SlideShare uma empresa Scribd logo
1 de 10
VMware Overview and
                  Security




11/12/2009                         1
Today’s Discussion
             Today’s

 Early Successes in Virtualization



 Current Virtualization Environment



 Overview of Virtual Environment Security


11/12/2009                                  2
Early Successes With Virtual
                    Implementations
      VDI                 VDI – WAH                                    VDI
                                                   SHACK
    External               Sun Ray                                   Internal
•   Security          •   Security            •   Performance   •   Security
•   Speed to market   •   Cost Savings        •   DR            •   Performance
•   Scalability       •   Improved            •   Scalability   •   Speed to market
                          Support structure




11/12/2009                                                                        3
Virtual Infrastructure

         Software                        Hardware
    Technologies Utilized           Technologies Utilized
    Vmware Virtual Infrastructure        EMC Clarion SAN

              Vmware ESX 3.5        Dell PowerEdge R900 Servers
       Virtual Center Server 2.5           Sun Ray DTUs
             Quest Provision VAS           Desktop PCs
                Sun Ray DVI




11/12/2009                                                        4
ESX 3.5 Host Hardware & Connectivity


                                                                       Service
                                                                       Console
                                            Service Console Network
                               4 Port NIC




                                               vMotion Network        vMotion
                                                                         VM
                               2 Port NIC                             Producton




                                            VM Production Network
        Dell PowerEdge R900    2 Port NIC
               ESX 3.5                                                Storage
        4 X 8 Core Processor
          128 GB Memory

                                               SAN Fibre Switch
                               2 Port HBA




11/12/2009                                                                        5
Datacenter


                                 Cluster       DRS     HA



    Current                                  DEV Cluster                      VMware
                                                           DEV HOST 1
                                                                              ESX 3.5

 Virtual Center                                                           DEV HOST 2
                                                                                            VMware
                                                                                            ESX 3.5
   Structure                                                                            DEV HOST 3
                                                                                                          VMware
                                                                                                          ESX 3.5

                                                                                                                    VMware
                                                                                                      DEV HOST 4
                                                                                                                    ESX 3.5


                  Datacenter

                                                DRS    HA
                                 Cluster


                                             VDI Cluster                      VMware
                                                           VDI HOST 1
                                                                              ESX 3.5

                                                                                            VMware
                                                                          VDI HOST 2
                                                                                            ESX 3.5

                                                                                                          VMware
                                                                                        VDI HOST 3
                                                                                                          ESX 3.5

                                                                                                                    VMware
                                                                                                      VDI HOST 4
                                                                                                                    ESX 3.5


                                                DRS    HA
                                 Cluster


                                             PROD Cluster                     VMware
                                                       PROD HOST 3
                                                                              ESX 3.5

                                                                                            VMware
                                                                        PROD HOST 4
                                                                                            ESX 3.5
                                                 VMware
                               PROD HOST 1
                                                 ESX 3.5                                                  VMware
                                                                                       PROD HOST 5
                                                                                                          ESX 3.5
                                                                VMware
                                             PROD HOST 2
                                                                ESX 3.5
                                                                                                     PROD HOST 6    VMware
                                                                                                                    ESX 3.5


                                                DRS        HA
                                 Cluster


                                             SHACK Cluster                   VMware
                                                      SHACK HOST 1
                                                                             ESX 3.5

                                                                                            VMware
                                                                        SHACK HOST 2
                                                                                            ESX 3.5
11/12/2009                                                                                                                    6
Virtualization Security Overview

  Virtual Machine Security



  ESX Host & Service Console Security



  Virtual Network Security



11/12/2009                              7
Virtual Machine Specific Security

      The physical applies in the virtual
      Remove unneeded virtual devices
      Use templates to deploy virtual machines
      Use native RDP rather than the virtual center console
      Storage permissions
      Persistent vs. non-persistent
      Enforce physical machine & remote console isolation




11/12/2009                                                    8
ESX & Console Security

      Base security steps:
             Restrict root privileges
             Use strong passwords
             Firewall restriction
             Limit services running in the service console
             Patch the ESX in accordance with your security policy
             Use of Virtual center to manage
      Configure SAN Storage correctly




11/12/2009                                                           9
Virtual Network Security

      Segregate network communications
      Ensure proper vSwitch settings
      Aim for consistency and compatible settings from physical
      network devices to virtual.




11/12/2009                                                        10

Mais conteúdo relacionado

Mais procurados

Hyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and TricksHyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and Tricks
Amit Gatenyo
 

Mais procurados (20)

VMware vSphere 5 seminar
VMware vSphere 5 seminarVMware vSphere 5 seminar
VMware vSphere 5 seminar
 
VMware vSphere5.1 Training
VMware vSphere5.1 TrainingVMware vSphere5.1 Training
VMware vSphere5.1 Training
 
Transitioning to vmWare ESXi
Transitioning to vmWare ESXiTransitioning to vmWare ESXi
Transitioning to vmWare ESXi
 
Xen server 6.1 customer presentation
Xen server 6.1 customer presentationXen server 6.1 customer presentation
Xen server 6.1 customer presentation
 
Vm6
Vm6 Vm6
Vm6
 
VMware vSphere Version Comparison 4.0 to 6.5
VMware  vSphere Version Comparison 4.0 to 6.5VMware  vSphere Version Comparison 4.0 to 6.5
VMware vSphere Version Comparison 4.0 to 6.5
 
Presentation disaster recovery in virtualization and cloud
Presentation   disaster recovery in virtualization and cloudPresentation   disaster recovery in virtualization and cloud
Presentation disaster recovery in virtualization and cloud
 
XenServer, Hyper-V, and ESXi - Architecture, API, and Coding
XenServer, Hyper-V, and ESXi -  Architecture, API, and CodingXenServer, Hyper-V, and ESXi -  Architecture, API, and Coding
XenServer, Hyper-V, and ESXi - Architecture, API, and Coding
 
VMware vSphere
VMware vSphereVMware vSphere
VMware vSphere
 
VMware HA deep Dive
VMware HA deep DiveVMware HA deep Dive
VMware HA deep Dive
 
ESX Server from VMware
ESX Server from VMwareESX Server from VMware
ESX Server from VMware
 
Virtualization Questions
Virtualization QuestionsVirtualization Questions
Virtualization Questions
 
Managing ESXi - Tools and Techniques
Managing ESXi - Tools and TechniquesManaging ESXi - Tools and Techniques
Managing ESXi - Tools and Techniques
 
V mware v sphere 5 fundamentals services kit
V mware v sphere 5 fundamentals services kitV mware v sphere 5 fundamentals services kit
V mware v sphere 5 fundamentals services kit
 
How to Optimize Microsoft Hyper-V Failover Cluster and Double Performance
How to Optimize Microsoft Hyper-V Failover Cluster and Double PerformanceHow to Optimize Microsoft Hyper-V Failover Cluster and Double Performance
How to Optimize Microsoft Hyper-V Failover Cluster and Double Performance
 
XS Oracle 2009 Intro Slides
XS Oracle 2009 Intro SlidesXS Oracle 2009 Intro Slides
XS Oracle 2009 Intro Slides
 
Hyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and TricksHyper-V Best Practices & Tips and Tricks
Hyper-V Best Practices & Tips and Tricks
 
VMware Advance Troubleshooting Workshop - Day 5
VMware Advance Troubleshooting Workshop - Day 5VMware Advance Troubleshooting Workshop - Day 5
VMware Advance Troubleshooting Workshop - Day 5
 
Introduction - vSphere 5 High Availability (HA)
Introduction - vSphere 5 High Availability (HA)Introduction - vSphere 5 High Availability (HA)
Introduction - vSphere 5 High Availability (HA)
 
XS Oracle 2009 Vm Snapshots
XS Oracle 2009 Vm SnapshotsXS Oracle 2009 Vm Snapshots
XS Oracle 2009 Vm Snapshots
 

Destaque

Cisco Confronts Microsoft Wi 172534
Cisco Confronts Microsoft Wi 172534Cisco Confronts Microsoft Wi 172534
Cisco Confronts Microsoft Wi 172534
bostomk
 
Alevizou et al Oer10 Presentation
Alevizou et al Oer10 PresentationAlevizou et al Oer10 Presentation
Alevizou et al Oer10 Presentation
Open University
 
Network Learning pres_Aborg 4 May 2010
Network Learning pres_Aborg 4 May 2010Network Learning pres_Aborg 4 May 2010
Network Learning pres_Aborg 4 May 2010
Open University
 

Destaque (14)

Computerizing Farmers Co-ops
Computerizing Farmers Co-opsComputerizing Farmers Co-ops
Computerizing Farmers Co-ops
 
Master Presentation
Master PresentationMaster Presentation
Master Presentation
 
Sweetpotato Knowledge Portal Brief Ver 2 20121022
Sweetpotato Knowledge Portal Brief Ver 2 20121022Sweetpotato Knowledge Portal Brief Ver 2 20121022
Sweetpotato Knowledge Portal Brief Ver 2 20121022
 
Future Is Integral April 2009
Future Is Integral April 2009Future Is Integral April 2009
Future Is Integral April 2009
 
Aurores
AuroresAurores
Aurores
 
Cisco Confronts Microsoft Wi 172534
Cisco Confronts Microsoft Wi 172534Cisco Confronts Microsoft Wi 172534
Cisco Confronts Microsoft Wi 172534
 
Alevizou, P: Engaging with Open Education
Alevizou, P: Engaging with Open EducationAlevizou, P: Engaging with Open Education
Alevizou, P: Engaging with Open Education
 
Alevizou et al Oer10 Presentation
Alevizou et al Oer10 PresentationAlevizou et al Oer10 Presentation
Alevizou et al Oer10 Presentation
 
Alevizou CreativeCitizen ESRC_Vienna
Alevizou CreativeCitizen ESRC_ViennaAlevizou CreativeCitizen ESRC_Vienna
Alevizou CreativeCitizen ESRC_Vienna
 
Katarzyna Kozinska_wikisym2010
Katarzyna Kozinska_wikisym2010Katarzyna Kozinska_wikisym2010
Katarzyna Kozinska_wikisym2010
 
Network Learning pres_Aborg 4 May 2010
Network Learning pres_Aborg 4 May 2010Network Learning pres_Aborg 4 May 2010
Network Learning pres_Aborg 4 May 2010
 
Alevizou_ Distributed Mentorship P2PU
Alevizou_ Distributed Mentorship P2PUAlevizou_ Distributed Mentorship P2PU
Alevizou_ Distributed Mentorship P2PU
 
Total Cost Of Ownership Of ICT In a Cooperative
Total Cost Of Ownership Of ICT In a CooperativeTotal Cost Of Ownership Of ICT In a Cooperative
Total Cost Of Ownership Of ICT In a Cooperative
 
ICT For Your Council
ICT For Your CouncilICT For Your Council
ICT For Your Council
 

Semelhante a 2009 Cms Conference VMware overview

IBM BladeCenter Foundation for Cloud: Integration Guide
IBM BladeCenter Foundation for Cloud: Integration GuideIBM BladeCenter Foundation for Cloud: Integration Guide
IBM BladeCenter Foundation for Cloud: Integration Guide
IBM India Smarter Computing
 
Vsphere 4-partner-training180
Vsphere 4-partner-training180Vsphere 4-partner-training180
Vsphere 4-partner-training180
Juan Ulacia
 
Vmug v sphere storage appliance (vsa) overview
Vmug v sphere storage appliance (vsa) overviewVmug v sphere storage appliance (vsa) overview
Vmug v sphere storage appliance (vsa) overview
subtitle
 
Esx configuration guide
Esx configuration guideEsx configuration guide
Esx configuration guide
Naga Raju N
 

Semelhante a 2009 Cms Conference VMware overview (20)

IBM BladeCenter Foundation for Cloud: Integration Guide
IBM BladeCenter Foundation for Cloud: Integration GuideIBM BladeCenter Foundation for Cloud: Integration Guide
IBM BladeCenter Foundation for Cloud: Integration Guide
 
VMware
VMware VMware
VMware
 
Todd Muirhead (@virtualTodd) - VMware vSA
Todd Muirhead (@virtualTodd) - VMware vSATodd Muirhead (@virtualTodd) - VMware vSA
Todd Muirhead (@virtualTodd) - VMware vSA
 
Emc world svpg68_2011_05_06_final
Emc world svpg68_2011_05_06_finalEmc world svpg68_2011_05_06_final
Emc world svpg68_2011_05_06_final
 
Infraestructure WMWARE
Infraestructure  WMWAREInfraestructure  WMWARE
Infraestructure WMWARE
 
Introduction to VMware Infrastructure
Introduction to VMware  Infrastructure  Introduction to VMware  Infrastructure
Introduction to VMware Infrastructure
 
Citrix XenDesktop on vSphere - Virsto Launch May 9, 2012
Citrix XenDesktop on vSphere  - Virsto Launch May 9, 2012Citrix XenDesktop on vSphere  - Virsto Launch May 9, 2012
Citrix XenDesktop on vSphere - Virsto Launch May 9, 2012
 
The Storage Hypervisor: The missing link for the Software Defined Datacenter
The Storage Hypervisor:  The missing link for the Software Defined Datacenter The Storage Hypervisor:  The missing link for the Software Defined Datacenter
The Storage Hypervisor: The missing link for the Software Defined Datacenter
 
Vsphere 4-partner-training180
Vsphere 4-partner-training180Vsphere 4-partner-training180
Vsphere 4-partner-training180
 
Vdi3.1 Technical Update
Vdi3.1 Technical UpdateVdi3.1 Technical Update
Vdi3.1 Technical Update
 
Vmug v sphere storage appliance (vsa) overview
Vmug v sphere storage appliance (vsa) overviewVmug v sphere storage appliance (vsa) overview
Vmug v sphere storage appliance (vsa) overview
 
Vsphere4 100325065654-phpapp01
Vsphere4 100325065654-phpapp01Vsphere4 100325065654-phpapp01
Vsphere4 100325065654-phpapp01
 
vSphere 4
vSphere 4vSphere 4
vSphere 4
 
Cisco Live
Cisco LiveCisco Live
Cisco Live
 
Juniper and VMware: Taking Data Centre Networks to the Next Level
Juniper and VMware: Taking Data Centre Networks to the Next LevelJuniper and VMware: Taking Data Centre Networks to the Next Level
Juniper and VMware: Taking Data Centre Networks to the Next Level
 
Virtualization Primer for Java Developers
Virtualization Primer for Java DevelopersVirtualization Primer for Java Developers
Virtualization Primer for Java Developers
 
Aplura virtualization slides
Aplura virtualization slidesAplura virtualization slides
Aplura virtualization slides
 
Esx configuration guide
Esx configuration guideEsx configuration guide
Esx configuration guide
 
Sun VDI 3.1 - Oct 2009
Sun VDI 3.1 - Oct 2009Sun VDI 3.1 - Oct 2009
Sun VDI 3.1 - Oct 2009
 
VMware Esx Short Presentation
VMware Esx Short PresentationVMware Esx Short Presentation
VMware Esx Short Presentation
 

2009 Cms Conference VMware overview

  • 1. VMware Overview and Security 11/12/2009 1
  • 2. Today’s Discussion Today’s Early Successes in Virtualization Current Virtualization Environment Overview of Virtual Environment Security 11/12/2009 2
  • 3. Early Successes With Virtual Implementations VDI VDI – WAH VDI SHACK External Sun Ray Internal • Security • Security • Performance • Security • Speed to market • Cost Savings • DR • Performance • Scalability • Improved • Scalability • Speed to market Support structure 11/12/2009 3
  • 4. Virtual Infrastructure Software Hardware Technologies Utilized Technologies Utilized Vmware Virtual Infrastructure EMC Clarion SAN Vmware ESX 3.5 Dell PowerEdge R900 Servers Virtual Center Server 2.5 Sun Ray DTUs Quest Provision VAS Desktop PCs Sun Ray DVI 11/12/2009 4
  • 5. ESX 3.5 Host Hardware & Connectivity Service Console Service Console Network 4 Port NIC vMotion Network vMotion VM 2 Port NIC Producton VM Production Network Dell PowerEdge R900 2 Port NIC ESX 3.5 Storage 4 X 8 Core Processor 128 GB Memory SAN Fibre Switch 2 Port HBA 11/12/2009 5
  • 6. Datacenter Cluster DRS HA Current DEV Cluster VMware DEV HOST 1 ESX 3.5 Virtual Center DEV HOST 2 VMware ESX 3.5 Structure DEV HOST 3 VMware ESX 3.5 VMware DEV HOST 4 ESX 3.5 Datacenter DRS HA Cluster VDI Cluster VMware VDI HOST 1 ESX 3.5 VMware VDI HOST 2 ESX 3.5 VMware VDI HOST 3 ESX 3.5 VMware VDI HOST 4 ESX 3.5 DRS HA Cluster PROD Cluster VMware PROD HOST 3 ESX 3.5 VMware PROD HOST 4 ESX 3.5 VMware PROD HOST 1 ESX 3.5 VMware PROD HOST 5 ESX 3.5 VMware PROD HOST 2 ESX 3.5 PROD HOST 6 VMware ESX 3.5 DRS HA Cluster SHACK Cluster VMware SHACK HOST 1 ESX 3.5 VMware SHACK HOST 2 ESX 3.5 11/12/2009 6
  • 7. Virtualization Security Overview Virtual Machine Security ESX Host & Service Console Security Virtual Network Security 11/12/2009 7
  • 8. Virtual Machine Specific Security The physical applies in the virtual Remove unneeded virtual devices Use templates to deploy virtual machines Use native RDP rather than the virtual center console Storage permissions Persistent vs. non-persistent Enforce physical machine & remote console isolation 11/12/2009 8
  • 9. ESX & Console Security Base security steps: Restrict root privileges Use strong passwords Firewall restriction Limit services running in the service console Patch the ESX in accordance with your security policy Use of Virtual center to manage Configure SAN Storage correctly 11/12/2009 9
  • 10. Virtual Network Security Segregate network communications Ensure proper vSwitch settings Aim for consistency and compatible settings from physical network devices to virtual. 11/12/2009 10