7.0

Table Of Contents
Table 5-21. Network Configuration Scenarios Supported by ESXi
Scenario Approach
You want to accept the DHCP-configured IP
settings.
In the ESXi direct console, you can find the IP address assigned
through DHCP to the ESXi management interface. You can use
that IP address to connect to the host from the vSphere Client
and customize settings, including changing the management IP
address.
One of the following is true:
n You do not have a DHCP server.
n The ESXi host is not connected to a DHCP
server.
n Your connected DHCP server is not
functioning properly.
During the autoconfiguration phase, the software assigns the link
local IP address, which is in the subnet 169.254.x.x/16. The assigned
IP address appears on the direct console.
You can override the link local IP address by configuring a static IP
address using the direct console.
The ESXi host is connected to a functioning DHCP
server, but you do not want to use the DHCP-
configured IP address.
During the autoconfiguration phase, the software assigns a DHCP-
configured IP address.
You can make the initial connection by using the DHCP-configured
IP address. Then you can configure a static IP address.
If you have physical access to the ESXi host, you can override
the DHCP-configured IP address by configuring a static IP address
using the direct console.
Your security deployment policies do not permit
unconfigured hosts to be powered on the
network.
Follow the setup procedure in Configure the Network Settings on a
Host That Is Not Attached to the Network.
ESXi Networking Security Recommendations
Isolation of network traffic is essential to a secure ESXi environment. Different networks require a
different access and level of isolation.
Your ESXi host uses several networks. Use appropriate security measures for each network, and
isolate traffic for specific applications and functions. For example, ensure that VMware vSphere®
vMotion® traffic does not travel over networks where virtual machines are located. Isolation
prevents snooping. Having separate networks is also recommended for performance reasons.
n vSphere infrastructure networks are used for features such as vSphere vMotion, VMware
vSphere Fault Tolerance, VMware vSAN, and storage. Isolate these networks for their specific
functions. It is often not necessary to route these networks outside a single physical server
rack.
n A management network isolates client traffic, command-line interface (CLI) or API traffic,
and third-party software traffic from other traffic. This network should be accessible only by
system, network, and security administrators. Use jump box or virtual private network (VPN) to
secure access to the management network. Strictly control access within this network.
n Virtual machine traffic can flow over one or many networks. You can enhance the isolation of
virtual machines by using virtual firewall solutions that set firewall rules at the virtual network
controller. These settings travel with a virtual machine as it migrates from host to host within
your vSphere environment.
VMware ESXi Installation and Setup
VMware, Inc. 220