Recommended Posts

Hi All, 

 

I would like to be able to connect a VM to a tagged VLAN without the host machine being connected to that VLAN. 

 

My machine only has one NIC and all the networks I connect to are tagged VLANs associated with that NIC. 

 

If I add the tagged VLAN to the NIC I can connect the VM to that network correct however my machine is then in that network as well. 

 

Does anyone know if this is possible? I really hope that makes sense! 

 

Thanks in advance. 

Well the connection to your machines nic would have to be trunked for starters. The switch port your currently connected to is most likely access and only allows the vlan your physical nic is in.

Hi BudMan, 

 

The port that my NIC is in, is tagged in both of the VLANS. I can bring up the VLAN on my machine and connect my VM to it no problem, however I don't want my machine to be in that lan for various reasons. 

So port is trunked already and allows both, ok.

So in workstation can you tag say a vswitch like you can in esxi?

post-14624-0-13920000-1385477606.png

What virtual nic do you have setup, vmxnet3 should allow for vlan ID right on the nic

post-14624-0-76985800-1385477661.png

From a quick google with workstation it seems you need to make map it in network correctly, and you might have to uncheck deterministic or other options on the vm nic to see it in the mapping, check out this article

http://brandonjcarroll.com/blog/using-vlans-with-vmware-workstation

Hi Budman, 

 

You can't change the VLAN tagged on the vswitch like ESXi, I was hoping the same thing. 

 

I've had a look at the article but that would still put my machine in that LAN. For I've removed everything from the networking selection (unticked Internet Protocol Version 6 etc.) which looks like I can't connect to that network, and nothing from that network can connect to my machine, but the VM is working fine. I think this will work ok for now. 

 

Thank you Budman. 

Your physical nic is going to require the ability to add multiple vlan tags - as per the article, then can create different virtual networks and match them up with the specific vlans you want to run your vms on.

You might be able to get away with juts putting the tag on the virtual nic on your vm and bridging it to your physical nic that is in a different vlan.

That article shows how to run different vms under different vlans, ie more than 1 can be done. Your just needing 1 I take it - but still applies. What is the actual physical nic you have in your machine.. Does it it support the advanced features like multiple vlan tags on it?

My NIC is an Intel 82579LM and yes it does support VLAN tagging. That's how I'm currently doing it. When you add a new Tagged VLAN it created a new adaptor which needs to be enabled for you to use it via VMware workstation. 

 

I didn't have a problem getting the VM into the VLAN, the problem is I don't want my physical machine in that VLAN at all but it seems to be working correctly now. 

I think that is all you can do evoman91 - just untick the un-needed protocols and services in the properties of the virtual adapter like you said. It seems a bit of a messy way to do it though, don't you think? 

  • 1 year later...

After creating your vlan interfaces, then creating your VMware workstation bridge to the new adapters, go into the local adapter and disable ipv4 and ipv6.  Your computer will not have access via ipv4 n'or 6 to communicate on that network, but your vmware workstation will still be able to bridge over that nic to the vlan and IT has IPv4 or 6 and will function just fine.  So again... vmware workstation nic, IPv4 is left on and alone, Local PC nic that it's bridging through has NO IPv4 or 6 enabled.  Therefore, no local computer access.

This topic is now closed to further replies.
  • Posts

    • According to Microsoft, Cause: One of the drivers controlling the device notified the operating system that the device failed in some manner.   https://support.microsoft.com/en-us/topic/error-codes-in-device-manager-in-windows-524e9e89-4dee-8883-0afa-6bca0456324e
    • This looks awesome, I will request access via Steam later this afternoon!
    • Personally, I’ve found that it’s usually worth investing in the infrastructure you don’t want to replace later, especially cabling. Running Cat6A (or better, depending on your needs) during an upgrade is relatively inexpensive compared to having to re-cable a few years down the road. For switches I try to balance current specs with realistic growth. If my budget allows it Ill choose switches with higher uplink speeds which leaves room for expanding later on, but I don’t necessarily overspend on access ports if the endpoints won’t benefit from them anytime soon. One lesson I’ve learned is that planning for scalability pays off. It’s much easier to add devices, VLANs, or higher-bandwidth workloads when your network infrastructure already supports it than to replace hardware later.  What is your budget like?
    • I hate the term, "future-proof." We saw it back in the 90's / 2000's, if not before. You cannot future-proof anything, since there is no definition of how far into the future you plan on prepping for. Best idea is to tell us what you currently have and what its use is at the moment, and we can then offer ideas about some areas that might need an upgrade and other areas that can be left alone.
    • I can agree that it is being used in a small capacity. I worked for a company where their engineers still used XP, and when asked why it was because their sensor software wasn't compatible with newer operating systems and the software was discontinued so they couldn't upgrade the software. Given that the sensors were still in use by companies, they had to continue using XP to support the sensor, otherwise the price to the company would have gone into the millions or billions. Our response was simple: Ok, you can keep the XP machine. But we're removing it from the network. "But then it can't access the Internet or folder shares!" Yup, kinda the point. If someone wants to continue using an unsecure OS they can do, I have no problem with that. But it should be isolated. Simple. I had a fight with a guy in the engineering department for weeks before he finally relented. But we digress.   What do I plan on doing to commemorate the anniversary? Nothing. I have fond memories of the OS, but at the end of the day it's just an OS. If I had some time I might see if I could install it on my Raspberry Pi for a laugh. But my reflex memory with today's OS ideas would probably get me frustrated and I'd uninstall it after 5 mins.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      539
    2. 2
      +Edouard
      269
    3. 3
      PsYcHoKiLLa
      154
    4. 4
      Steven P.
      99
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!