| Unique Visitors |
Great, thanks!! Then I'll just need to make sure my switches and firewall will be properly configured..
(colo wild west/internet) (firewall) (pair of switches) (4 esxi hosts running the internal workload/management VMs and cloud consumption VMs)
I will just configure all of my internal VLAN IP ranges in the firewall, and then setup a firewall rule: to not scan any traffic that originates from VLAN K (vCDNI) , since this traffic will be secured by the automated vShield VM.
VLAN J and VLAN C will have the same gateway (the one assigned by my colo)..
Have a great weekend!
]]>Hi George, In that case one VLAN for Internet is fine. There is no need as far as I can see to separate them out. Given they are both considered the Internet, i.e. wild west. Provided your internal workloads and vCD Cells etc are still protected by firewall still of course.
]]>According to the diagram from the above pdf I (snapshot here: http://www.picpaste.com/Screen_Shot_2013-02-02_at… ), the right part shows one connection needed for the customer's workloads, and one connection needed for my cloud management workloads (where my central firewall sits)..
unless if im not interpreting the diagram correctly?
Keep up the great work!!
]]>Hi George, I think the guidelines are appropriate and I think you'd need to implement the VLANS as recommended to adhere to the design. When you mean co-locating inside a datacenter would your use case still be for public cloud? I guess you could reduce by one VLAND and have the hosts vmkernel port for management connect to the management network, which is quite common in public cloud implementations. But this would be a variation from what is recommended in the implementation guidelines and the decision would really be dependant on what your security requirements are. Given it's only the management vmkernel port that would be on the management VLAN ordinarily I wouldn't have a problem with that. But you need to consider all the security requirements and constraints before making a decision.
]]>Do you think that this design would require two separate VLAN connections if co-locating inside a datacenter, or it would be possible to have a single VLAN to the internet and still adhere to the design?
]]>