Configuring network isolation

As a rule, all storage traffic, regardless of the medium or protocol used, should be isolated from any and all management or client network traffic. The IP network segmentation should employ separate physical switches where possible. If a shared physical switch is used, then a VLAN should be used to isolate the iSCSI traffic from all other network traffic on the network. IP Security (IPSEC) is currently not supported for IPv4 iSCSI traffic.

We'll configure a separate vSwitch for iSCSI traffic, which is always the preferred method to isolate storage traffic and prevent commingling with management and VM network traffic.

Getting ready

In order to proceed, we require access to vSphere Web Client. The client can be run on ...

Get VMware vSphere Security Cookbook now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.