| Unique Visitors |
Hi Fo, It's not the vNIC driver that does this, it's SRM doing it via VIX. It's just changing the IP address inside the Guest OS when the VM is recovered and powered on at the recovery site, which is in a different IP subnet. This is not necessary with stretched layer 2, but many companies don't have that available and do need to change IP's. vSwitch Security configuration also needs to be taken into account.
]]>Hi Fo, We do have a safe an reliable IP change service via VIX. Provided the proper security controls around it's use are implemented. It's also possible via vCenter Customization Scripts.
]]>I am unsure whether it is good to let the vNIC driver having the capability of changing IP by responding to fail over requirements from SRM.
]]>Hi Dave, I agree. However external auditors and organizations without full knowledge of the impact often make the call as to which recommendations must be applied. Also it is often a requirement to meet certain regulations. In these situations there may be little room to maneuver. Then there is the fact that it's the vSphere Hardening Guide, and doesn't take into account other VMware Products. I will ask VMware to include a note re breaking SRM functionality with this particular recommendation though, given it's now well known.
]]>I have to agree, DHCP is a very effective way to address the IP change. I've just completed a deployment with one of my customers doing just that across a multi-tier SAP implementation. DHCP spoofing is certainly a risk but if a company is that concerned about security they would have a lot of other measures in place to help mitigate that risk. But then that said I'm not a security expert !!
]]>