Bolt-On Security for Virtual Servers

Virtualization security planning done at every step of design and implementation will help you handle key issues including data co-mingling, network attack prevention, forensics, auditing, disaster recovery, and business continuity.

By Edward L. Haletky, CIO.com,

What's the problem with bolt-on security for virtual servers and virtual environments? Too many people forget that VMware Virtual Infrastructure 3 (VI3) is the entire virtual environment (VE). Granted the core is VMware ESX, VMware ESXi, and can include VMware Server, but it is much more than that. Let's consider the many pieces of your enterprise that must be examined as you secure virtualization.

VI3 includes VMware Clustering, and independent hosts incorporating such items as VMware Dynamic Resource Scheduling (DRS), VMware High Availability (HA), VMotion, and Storage VMotion.

Then there's the storage technology in use in your enterprise, whether it's local storage or remote storage such as iSCSI, NFS over NAS, or SAN physical devices, or the Lefthand Networks Virtual SAN Appliance. Once we discuss storage, we need to discuss how virtual machines access the storage, whether using virtual machine disk files, using raw disk maps to logical units (LUNs) presented to the virtualization host, using iSCSI initiators within the VM, accessing a NAS or SAN directly via the network, or using Fibre Channel N_Port ID Virtualization.

If a network is involved, which is almost always the case, we need to discuss the networks involved and how VMs are accessed. Are the virtual machines accessed via a DMZ? Via production, administrative, or test networks? Are the VMs communicated with using some form of special application, VPN, SSL Tunnel, RDP, Virtual Desktop Infrastructure (VDI), or the remote console over the web of the VMware Virtual Infrastructure Client?

In order to create and manage VMs, we now add into the mix the question of how you manage the entire environment, whether via something that uses the VMware SDK, VIC connected to Virtual Center, or even a single host, VMware Lab Manager, VMware Life Cycle Manager, or via the remains of the full service console.

All of this is just a brief view of what comprises the virtual environment, whether you're using technology from VMware or other vendors. Virtualization security is needed every step of the way. It is possible to bolt-on security after the environment is deployed, but that is just a stop gap solution at best. Security should be considered from the very beginning of a virtual infrastructure deployment.

Remember, virtual security applies not only to the virtual environment but also to what touches or interfaces with the environment, including firewalls, routers, gateways, intrusion detection and prevention systems (IDS/IPS), storage and switch fabrics. Included in switch fabrics are VLANs and NPIV.

Virtualization security planning done at every step of design and implementation will help you handle key issues including data co-mingling, network attack prevention, forensics, auditing, disaster recovery, and business continuity.

That's why when you think virtual security, you must think far beyond ESX server.

Virtualization expert Edward L. Haletky is the author of "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers," Pearson Education (2008.) He recently left Hewlett-Packard, where he worked in the Virtualization, Linux, and High-Performance Technical Computing teams. Haletky owns AstroArch Consulting, providing virtualization, security, and network consulting and development. Haletky is also a champion and moderator for the VMware discussion forums, providing answers to security and configuration questions.

Copyright © 2008 IDG. All rights reserved.

Related Articles
Regional Articles
- Bolt-On Security for Virtual Servers Alabama
- Bolt-On Security for Virtual Servers Alaska
- Bolt-On Security for Virtual Servers Arizona
- Bolt-On Security for Virtual Servers Arkansas
- Bolt-On Security for Virtual Servers California
- Bolt-On Security for Virtual Servers Colorado
- Bolt-On Security for Virtual Servers Connecticut
- Bolt-On Security for Virtual Servers DC
- Bolt-On Security for Virtual Servers Delaware
- Bolt-On Security for Virtual Servers Florida
- Bolt-On Security for Virtual Servers Georgia
- Bolt-On Security for Virtual Servers Hawaii
- Bolt-On Security for Virtual Servers Idaho
- Bolt-On Security for Virtual Servers Illinois
- Bolt-On Security for Virtual Servers Indiana
- Bolt-On Security for Virtual Servers Iowa
- Bolt-On Security for Virtual Servers Kansas
- Bolt-On Security for Virtual Servers Kentucky
- Bolt-On Security for Virtual Servers Louisiana
- Bolt-On Security for Virtual Servers Maine
- Bolt-On Security for Virtual Servers Maryland
- Bolt-On Security for Virtual Servers Massachusetts
- Bolt-On Security for Virtual Servers Michigan
- Bolt-On Security for Virtual Servers Minnesota
- Bolt-On Security for Virtual Servers Mississippi
- Bolt-On Security for Virtual Servers Missouri
- Bolt-On Security for Virtual Servers Montana
- Bolt-On Security for Virtual Servers Nebraska
- Bolt-On Security for Virtual Servers Nevada
- Bolt-On Security for Virtual Servers New Hampshire
- Bolt-On Security for Virtual Servers New Jersey
- Bolt-On Security for Virtual Servers New Mexico
- Bolt-On Security for Virtual Servers New York
- Bolt-On Security for Virtual Servers North Carolina
- Bolt-On Security for Virtual Servers North Dakota
- Bolt-On Security for Virtual Servers Ohio
- Bolt-On Security for Virtual Servers Oklahoma
- Bolt-On Security for Virtual Servers Oregon
- Bolt-On Security for Virtual Servers Pennsylvania
- Bolt-On Security for Virtual Servers Rhode Island
- Bolt-On Security for Virtual Servers South Carolina
- Bolt-On Security for Virtual Servers South Dakota
- Bolt-On Security for Virtual Servers Tennessee
- Bolt-On Security for Virtual Servers Texas
- Bolt-On Security for Virtual Servers Utah
- Bolt-On Security for Virtual Servers Vermont
- Bolt-On Security for Virtual Servers Virginia
- Bolt-On Security for Virtual Servers Washington
- Bolt-On Security for Virtual Servers West Virginia
- Bolt-On Security for Virtual Servers Wisconsin
- Bolt-On Security for Virtual Servers Wyoming
Related Articles
- Choosing the Correct Web Hosting Service
Choice of web server will be one of the most important decisions you ever make with your online business. Why? Because the web server you choose will do, literally or break your online business.
- Steps to Safer Virtual Servers
- Virtual Machines May Pose New Threats
- OpenVZ / Virtuozzo
- Auditing and Improving Virtual Server Security
- Virtual Fax
- Virtual Servers Within the DMZ Networks
- IT Security Information
- Hosting Types
- Tips for Increasing Virtual Machines

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History