6.7

Table Of Contents
ESXi Networking Security Recommendations
Isolation of network traffic is essential to a secure ESXi environment. Different networks require different
access and level of isolation.
Your ESXi host uses several networks. Use appropriate security measures for each network, and isolate
traffic for specific applications and functions. For example, ensure that VMware vSphere vMotion
®
traffic
does not travel over networks where virtual machines are located. Isolation prevents snooping. Having
separate networks is also recommended for performance reasons.
n
vSphere infrastructure networks are used for features such as vSphere vMotion, VMware vSphere
Fault Tolerance, and storage. Isolate these networks for their specific functions. It is often not
necessary to route these networks outside a single physical server rack.
n
A management network isolates client traffic, command-line interface (CLI) or API traffic, and third-
party software traffic from other traffic. This network should be accessible only by system, network,
and security administrators. Use jump box or virtual private network (VPN) to secure access to the
management network. Strictly control access within this network.
n
Virtual machine traffic can flow over one or many networks. You can enhance the isolation of virtual
machines by using virtual firewall solutions that set firewall rules at the virtual network controller.
These settings travel with a virtual machine as it migrates from host to host within your vSphere
environment.
Choose Network Adapters for the Management Network
Traffic between an ESXi host and any external management software is transmitted through an Ethernet
network adapter on the host. You can use the direct console to choose the network adapters that are
used by the management network.
Examples of external management software include the vCenter Server and SNMP client. Network
adapters on the host are named vmnicN, where N is a unique number identifying the network adapter, for
example, vmnic0, vmnic1, and so forth.
During the autoconfiguration phase, the ESXi host chooses vmnic0 for management traffic. You can
override the default choice by manually choosing the network adapter that carries management traffic for
the host. In some cases, you might want to use a Gigabit Ethernet network adapter for your management
traffic. Another way to help ensure availability is to select multiple network adapters. Using multiple
network adapters enables load balancing and failover capabilities.
Procedure
1 From the direct console, select Configure Management Network and press Enter.
2 Select Network Adapters and press Enter.
3 Select a network adapter and press Enter.
After the network is functional, you can use the vSphere Web Client to connect to the ESXi host through
vCenter Server.
VMware ESXi Installation and Setup
VMware, Inc. 196