ESXi network redundancy

Hi all

I would like to ask a few questions about my design of the network.

I use the small DELL blade solution. (Dell VRTX).

Currently, we have two servers with essential M620 HA cluster installed with ESXi 5.5 blades more license.

I have decided to dismiss more my network configuration.

Each blade has two ports 10 GB switch LOM connected internally (module e/s inside the chassis of the blade) and also connected 2 ports PCI network cards.

As an attachment, you can find my layout of network design.

EXPLANATION OF THE LAYOUT

*********************************

NIC1, NIC2 = LOM

NIC3 NIC4 = PCI CARD

NIC1 + NIC3 = kernel Ports (NIC 1 - standby adapter)

NIC2 * NIC4 = Standart (NIC2 - Standby adapter) ports

VSWITCH1 = used for V-MOTION, MANAGEMENT, NETWORK (same as our network LAN, VLAN7)

VSWITCH2 = branches with 3 MPLS network VLAN

CONNECTION of RED = traffic vlan 7 geocoded

CONNECTION BLUE = trunk (VLAN1, 2, 3)

CONNECTION GREEN = trunk (VLAN 1,2,3,7)

BB is two stucked switch node.

I would like to ask if my drawing is correct.

Thanks in advance

Hi Roman,

First of all, I would be divided management and vMotion traffic VLANS separated. I've seen some process of vMotion goes wild, I like to keep this seperated ;-)

Thus, you could use NIC1 to management, with NIC3 mode sleep for this and use NIC3 for vMotion with NIC1 pending.

Secondly, I recommend you to use NIC2 and NIC4 in active/active mode, if you use the second card for the VM network traffic load balancing and not to waste it in fashion watches.

See you soon

Tim

Tags: VMware

Similar Questions

  • "This host currently has no management network redundancy", but there are?

    While in vcenter, the summary for a host tab displays this message:

    "This host currently has no management network redundancy.

    I have attached photos of the host > Configuration > network and host > Configuration > network cards pages. It seems to me that the management network is behind 2 NIC's team together.

    What I am doing wrong? How can I fix?

    Thank you

    More than an idea. Righ click hosts and run "reconfigure for HA.

    André

  • That errro again... host currently has no error management network redundancy

    I don't get the "host currently has no error management network redundancy.

    I think that I have the correct configuration, but not sure since our network guys gave me the IP addresses to use for HA.

    Here is the config for HA

    ESX Server 6.

    Service console is on 0 to 172.16.1.106 in 255.255.0.0 vSwitch

    The second redundancy console) is on vSwitch 4 to 77.77.77.10 in 255.255.255.0.

    ESX Server 5.

    Service console is on vSwitch 4 to 172.16.1.105 in 255.255.0.0

    The second redundancy console) is on vSwitch 4 to 77.77.77.9 in 255.255.255.0.

    I've reconfigured HA on ESX Server 6 and ESX Server 5 and even restarted them but still not the mistake of redundancy...

    Something is not properly configured?

    stanj wrote:

    If the collection of network adapters offer the same functions of redundancy, so why so many articles point to using a second console HA redundancy?

    It's simply the options given. There are several ways to provide a redundancy of HA heartbeat.

    The article also indicates HA advanced features such as das.isolationaddress2 and das.failuredetectiontime will be charged when you set up a secondary service console. It is an approach more effective, but still more complicated?

    These advanced options are not always available and also provide another way to configure HA redunancy.

    Here's something interesting to look at as well

    http://www.yellow-bricks.com/VMware-high-availability-deepdiv/

    For me, I always learned the KISS method (Keep it Simple stupid).  Add a second NETWORK card is the easiest way to keep your redundant environment, in my opinion

  • Create alarm "Network redundancy lost" by the script?

    Hello:

    I'm trying to write a script that will create the alarm in order to monitor the redundancy of the lost network (I know manually there) on the host.

    I know how to create alarm for additional exhibit the ' basic' event (LucD - thank you for your help) and I know that I have for alarm 'Lost network redundancy' to use 'vprob.net.redundancy.lost' instead of 'EnteringMaintenanceModeEvent' (as in my example); but I still struggle to combine...

    Can someone help me please?

    Thank you

    qwert

    I don't have a particular script fantasy with the settings and all the rest, but I can show you the steps to filter alarms by name and remove the desired one.

    alarm #retrieve Manager

    $alarmManager = get-view-Id "AlarmManager-AlarmManager.

    #Get the entity that contains the alarm that you want to remove. I'll do it for a virtual machine

    $entityView = get-Vm-name MyVm | Get-View

    #get all MoRefs alarm

    $alarmMoRefList = $alarmManager.GetAlarm($entityView.MoRef)

    #Retrieve tha alarm views from the MoRefs

    $alarmViewList = $alarmMoRefList | foreach (Get-view $_)

    #Now filter the name alrams

    $alarmToDelete = $alarmViewList | where {$_.Info.Name - eq "AlarmToDelete"}

    #Finally remove alarms

    $alarmToDelete.RemoveAlarm)

    It shouldn't be hard to put this in a script or function reussable. If you have problems with this, I'll be happy to help you again!

  • Lost network redundancy!

    Normally, when die NIC 1, we have netword redundancy. But this time, time 2 die of network card in a standard switch in a 5.1 ESXi host-> that is why, many network down-> affect to multiple virtual machines. There is only avaible network management yet.

    Is there anyone to deal with this problem? Help us...

    Thank you!

    If it is urgent and machines production is declining, please contact VMware Support.

    If its not urgent please let us know more details about what happened, what kind of configuration it is, etc. error messages.

    Linjo

  • alert the uplink network redundancy lost

    VCenter has an uplink lost redundancy alert network, which takes about 5 days. The alert cannot be recognized or green value, because the option is grayed out. VCenter client does not show the cards down. A few questions

    -How can the alert being erased?

    -Where should I look for the question? I checked the network adapters on the host's configuration in vcenter client. Where would be ESXI connect alerts for this problem?

    It's vCenter.  Alarms are sometimes "buggy".

  • iSCSI multipath vs network redundancy?

    If I have a redundant network, say a VMkernel port on a vSwitch with two VMnic, maybe Port ID load balancing and the two vmnic goes to two different physical switches and there are redundant links on all switches between the ESXi host and iSCSI SAN and it is Rapid Spanning Tree set up, and there is a kind of Etherchannel / Link aggregation on the iSCSI Server , but only a single IP address...

    Is there an advantage to configuring iSCSI multipath and let the VMkernel manage failover, rather than let the network itself, make sure that there is a path between the host and the target?

    Primary storage provider use several IP for storage NIC (in some cases two different networks).

    With the VMware multichannel modules, you are limited to only one path (at that moment) to a LUN, but the seller might have is multichannel modules, or of course, you can use LUN more have used more of paths.

    Bandwidth could be interesting with several virtual machines... or I/O loads.

    André

  • ESXi Network Setup 4 nic

    Hello

    I'm currently setting up a new environment of ESXi 4.1. I have 4 NIC on each host. I have seen many different discussions on the separation of vmotion/management. However, I do not think what is ideal with the current network adapter configuration because should I choose to use 2 network cards for management and redundancy of management.

    That's why I think, I separate the 4 network cards on two different switches and on each one I create two trunks (or to cisco etherchannel) while both of these trunks includes 50% of the EPS to a single host. Should I choose to spend 2 network cards on management (one for each switch) I no longer have the ability to trunk/etherchannel to the switch and going so lose the two redundancy on this specific switch and the additional bandwidth, I get by both trunking interfaces.

    Any ideas on this subject?

    / Kris

    The only way I could think it would be with a managed switch making the port tcp based QoS on, I'm pretty sure that the management and the vMotiontraffic will be on different ports for what are your servers.

    It will depend on your brand, a model of switch and how it built of UZ ACL / Classes but it should be fairly easy to build given the level of the managed layer 3.

    The question is whether he can do this level of control of frame/packet without too general.

  • Basic question about ESXi networks

    Hi all

    It may be a very simple question for you but I am new to ESXi and I need your help.

    I have a configuration of ESXi envionrment like that.

    192.168.1.200 - ESXi Server

    192.168.1.50 - a Linux machine

    192.168.1.60 - a Windows 8.1

    ESXi server connects to a router and the network is 192.168.1.0/24.

    The topology just like that.

    Screen Shot 2016-07-03 at 11.08.25 AM.png

    My problem is,

    1. I have a Mac machine connect to the same router. There is a web interface built into the Linux box. Can I use the Windows 8 to go, but I can't use the machine to physical Mac do. The firewall is off turn in ESXi already

    2. How can I make the two machines able to access internet?

    Thank you!!

    After taking a second look at the configuration of the network, I have seen that you have configured a VLAN ID on the port group. Assuming you are using a router not supported (i.e. without ports trunk/tag), this may cause the problem. Please remove the VLAN ID to see if that solves the problem.

    André

  • ESXi Network Setup?

    Hi people

    I have a question for you guys, maybe it's "s too bad for you, but I am quite unsure of what follows. If I have an ESXi server with an edge quadport NIC and I have a Cisco switch with spanning tree active what happens when I:

    Set all 4 ports on the switch, create a vSwitch standard on the ESXi and attach all 4 cards active network with political LB "based on the original Port ID.

    Based on my understanding he will distribute all my virtual machines in all of these NICs attached and all virtual machines are able to communicate (send AND receive) through these 4 vNIC/NICs. There are toggled a virtual machine which is pinned to a VNIC to an another VNIC when I unplug the specific cable.

    BUT

    My colleagues told me NOT! You will only be able to send data on all cards, but receive vNIC alone due to the MAC source/destination of the virtual machines respectively address the NIC in the host.

    Is this true? Exactelly what this policy process "origin port ID". Because there is additional one called "Mac-based..".

    Often, we set up systems like this:

    A server has 2 x quad port NIC. There is a vswitch with 2 cards attached (initially 1, first on a 2nd map) and we set up "based on the source port ID. Further we do NOT set a battery or an Etherchanne on switches connected to the NICs (via cross).

    We want to only have simpe LB and failover in the event of a path failure. It will work correctly (sending and receiving)? My colleagues told me that will not work as long as the switches are not stacked? Why should it not? My understanding of the VM switch vNIC another that is connected to an another NIC which even once, is connected to another standalone switch.

    When the wenn must configure "based MAC" or "HASH IP"? Well, I know when configuring "IP pole" then you must implement an Etherchannel between the host and the switch and set the IP hash strategy or you do not have the additional bandwidth.

    Why would we need to assign adapters Eve and not active? Which is used to deny the problems with loops in an environment no spanning tree?

    How to configure the network (amount of NIC, vSwitches, portgroup assignment, vmotion, etc. and switches)?

    Thank you very much

    What happens when I:

    Set all 4 ports on the switch, create a vSwitch standard on the ESXi and attach all 4 cards active network with political LB "based on the original Port ID.

    Based on my understanding he will distribute all my virtual machines in all of these NICs attached and all virtual machines are able to communicate (send AND receive) through these 4 vNIC/NICs. There are toggled a virtual machine which is pinned to a VNIC to an another VNIC when I unplug the specific cable.

    BUT

    My colleagues told me NOT! You will only be able to send data on all cards, but receive vNIC alone due to the MAC source/destination of the virtual machines respectively address the NIC in the host.

    Is this true? Exactelly what this policy process "origin port ID". Because there is additional one called "Mac-based..".

    It is quite simple, in the default configuration of "based on the original ID Port" each vNIC a VM has only a single active physical uplink at some point in time. This physical NETWORK adapter is used by the host to send as well as receive traffic for this particular vNIC (because your physical switch will learn the VM vNIC MAC on the currently active port only will pass the traffic through this link).

    The distribution is static and only changes when you add/remove/connect/disconnect rising physics or the vNIC (power/power on, disconnect/connect the vNIC). The behavior is the same for the standard vSwitches but also distributed with this policy. You can see the current mapping in the sight of esxtop (r) network:

    The route in source option MAC hash function is very similar, but instead of using the internal ID virtual port, it establishes a static mapping based on the MAC address of an Ethernet frame transmitted by a vNIC source. This approach also maintains a static table of MAC on your physical switch to prevent the beating of MAC. A unique vNIC VM traffic will use several ports, if the virtual machine uses several source MAC addresses. Who should never usually happen unless you do some fancy stuff of networking within the virtual machine and multiple virtual interfaces and it means also you must allow forged passes and MAC changes in security of port vSwitch group options. This article summarizes very well:

    Hostile coding: VMware: MAC LB hash function

    A server has 2 x quad port NIC. There is a vswitch with 2 cards attached (initially 1, first on a 2nd map) and we set up "based on the source port ID. Further we do NOT set a battery or an Etherchanne on switches connected to the NICs (via cross).

    We want to only have simpe LB and failover in the event of a path failure. It will work correctly (sending and receiving)? My colleagues told me that will not work as long as the switches are not stacked? Why should it not? My understanding of the VM switch vNIC another that is connected to an another NIC which even once, is connected to another standalone switch.

    Your colleague is wrong, you don't need any special configuration to the ID load balancing mechanism base port. It will work very well with the recovery, due to the static mapping simple explained above. It will be just like plugging a system of one switch on the other (in the same broadcast domain).

    When the wenn must configure "based MAC" or "HASH IP"? Well, I know when configuring "IP pole" then you must implement an Etherchannel between the host and the switch and set the IP hash strategy or you do not have the additional bandwidth.

    MAC based transmission is also static, but based on the source MAC and has nothing to do with etherchannel/LACP. See my explanation and article above.

    Why would we need to assign adapters Eve and not active? Which is used to deny the problems with loops in an environment no spanning tree?

    vSwitches form loops unless you do really bad things in a VM with multiple network cards to configure some ornithology within this VM operating system. The active settings / standby are basically just primary/secondary hierarchy in case you want the traffic to a group of particular port through a specific binding, unless a failover occurs.

    How to configure the network (amount of NIC, vSwitches, portgroup assignment, vmotion, etc. and switches)?

    Depends on. On a lot of factors.

    To summarize:

    -separate your network with VLAN slipped into a totally physical configuration

    -vMotion put on a non-routed private VLAN with a dedicated physical connection (or active / standby time of team settings ensure vMotion is not shared with other traffic except in a case of failover)

    -use physical rising as much as you want for a bandwidth

    -for IP (NFS, iSCSI) storage or FT, use dedicated as well physical uplink

  • ESXi network problem

    I have a strange problem of networking with ESXi, my infrastructure is described below:

    I'm under vCenter 5.5 on a VCSA (5.5.0 update 2d, Build 2442330). The environment is a mixture of ESXi 5.1 (especially U2) and 5.5U1a. We have 1 primary site with 5 sites all remote connected via GRE VPN tunnels, The VCSA is in the main site, each remote site has at least 1 ESXi server managed by the VCSA. Each remote site has independent internet so for each site, the basic router (which ends the GRE VPN) routes inside networks (essentially 10.0.0.0/8) through the tunnel and has a default route to the local firewall. ESXi boxes that are not configured with the router as the default gateway, none of the custom static routes have been added to ESXi.

    Two of my remote sites (a site has two servers ESXi, the other has a site) ESXi servers keep losing contact with vCenter. Nothing else on these networks is never a problem to talk to the main site, including talking to the VCSA. Three servers are different versions of 5.1. Here's what I've done for troubleshooting:

    1. ESXi can ping on virtually any host through the tunnel to the main site with the exception of the VCSA.
    2. I isolated my network management in ESXi to a physical NETWORK card and made a SPAN on the switch port, a capture of packets revealed that when the rattling of the VCSA ESXi put the packet on the wire with a destination MAC of the firewall. For all the other hosts on the main site of subnet ESXi sends the packet with a destination MAC address of the core router. Packet capture on ESXi itself (using tcpdump-uw) shows the same thing.
    3. The ARP tables on all hosts show correct MAC addresses for the router base and the firewall.
    4. Make a "vmkping - I vmk0 - N < core router > < VCSA >" succeeds (destination MAC is correct in this case).
    5. Add a static route to ESXi to the address of the VCSA force it to the top of base does not work, ESXi continues to send the packet to the Mac static routes these firewall have been removed after the failed test of workaround.
    6. Restart the host will solve the problem for a short time.

    Some info:

    These three server 1 is an IBM x 3300 M4 using Intel I350 GB network cards, the other two are R620s from Dell. The R620s each have 1 4-port Broadcom BCM5720-1 4 Intel 82580 ports. IPv6 has been disabled on all three hosts. Right now vmk0 is linked to an Intel NETWORK card on three servers, but barely I started to watch it, so I don't know if we saw the problem with vmk0 with a Broadcom.

    The Dells are inherited, so we have not done installs it but I reinstalled one of them yesterday (it was 5.1 U2 I reinstalled 5.1 U3) at the request of support for VMware. Support noted that the firmware and drivers were outdated and did not meet the HCL for those who have been updated when I reinstalled.

    IBM has been purchased and installed by our care last summer, firmware and drivers correspond to this LIST with the exception of the version of the BIOS that is a future release (it corresponds to the HCL for 5.5).

    I have a pension case, SR 15633456803. Initially, they tried to blame the network. Although it is clear to me that this is not a network problem, I put a case of Cisco in any way. Cisco has quickly threw the evidence I had gathered and made the same determination. The only way that this could be a network problem is with ProxyARP. ProxyARP is disabled on my firewalls, ESXi has correct ARP tables and when you talk to anything on the main network, in addition to the VCSA it sends the packet to the MAC address so clearly not a question of ProxyARP. At this point VMware said essentially that they are running out of ideas. I hope my reinstalled host stay online for more than a week, then I'll reinstall the other two hosts and call it a day if all goes well, but I'm preparing for the possibility that may not happen.

    We never seen anything like this or have any ideas?

    I understand the problem, ESXi does not correctly release the generated ICMP redirects. You can force the issue by restarting the vmk0 interface (or any port of kernel VM is your management interface) VMware KB: Internet control management protocol redirects, because a permanent fix I will disable ICMP redirects on my routers.

  • esxi Network Setup 4 and esxi 5.5 the same

    Hello

    We have a customer with the following network configuration (see picture). They run ESXi and vCenter 4.0.

    We have added a new separate system with ESXi and vCenter 5.5 and to set up the network, the same.

    My question is this service console, I can't to be able to set this up, it's that are not part of ESXi 5.5?

    If you see the other image, I configured 2 one for management and one for vMotion VMkernel Port, they will be on the same network.

    Would that be correct?

    I don't mind not the network adapters are not connected again... and another thing must use active active alle 4 cards?

    Old configuration

    old config.jpg

    New configuration

    new config.jpg

    Since the release of vSphere 5, he didn't there no Service Console more... the management can be performed via VMkernel port with active management traffic.

    About vmnic design, my recommendation is:

    vSwitch0:

    For vMotion PortGroup - vmnic0 Active and standby vmnic3

    PortGroup management - vmnic3 Active and standby vmnic0

    vSwitch1:

    PortGroup for VMS - vmnic1 Active and active vmnic2

  • ESXi-Networking

    I have ESXi server with 3 maps and I'm looking for advice for best practices to connect:

    My network environment: external ISP connection Cisco router.

    Two switch (vLan interconnection).

    Please can someone help!

    As you got only 3 network cards then I would say to keep 1 card 2 management and vMotion network and other NETWORK cards network for traffic from virtual machines as virtual machine network is more critical because they are real workloads of your installation.

  • Networking question in VMware Workstation / nested ESXi network configuration problem

    Hi guys,.

    I am trying to set up a virtual lab, I setup a domain, a vcenter server and up to 1 ESXi host controller.

    I am really struggling with the network aspect in establishing a vmnic for storing shared, please see the attached screenshots and a few questions:

    1. Is a vmnic a real network map? or vmnic correspond to "network adapters" that you put in place since the setting of your virtual machine?

    I followed a tutorial and implement 3 NICs on the ESXi host, in Bridge mode, I tried this in my configuration of vmworkstation and I lose the connection to my server vcenter to the ESXi host.

    See screenshot attached to how I configured my ESXi host, screenshot is called 'screenshot2esxihost network', I run got each of the maps defined on NAT network.

    screenshot2esxihost network.JPG

    See also the screenshot of how I have my configuration of network settings in my VMWare Workstation, screenshot is called "screenshot1. the tutorial does not show how it has its editor of the virtual network configuration, but it puts its ESXi host NICs in BRIDGED mode, and I'm guessing that you can set this time within the virtual network adapter. If someone could tell me what changes should I make in there and on the network cards in my ESXi host, which would be really useful.

    screenshot1.JPG

    My domain controller, server ESXi hosts and vcenter are currently on the 192.168.86 range, which currently stood at NAT

    See also a screenshot from the vsphere client - I don't see a vmnic "vmnic0", my goal is to be able to add a "vmnic2" for a separate storage network.

    screenshot3 unable to add anymore vmnics.JPG

    any help would be received with gratitude, I VCP510 review at the end of the month and really hope to be able to get my lab setup as soon as possible.

    The vmnic is the rising 'physical' of an ESXi host. So with the 3 network cards that you configured for the host in VMware Workstation you will see under "Network adapters" and you can use them to vSwitches in the section "network".

    André

  • Mudbrick ESXi networking Visio templates

    Hi all

    I'm looking to find templates in Visio that I can use to show how our ESXi server is configured for networking.  I need icons/shapes to show groups/vmnic and distributed switches port mapped to physical/vmnic NIC.

    Thank you very much

    The only template used there is the NETWORK card, the rest can be easily build up to standard visio shapes and graphics manipulation.

    The NETWORK card is contained in the set of template that David has provided the link too.

Maybe you are looking for