So, we are rebuilding our backup infrastructure in more segmented network, new AD domain etc. I got some good advise from @foggy in my first thread: Move Veeam to a new environment - poke a hole in my plan!
One thing I forgot to mention was since we are moving from NetApp storage (storage integrated snapshots) to Nutanix, we'll need to change transport mode. This requires some additional planning. According to Nutanix Best Practice for Veeam, NFS direct is strongly recommended. Network transport mode is only used if NFS direct fails for some reason.
Since we want to build more segments, or referred to as zones in VBR Infrastructure Hardening Guide. In that guide ESXi hosts, Proxy, Repos and Nutanix Control VM (CVM) should reside on the same network (page 16). I can see that this is of course for performance and reliability to not traverse a firewall.
Having Veeam Proxy/Repo, ESXi hosts and Nutanix CVM share same VLAN network is fine for us. Let's call it "Virtual Infra Network"
Question:
Can I place Veeam Management server and vCenter in their own network segment, "Virtual Management Network"? Also, Prism Central (Nutanix management) will be placed there.
Is this placement recommended from a security and performance perspective?
EDIT: For a diagram over the discussed setup, please see: https://imgur.com/wcLdTQv. I want to add an additional network for vCenter, VBR mgmt for exaple on 10.10.15.0/24 network.
Let me know if I am not clear!
Thanks!
