Hi Bill,
You are a genius. You've just solved the mystery to my config problems.
1) You mentioned about isolating one of the NIC from the host machine. How
do I configure the isolation? I looked at the property settings and does see
"VMWARE Bridge Protocol". Is this what you were referring to? If so, I
would just uncheck everything else... including TCP/IP Protocol? Is this
what you were referring to?
Also, I am confused at the comment where you mentioned "to avoid the
possibility of BYPASSING the ISA Firewall". Could you please clarify the
"bypassing" term when referring to the ISA and the HOST?
2) I clearly understood about one of the NIC is in the same IP subnet as the
other
machines on switch1. You mentioned it does not have an IP address on the
host machine. So do I just leave it blank in the auto detect mode for both
IP and DNS?
Thanks a million!
--
Regards,
Andy
"Bill Grant" wrote:
> Combining this info with the diagram you posted in the
> public.virtualserver NG, I am beginning to see what you want to do.
>
> If you have a NIC in each host machine which is plugged into a port on
> your internal switch (switch2 in your diagram) and link the NICs on your vm
> guest machines to this network, they should all be able to communicate
> because, from a networking point of view, they are all in the same segment.
> The virtual machines will behave just like additional machines plugged into
> the switch. You cannot use a loopback adapter in this case, because you need
> to be able link virtual machines which are running on a different host. (Any
> other physical machines plugged into this switch will also be reachable).
>
> To access the Internet these machines would use the ISA server vm. This
> machine would have its "public" NIC connected to switch1. This NIC would be
> isolated from the host machine (as discussed in another posting) to avoid
> the possibility of bypassing the ISA firewall.
>
> With this setup, all of the machines actually plugged into switch2 and
> all of the vms with one NIC will be in your private network. They will
> access the Internet through ISA server running in one vm, which is connected
> to the Internet via switch1. This NIC is in the same IP subnet as the other
> machines on switch1. It does not have an IP address on the host machine.
>
>
>
|