not needed for any one
port group as long as the host network
connection never reaches saturation. This
method is very similar to how VMware
shares processor resources, allowing VMs
to burst processor utilization as needed
due to the likelihood that many VMs won’t
burst at the same time.
TheIntelNetworkingTestlabconrms
the viability of replacing multiple GbE
ports with a pair of 10GbE ports in the
congurationmentionedinthispaper.A
number of VMs were installed on each of
two hosts, and the process of migrating
all of the VMs on one host to the other
and back again was timed. This testing
wasdonewithnootherworkortrafc
owsonthesystems.Asapointof
comparison,networktrafcowswere
started to all of the VMs on each host,
and the migration exercise was run again.
The result was that the time required
to migrate the VMs was only minimally
affected.
1
•Logical partitioning protects individual
traffic flows. VMware vSphere can
control the effects from any individual
VM on the traffic flows of other VMs that
share the same physical connection.
•Internal and external traffic do not
need to share a physical connection.
DMZs can be configured on different
network adapters to isolate internal
traffic from external traffic as security
needs dictate.
•Back-end services are handled by
VMware ESX. Administrative traffic and
other back-end services are handled by a
separate networking stack managed by
the VMkernel, providing further isolation
from VM traffic, even on the same
physical connection.
Traffic Segmentation and
Ensuring Bandwidth
10GbE provides enough bandwidth for
multipletrafctypestocoexistonasingle
port, and in fact, in many cases Quality of
Service (QoS) requirements can be met
simply by the availability of large amounts
ofbandwidth.Thepresenceofsufcient
bandwidth can also dramatically improve
the speed of live VM migration using
VMotion, removing potential bottlenecks
for greater overall performance. Beyond
thegeneralavailabilityofsignicant
bandwidth,however,trafcsegmentation
can provide dedicated bandwidth for each
classofnetworktrafc.
Whilesegmentingtrafcowsonto
discreet GbE connections is also a viable
means of providing dedicated bandwidth
toaspecictrafctypeorfunction,doing
so has distinct shortcomings. For example,
allocating two GbE connections to a VM
trafcportgroupprovidesapotential
of 2 Gbps of dedicated bandwidth, but
if additional bandwidth is needed for
sporadictrafcspikesfromthatport
6
Simplify VMware vSphere* 4 Networking with Intel® Ethernet 10 Gigabit Server Adapters