How can I configure VLANs in SonicWall NSv GEN7 and above?

Description

This article outlines the steps required to configure VLANs on a SonicWall NSv using VMware/ESXi Virtual Switches.

To configure virtual interfaces on an NSv, the parent interface must be mapped to a VMware port group configured with VLAN ID 4095. The NSv treats a port group configured with VLAN 4095 as a trunk port, allowing it to process traffic from multiple VLANs.

 

Environment

The following environment was used when creating this article:

  • VMware ESXi 6.5
  • Windows Server 2016
  • SonicWall NSv on Classic mode

In this example, we will create two virtual interfaces, X0:V100 and X0:V200, with X0 configured as the parent interface.

Resolution

1.- Add 2 virtual interfaces, one for each VLAN. 

Go to Network | System | Interfaces | Add Interfaces |  Virtual Interface. 

Set up the Interface Settings per your requirement. 

In this case, X0:V100 interface is configured with an IP address of 172.16.100.1/24.

Same for V200, X0:V200 interface is configured with an IP address of 172.16.200.1/24.
 

2. Create three Port Groups in VMware: 

One Port Group for VLAN 100 
One Port Group for VLAN 200
One Trunk Port Group configured with VLAN ID 4095

Note: The NSv parent interface should be connected to the Trunk Port Group (VLAN 4095), while virtual machines can be connected to the VLAN 100 or VLAN 200 Port Groups as required.

TIP: Information in setting up a Virtual Network, Virtual Switches and Port Groups can be found here: Virtual Networking in SonicWall NS𝘷.

 Port Group for X0:V100 network is set up as follows

 Both the Virtual Interfaces are created successfully on the NS𝘷. Port Groups for X0:V100 and X0:V200 need to be created on the Virtual Switch, so that they can be bound to the network adapters of the Virtual Machines (Windows Server) in the network. A Port Group is a essentially group of ports on a vSwitch, created to provide logical segmentation. A Port Group connects to a vSwitch, and a vSwitch connects to a physical network interface.  

Port Group for X0:V200 network is set up as follows

A dedicated Trunk Port Group must be created to allow the NSv to receive both tagged and untagged traffic on the X0 interface. In VMware ESXi, configuring a Port Group with VLAN ID 4095 enables trunk mode, allowing all VLAN-tagged traffic to pass through to the guest virtual machine.


3.- Create the DHCP Server on the NS𝘷 for Interfaces, X0, X0:V100 and X0:V200 

Go to under Network | System | DHCP Server.

TIP: Configuring the DHCP Server on the SonicWall 


 

4.- Assign the network adapter to the Trunk Port Group (VLAN ID 4095) and verify that traffic for all configured VLANs is correctly forwarded to the NSv.

Trunk Port Group must be assigned to the Network Adapter 1 (X0 Interface) of the NS𝘷.

 

5.- To verify that the trunk port is functioning correctly, assign the X0, X0:V100, and X0:V200 Port Groups to the Windows Server network adapter one at a time. 

X0: V100 Port Group is assigned to the Network Adapter of the Windows Server.

 

  Port Group X0: V200 is assigned to the Network Adapter of the Windows Server.

 

 

DHCP Troubleshooting:

After running ipconfig /release followed by ipconfig /renew on the Windows Server, the DHCP DORA (Discover, Offer, Request, Acknowledgment) process should be visible on the SonicWall when a packet monitor is configured to capture UDP ports 67 and 68.

 

Image

        TIP: Further reading for ESXi Networking Configurations:

      Create a vSphere Standard Switch, Edit a Standard Switch Port Group, About vSphere Networking

      Related Articles

      • Troubleshoot steps if a firewall status is Offline on NSM SaaS
        Read More
      • Microsoft Teams randomly dropping (Video conferencing applications)
        Read More
      • Key exchange (DH) Groups Supported - Site to Site VPN
        Read More
      not finding your answers?