Isolation based on Security Groups in Advanced Zone - VMWare Hypervisor

1       Background

Isolation of VM Traffic is achieved using Security Groups in Basic Zones. For Advanced zone, traffic can be isolated on a per network basis using VLANs.  Advanced Zones support shared as well as isolated networks.  Currently, there is no way to isolate guest traffic within a network. There is another similar requirements document for SG support in advanced zone for XS and KVM.

For VMWare Hypervisor, since the classic SG support can't be added, one of the solutions would be to support PVLANs (Private VLANs) for this solution.

Use Cases:

Customer Benefits:

2        Requirements

4       Upgrade Scenarios

There are no upgrade requirements as this would be a new feature.

5       Non-Requirements

6       Bugs

7       References: