<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Segmentation for VMware workloads in VMware Solutions Discussions</title>
    <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133649#M9049</link>
    <description>&lt;P&gt;Hi there, we have been using our NetAPP FIler FAS for a couple of years, and I'm looking on design ideas on how we can include this new usecase. &amp;nbsp;We have a customer coming in that will want 4 different envrionments with similar applications in each envrionment. &amp;nbsp;We are going to use portgroups/vlans on that segment to have them access their volumes on netapp. &amp;nbsp;I think we will have both NFS mounts for Oracle filesystems, and they will also have some CIFS shares. &amp;nbsp;I believe that the current NFS is v3. &amp;nbsp;So I"m trying to come up with an architecture where each envrionment can access file mounts on the NetAPP for access. &amp;nbsp;I thought about using SVM, but I'm wondering if that is overkill for what I'm trying to protect against. &amp;nbsp;We will still end up managing these netapp volumes, so they will not have separate admins on each volume.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that I could do it with firewall rules so that all traffic leaving the segement in vSphere can only talk to a particular LIF on the NetAPP. &amp;nbsp;Then we could use export policies for the NFS workload, and the for CIFS, there would have to be access based on which envrionment the request is coming from. &amp;nbsp;I believe they will have an AD per envrionment, so that will make it easy. &amp;nbsp;&lt;/P&gt;&lt;P&gt;When I talk about protecting against...my concerns are that vms in one environment can not mount shares/volumes on the wrong netapp mount point. &amp;nbsp;I don't want development &amp;nbsp;vms writing to production data on NetAPP. &amp;nbsp;I want to keep to policies pretty generic so that I don't have to do much on the vms(if possible). &amp;nbsp;I would like to hear what are some of the better ways to control access into a netAPP from a multi-tenant VMware envrionment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I've tried ot provide a rough picture of how it would look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Sony,&lt;/P&gt;</description>
    <pubDate>Wed, 16 Aug 2017 14:55:55 GMT</pubDate>
    <dc:creator>sonyf</dc:creator>
    <dc:date>2017-08-16T14:55:55Z</dc:date>
    <item>
      <title>Segmentation for VMware workloads</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133649#M9049</link>
      <description>&lt;P&gt;Hi there, we have been using our NetAPP FIler FAS for a couple of years, and I'm looking on design ideas on how we can include this new usecase. &amp;nbsp;We have a customer coming in that will want 4 different envrionments with similar applications in each envrionment. &amp;nbsp;We are going to use portgroups/vlans on that segment to have them access their volumes on netapp. &amp;nbsp;I think we will have both NFS mounts for Oracle filesystems, and they will also have some CIFS shares. &amp;nbsp;I believe that the current NFS is v3. &amp;nbsp;So I"m trying to come up with an architecture where each envrionment can access file mounts on the NetAPP for access. &amp;nbsp;I thought about using SVM, but I'm wondering if that is overkill for what I'm trying to protect against. &amp;nbsp;We will still end up managing these netapp volumes, so they will not have separate admins on each volume.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that I could do it with firewall rules so that all traffic leaving the segement in vSphere can only talk to a particular LIF on the NetAPP. &amp;nbsp;Then we could use export policies for the NFS workload, and the for CIFS, there would have to be access based on which envrionment the request is coming from. &amp;nbsp;I believe they will have an AD per envrionment, so that will make it easy. &amp;nbsp;&lt;/P&gt;&lt;P&gt;When I talk about protecting against...my concerns are that vms in one environment can not mount shares/volumes on the wrong netapp mount point. &amp;nbsp;I don't want development &amp;nbsp;vms writing to production data on NetAPP. &amp;nbsp;I want to keep to policies pretty generic so that I don't have to do much on the vms(if possible). &amp;nbsp;I would like to hear what are some of the better ways to control access into a netAPP from a multi-tenant VMware envrionment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I've tried ot provide a rough picture of how it would look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Sony,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 14:55:55 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133649#M9049</guid>
      <dc:creator>sonyf</dc:creator>
      <dc:date>2017-08-16T14:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Segmentation for VMware workloads</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133654#M9050</link>
      <description>&lt;P&gt;If each "environment" has a different AD domain, then you will need multiple SVMs. &amp;nbsp;Beyond that, assuming each environment is using a different subnet, configure the export rules to only allow connections from the appropriate subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 15:26:28 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133654#M9050</guid>
      <dc:creator>asulliva</dc:creator>
      <dc:date>2017-08-16T15:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Segmentation for VMware workloads</title>
      <link>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133674#M9052</link>
      <description>&lt;P&gt;Andrew,&lt;/P&gt;&lt;P&gt;Thanks for the response. &amp;nbsp;So if we have different ADs for each env, then we should segment by SVM. &amp;nbsp;Otherwise, if we are just talkng about NFS mounts, and a single AD environment, then we could get a way with a single SVM. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Sony,&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 02:23:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/VMware-Solutions-Discussions/Segmentation-for-VMware-workloads/m-p/133674#M9052</guid>
      <dc:creator>sonyf</dc:creator>
      <dc:date>2017-08-17T02:23:39Z</dc:date>
    </item>
  </channel>
</rss>

