For both the VxRail stretched cluster and the VxRail 2-node cluster, the networks on the vSAN witness virtual appliance must be properly configured to ensure proper cluster operations.
You must follow these guidelines:
- The vSAN witness virtual appliance must be configured with two separate networks during deployment:
- One for management called the Management Network.
- One to support vSAN witness traffic called the Secondary Network.
- The IP address that is assigned for vSAN witness management on the Management Network must be reachable by the VMware vCenter Server instance supporting the VxRail cluster.
- The vSAN witness must be added to the VMware vCenter Server inventory as an ESXi host to support vSAN witness traffic with the VxRail cluster.
- Each VxRail node and the vSAN witness must be able to connect over the vSAN witness traffic network.
- An IP address is assigned to each VxRail node in the cluster to support vSAN witness network traffic.
- An IP address is assigned to the vSAN witness virtual appliance also to support vSAN witness network traffic on the Secondary Network.
Figure 63. Network relationships for vSAN witness and VxRail. Network relationships for vSAN witness and VxRail
- If it is a VxRail-managed VMware vCenter Server, then the vSAN management traffic on the Management Network must route to the VxRail-managed VMware Server network. VxRail Manager configures this network during the initial build process.
- For a 2-node cluster planned with only Layer 2 networking, and a VxRail-managed VMware vCenter Server, the IP address that is assigned for vSAN witness management must be in the VxRail-managed VMware vCenter Server network subnet range.
- If it is a customer-managed VMware vCenter Server instance, then the vSAN management traffic on the Management Network must to route to this VMware vCenter Server instance.
Figure 64. With or without Witness Traffic Separation network. With or without Witness Traffic Separation network. - If a Witness Traffic Separation (WTS) network is being planned for the VxRail cluster, then the vSAN witness traffic on the Secondary Network must be able to route to this network.
- If a Witness Traffic Separation (WTS) network is not being considered for the VxRail cluster, then the vSAN witness traffic on the Secondary Network must be able to route to the vSAN network planned for the VxRail cluster.