Browse this section

Separating management, application and backup networks

Network design should make it clear which systems may communicate and who may administer them. Separating management, application and backup traffic can make access policies easier to maintain, but a network label or VLAN alone is not a complete security control.

Prepare a network inventory

  • List each network, address range, gateway and the systems that need to use it; avoid overlapping ranges with existing sites or VPNs.
  • Identify management interfaces and restrict their access to approved administrators and trusted access paths.
  • Document required application flows by source, destination, protocol and port.
  • Specify backup and migration traffic, routing requirements and any expected bandwidth peaks.

Review firewall and routing changes as one coordinated operation. Test permitted traffic and blocked traffic after deployment, and keep an emergency access method available. Include your current network diagram with a configuration request when possible.

Was this guide helpful?

Related guides

When to choose a managed private cloud

A private cloud can help organise multiple virtual machines on a planned cluster, with shared operational controls and capacity management. It is most useful when the environment needs to b…

Understanding usable capacity in a vSAN cluster

Raw drive capacity is not the same as space available to virtual machines in a distributed storage cluster. Protection policies, layout, metadata, operational reserves and rebuild requireme…

Requesting virtual-machine changes safely

A request to change a virtual machine should identify both the new resource requirement and the effect on the application. Some changes can be made online in certain environments, while oth…

Need help applying this to your service?

Tell us your service reference and what you need to achieve. Never include passwords or private keys in a ticket.

Contact support →
← All knowledgebase topics