Avoid high-risk data comingling with VMware virtual networks to prevent security vulnerabilities

Running VMware in an environment that involves converged networks causes data comingling, which, although intrinsically harmless, can be harmful if the wrong data is comingled. Network convergence happens because not many people use 100% of a 10 Gigabit Ethernet network bandwidth; many people do not even use the full bandwidth of a 1 Gigabit Ethernet link. The goal is to use the unused bandwidth for other aspects of networking as laying new cable is often not possible due to a lack of network interface cards (NICs), and it's expensive and time consuming.

The simple solution is to often run more over the wire than just one item, also known as data comingling. Data comingling is not a security issue per say, as long as the data on the wire shares the same classification level and security zone. Data comingling can become a problem, however, when data on the same wire isn't of the same classification level and security zone.

Classification levels define who can see any data that lives on the wire, while security zones cover to where the wire is connected and possibly how it is used. For example, a DMZ tends to be a hostile environment compared to the security zone named production. Comingling the data in these two zones will raise the level of risk that normally exists without data comingling on a converged network. .