The vSAN witness appliance contains a special ESXi installation that provides quorum and tiebreaker services for stretched clusters in a VI workload domain of VMware Cloud Foundation.
vSAN Witness Deployment Specification
Appliance Size |
Supported Capacity |
Number of vCPUs |
Memory |
Storage |
---|---|---|---|---|
Tiny |
Supports up to 10 virtual machines and 750 witness components |
2 |
8 GB |
The appliance has three virtual disks.
|
Medium |
Supports up to 500 virtual machines and 21,000 witness components |
2 |
16 GB |
The appliance has three virtual disks.
|
Large |
Supports over 500 virtual machines and 45,000 witness components |
2 |
32 GB |
The appliance has five virtual disks.
|
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
VCF-WLD-vSAN-WTN-001 |
Deploy a vSAN witness appliance in a location that is not local to the ESXi hosts in any of the availability zones of the VI workload domain. |
The witness appliance has these features.
|
A third physically-separate location is required. Such a location must have a vSphere environment running to host the witness appliance. Another VMware Cloud Foundation Instance in a separate physical location might be an option. |
VCF-WLD-vSAN-WTN-002 |
Deploy a large-size witness appliance. |
A large-size witness appliance supports more than 500 virtual machines which is required for high availability of workloads that run in the SDDC. |
The vSphere environment at the witness location must satisfy the resource requirements of the witness appliance. |
vSAN Witness Network Design
When using two availability zones, to be able to communicate to the vCenter Server instance, connect the vSAN witness appliance for the VI workload domain to a network that is routed to the management network of the management domain in the first availability zone.
VMware Cloud Foundation uses vSAN witness traffic separation where you can use a VMkernel adapter for vSAN witness traffic that is different from the adapter for vSAN data traffic. You configure vSAN witness traffic in the following way:
On each ESXi host in both availability zones, place the vSAN witness traffic on the management VMkernel adapter.
On the vSAN witness appliance, use the same VMkernel adapter for both management and witness traffic. This VMkernel adapter is connected to a network that is routed to the management networks of the management domain and the VI workload domain in both availability zones.
For information about vSAN witness traffic separation, see vSAN Stretched Cluster Guide on VMware Cloud Platform Tech Zone.
- Management Network
-
Routed to the management networks of the management domain and the VI workload domain in both availability zones. Connect the first VMkernel adapter of the vSAN witness appliance to this network. The second VMkernel adapter on the vSAN witness appliance is not used.
Place the following traffic on this network:
Management traffic
To be able to communicate to the vCenter Server instance, the vSAN witness appliance for the VI workload domain must be routed to the management network in Availability Zone 1.
vSAN witness traffic
Decision ID |
Design Decision |
Design Justification |
Design Implication |
---|---|---|---|
VCF-WLD-vSAN-WTN-003 |
Connect the first VMkernel adapter of the vSAN witness appliance to the management network in the witness site. |
Connects the witness appliance to the vCenter server instance and ESXi hosts in the VI workload domain. |
The management networks of both the management and VI workload domains in both availability zones must be routed to the management network in the witness site. |
VCF-WLD-vSAN-WTN-004 |
Configure the vSAN witness appliance to use the first VMkernel adapter, that is the management Interface, for vSAN witness traffic. |
Separates the witness traffic from the vSAN data traffic. Witness traffic separation provides the following benefits:
|
The management networks for both the management and VI workload domains in both availability zones must be routed to the management network in the witness site. |
VCF-WLD-vSAN-WTN-005 |
Place witness traffic on the management VMkernel adapter of all the ESXi hosts in the VI workload domain. |
Separates the witness traffic from the vSAN data traffic. Witness traffic separation provides the following benefits:
|
The management networks for both the management and VI workload domains in both availability zones must be routed to the management network in the witness site. |
VCF-WLD-vSAN-WTN-006 |
Allocate a statically assigned IP address and host name to the management adapter of the vSAN witness appliance. |
Simplifies maintenance and tracking and implements a DNS configuration. |
Requires precise IP address management. |
VCF-WLD-vSAN-WTN-007 |
Configure forward and reverse DNS records for the vSAN witness appliance assigning the record to the child domain for the VMware Cloud Foundation instance. |
Enables connecting the vSAN witness appliance to the VI workload domain vCenter Server by FQDN instead of by IP address. |
You must provide DNS records for the vSAN witness appliance. |
VCF-WLD-vSAN-WTN-008 |
Configure time synchronization by using an internal NTP time for the vSAN witness appliance. |
Prevents any failures in the stretched cluster configuration that are caused by time mismatch between the vSAN witness appliance and the ESXi hosts in both availability zones and VI workload domain vCenter Server. |
|