ESXi access from VMKernel network different from Management one

ESXi access from VMKernel network different from Management one


For a series of coincidences and after several tests I realized that in vSphere 6.x (but I would say also in 5.x) there is a curious case of backdoor of services without one having enabled them. In my case, as a client starts an SSH or management connection to ESXi host from Management VMkernel network interface if the client is on the same TCP/IP Address of another VMKernel portgroup (VMotion, FT but not Management type) the ESXi host VMkernel tries to reply from that interface. The result is that no connection could be established because of the first one remains in RCVD status.

So, every kind of VMkernel port group created in the default TCP/IP stack of ESXi host "magically" becomes management by enabling SSH access (if service is started & firewall open), TCP 902 for management, powercli access and so on.

The problem in addition to these unsafe and unwanted accesses by those who administer it, are also dangerous for a form of asymmetric routing that the VMKernel starts to do when it is in a condition as in the figure:

Non è stato fornito nessun testo alternativo per questa immagine


The only way to stop accessing from VMkernel port group is to set VMotion, FT in VMotion TCP/IP Stack.

 

ESXi management on network

192.168.195.114 from vswitch0 with dedicated vmnic0

VMotion network

192.168.208.155 from vswitch1 with dedicated vmnic1

SIM SALA BIM!

Non è stato fornito nessun testo alternativo per questa immagine
Non è stato fornito nessun testo alternativo per questa immagine


But what about vSphere Replication?

Same issue on Replication Network , where management has not been enabled

Non è stato fornito nessun testo alternativo per questa immagine



Non è stato fornito nessun testo alternativo per questa immagine

Davide Sitta

Solution Architect & Technical Account Manager

@-mail: d.sitta@lutech.it




 


Please recycle in case of obsolescence

To view or add a comment, sign in

More articles by Davide Sitta

  • Stacchiamoci dall'ombelico

    La PMI è pronta a staccarsi dall’ombelico? Oggi 7 Luglio 2022, sempre più IT manager si chiedono se per la loro azienda…

  • Cutting off the navel

    Is the #SME and #SMB ready to break away from the navel? Today 7 July 2022, more and more IT managers are wondering if…

  • VMware vSphere Phantom VMkernel Interface

    Hi everyone for another series of coincidences I found myself in spring 2019 to have a new surprise from the VMkernel…

    1 Comment
  • esserci sempre senza farlo sapere

    Tratto da una email di chi sa cosa vuol dire lavorare come system integrator. Le gratifiche che ti fanno pensare che…

    1 Comment
  • The show must go on with Cluster Data ONTAP systems

    http://www.netapp.

Others also viewed

Explore content categories