Setting it with a new vSwitch that is connected to a VMNIC which is in turn connected to your DMZ switch will be just fine. VMs on two different vSwitches can't communicate unless the traffic is routed between the two vSwitches. That routing could be a router VM connected to both vSwitches or a physical router on your network. But otherwise ESXi won't pass traffic between the vSwitches.
↧