4.0

Table Of Contents
Lab Manager User’s Guide
56 VMware, Inc.
5SpecifytheaccessrightsfortheusersandclickOK.
Ifyoushareaconfigurationwithusersoutsideoftheworkspaceinwhichtheconfigurationwascreated,
youcanonlyspecifyReadaccess.Inaddition,configurationscreatedinGlobalcanonlybesharedwith
Readaccess.
6ClickOKandDone.
Configuration Networking
Beforeyoudeployaconfiguration,itishelpfultounderstandhowconfigurationnetworkingworksin
Lab Manager.
Physical Networks
InLab Manager,physicalnetworksrepresentphysicalnetworksconnectedtothevSpheredatacenter.
These networksexistoutsideconfigurationsandspanconfigurations.Virtualmachinesthatconnecttothe
samephysicalnetworkcancommunicatewitheachother,evenifthevirtualmachinesbelongtodifferent
configurations.
Thephysicalnetworksavailabletoaconfigurationarebased
onthephysicalnetworksassignedtothe
configuration’sorganization.
Physicalnetworksareboundtovirtualswitches(vSwitches)ononeormoreESX/ESXihostsinLab Manager.
YoucanbindaphysicalnetworktoasinglevSwitchperhost,andyoucanonlybindphysicalnetworksto
vSwitcheswithphysicaladapters.Theadapter
vSwitchassociationismadeinvCenter,andtheusermust
makethecorrectassociation.YoucanalsobindaphysicalnetworktoavNetworkDistributedSwitch.
AvNetworkDistributedSwitchfunctionslikeasinglevirtualswitchacrossallassociatedhosts.Thisallows
virtualmachinestomaintainconsistentnetworkconfigurationastheymigrate
acrossmultiplehosts.
Whenyoubind,Lab ManagercreatesaportgrouponthevSwitch,oradvPortgrouponthevNetwork
DistributedSwitch,namesitbasedontheLab Managerphysicalnetworkname,andreportsthatastheName
invCenterontheNetworkPropertiespage.IftheLab Managerphysicalnetworkspecifiesa
VLANID,Lab
ManagersetsthisontheportgroupordvPortgroup.Lab Managerdoesnotuseoraffectexistingportgroups
onthevSwitchorvNetworkDistributedSwitch.
Fencing Virtual Machines
Whenyoudeployaconfigurationthatincludesaphysicalnetwork,youcanchoosetoisolatetheconfiguration
virtualmachinesfromothermachinesonthenetwork.ThispreventsIPandMACaddressconflictsthatcould
existifmultiplecopiesofthesamemachinearedeployedatthesametime.
Fencingaconfiguration
isolatesthevirtualmachinesthataredefinedtobeconnectedtothephysicalnetwork
fromthedatacenternetworkusingavirtualrouter(VR)andbidirectionalnetworkaddresstranslation(NAT).
Typically,youwanttoenablenetworkfencingunderthesecircumstances:
Youhaveaconfigurationwithoneormoreservers,andyouanticipatecloningtheconfiguration
numeroustimes.
Youhaveaconfigurationinvolvingadifficultandcomplexsetup,andcloningtheconfigurationisan
easierroutethanrepeatingthesetup.
Fromaperformanceperspective,networkfencingimpactsthetrafficflowbetweenmodules.Fencingrequires
aslightlyhighernumberofresourcesonthehost,suchasmemory,CPU,andnetworking.
Ifyouenablefencing
butneveruseit,theseresourcesarenotconsumed.
Virtualmachinesinaconfigurationhavepreconfigured(internal)IPaddresses.Whenyoudeployvirtual
machinesinfencedmode,Lab ManagerassignsauniqueexternalIPaddresstoeachofthesemachines.
Throughtheseexternaladdresses,virtualmachinesbothinside
andoutsidethefencecancommunicatewith
eachother.Lab Managerusesavirtualmachinecalledavirtualrouter(VR)toroutepacketsbetweenthese
virtualmachines.Lab Managerconfiguresthevirtualrouterwhenyoudeployafencedconfigurationand
deletesitwhenyouundeploytheconfiguration.