Isolation in Advanced Zone using PVLANs

1       Background

Isolation of VM Traffic is achieved using Security Groups in Basic Zones. For Advanced zone, traffic can be isolated on a per network basis using VLANs.  Advanced Zones support shared as well as isolated networks.  Currently, there is no way to isolate guest traffic within a network. There is another similar requirements document for SG support in advanced zone for XS and KVM.

Another way of supporting isolation within a guest network is using PVLANs. This requirements document captures the requirement related to adding PVLAN support. For VMWare Hypervisor, since the classic SG support can't be added, one of the solutions would be to support PVLANs (Private VLANs) for this solution.

Customers / Users have asked for the following requirements across all Hypervisors.

Use Cases:

The most common requirement is for customers to run multiple Shared Networks to offer various services like monitoring, patching, etc. Although, not all of the requirements can be met with PVLAN support, this basic requirement could be addressed with CS enabling the PVLAN support.

Customer Benefits:

2        Requirements

4       Upgrade Scenarios

There are no upgrade requirements as this would be a new feature.

5       Non-Requirements

6       Bugs

7       References: