8.0

Table Of Contents
Table 4-21. Network Configuration Scenarios Supported by ESXi (continued)
Scenario Approach
The ESXi host is connected to a functioning DHCP
server, but you do not want to use the DHCP-
configured IP address.
During the autoconfiguration phase, the software assigns a DHCP-
configured IP address.
You can make the initial connection by using the DHCP-configured
IP address. Then you can configure a static IP address.
If you have physical access to the ESXi host, you can override
the DHCP-configured IP address by configuring a static IP address
using the direct console.
Your security deployment policies do not permit
unconfigured hosts to be powered on the
network.
Follow the setup procedure in Configure the Network Settings on a
Host That Is Not Attached to the Network.
ESXi Networking Security Recommendations
Isolation of network traffic is essential to a secure ESXi environment. Different networks require a
different access and level of isolation.
Your ESXi host uses several networks. Use appropriate security measures for each network, and
isolate traffic for specific applications and functions. For example, ensure that VMware vSphere®
vMotion® traffic does not travel over networks where virtual machines are located. Isolation
prevents snooping. Having separate networks is also recommended for performance reasons.
n vSphere infrastructure networks are used for features such as vSphere vMotion, VMware
vSphere Fault Tolerance, VMware vSAN, and storage. Isolate these networks for their specific
functions. It is often not necessary to route these networks outside a single physical server
rack.
n A management network isolates client traffic, command-line interface (CLI) or API traffic,
and third-party software traffic from other traffic. In general, the management network is
accessible only by system, network, and security administrators. To secure access to the
management network, use a bastion host or a virtual private network (VPN). Strictly control
access within this network.
n Virtual machine traffic can flow over one or many networks. You can enhance the isolation of
virtual machines by using virtual firewall solutions that set firewall rules at the virtual network
controller. These settings travel with a virtual machine as it migrates from host to host within
your vSphere environment.
Choose Network Adapters for the Management Network
Traffic between an ESXi host and any external management software is transmitted through an
Ethernet network adapter on the host. You can use the direct console to choose the network
adapters that are used by the management network.
Examples of external management software include the vCenter Server and SNMP client. Network
adapters on the host are named vmnic
N
, where N is a unique number identifying the network
adapter, for example, vmnic0, vmnic1, and so forth.
VMware ESXi Installation and Setup
VMware, Inc. 228