<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gabes Virtual World &#187; Security</title>
	<atom:link href="http://www.gabesvirtualworld.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gabesvirtualworld.com</link>
	<description>Your P.I. on virtualization</description>
	<lastBuildDate>Tue, 24 Jan 2012 20:15:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>VMware vSphere Health Check</title>
		<link>http://www.gabesvirtualworld.com/vmware-vsphere-health-check/</link>
		<comments>http://www.gabesvirtualworld.com/vmware-vsphere-health-check/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 15:40:29 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[performance]]></category>
		<category><![CDATA[PowerShell]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[health check]]></category>
		<category><![CDATA[powerpack]]></category>
		<category><![CDATA[powershell]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vsphere]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=2216</guid>
		<description><![CDATA[<p>At the Dutch VMUG event 2011 I gave a presentation on how to check your VMware environment to make sure it is healthy. When creating the presentation I had a lot of doubts because I was afraid everyone would think these points were very obvious. But on the other hand, when visiting customers and doing [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/vmware-vsphere-health-check/">VMware vSphere Health Check</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>At the Dutch VMUG event 2011 I gave a presentation on how to check your VMware environment to make sure it is healthy. When creating the presentation I had a lot of doubts because I was afraid everyone would think these points were very obvious. But on the other hand, when visiting customers and doing these health checks for them, I found a lot of those “obvious” issues in their environment. I decided to stick to my plan and test the audience and it turned out they were very happy with my presentation and I saw a lot of people in the audience taking notes. The replies afterwards also showed that for many people there were a lot of eye-openers in this presentation. I therefore decided to convert the power point presentation into this blogpost and hope my readers find it a valuable health check. </p>
<p>In the top menu bar of this blog you&#8217;ll find the &#8220;<a href="http://www.gabesvirtualworld.com/health-check/vmware-vsphere-health-check/?utm_source=blogpost&#038;utm_medium=internal&#038;utm_campaign=healthcheck">Health Check</a>&#8221; section. There you can find the various pages that together give you a complete health check.</p>
<div class="shr-publisher-2216"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fvmware-vsphere-health-check%2F' data-shr_title='VMware+vSphere+Health+Check'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fvmware-vsphere-health-check%2F' data-shr_title='VMware+vSphere+Health+Check'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/vmware-vsphere-health-check/">VMware vSphere Health Check</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/vmware-vsphere-health-check/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tintri VMstore &#8211; VM only storage appliance</title>
		<link>http://www.gabesvirtualworld.com/tintri-vmstore-vm-only-storage-appliance/</link>
		<comments>http://www.gabesvirtualworld.com/tintri-vmstore-vm-only-storage-appliance/#comments</comments>
		<pubDate>Thu, 18 Aug 2011 22:29:17 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[storage]]></category>
		<category><![CDATA[VMsafe]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=1790</guid>
		<description><![CDATA[<p>Last evening I had a WebEx session with Tintri in which they told me about their “VM only” storage appliance VMstore and I must admit that I’m impressed with what they have to offer. I have not yet had the opportunity to test this appliance, all info in this blog post is from the WebEx [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/tintri-vmstore-vm-only-storage-appliance/">Tintri VMstore &#8211; VM only storage appliance</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Last evening I had a WebEx session with Tintri in which they told me about their “VM only” storage appliance VMstore and I must admit that I’m impressed with what they have to offer. I have not yet had the opportunity to test this appliance, all info in this blog post is from the WebEx session and documentation provided by Tintri.</p>
<p>&nbsp;</p>
<h2>What is Tintri VMstore?</h2>
<p>It’s an easy to install storage box that comes in only one configuration: 8.5TB of usable data. In the box is a mix of SATA disks of flash disks. The storage is offered to your VMware environment as one big NFS datastore. By moving data back and forth from SATA to flash, VMstore will eliminate storage performance bottlenecks.<span id="more-1790"></span></p>
<p>&nbsp;</p>
<h2>What’s under the hood?</h2>
<p>The idea of the VMstore is that you no longer carve your storage into different volumes, LUNs, raid-configs, etc. You have just one big volume that is presented as one single datastore to your VMware infrastructure. Having just one single datastore and no LUNs with different performance characteristics, eliminates a lot of storage configuration and management.</p>
<p>What VMstore actually is doing is moving your data from slow rotating disks into super fast flash storage. Moving ALL of your data to flash would be very costly, so they use the flash storage as cache, but a rather big cache. Contrary to other vendors, VMstore uses the flash for read and write, not just read.</p>
<p>To make optimal use of the flash cache, all data that is moved into cache is compressed and deduped. Where other storage vendors use 64K blocks of data to move into cache, VMstore uses only 8K blocks, making it possible to more precisely address the data that should be moved to cache. Tintri says their hitting cache for 97% of all IOPS in production environment.</p>
<p>Of course the flash and 16 SATA disks are protected by RAID, which is a RAID6 level, but for your storage workload, you don’t need different RAID levels.</p>
<p>&nbsp;</p>
<h2>Auto-alignment</h2>
<p>Another technique they are using, which will be announced soon, is auto-alignment. Yes, that is correct; VMstore will automatically align all those VMDK’s that you place on the VMstore. This is a feature I would welcome very much, not even for all the performance gains it would bring to VMstore, but for all those VMs that are still on my to-do list that need re-alignment. Maybe I can ‘test’ a VMstore appliance for a week and storage VMotion all my VMs back and forth between my current storage and the VMstore.</p>
<p>&nbsp;</p>
<h2>Silver, Gold, Platinum</h2>
<p>Since there is just one big volume there is no option to differentiate between Silver, Gold or Platinum performance levels. The only influence you have on the performance of a VM (or single VMDK of a VM) is to pin it to the flash cache. Say a VM with a database running inside, is running for a few days and the most used parts of that VMDK have been moved into flash, you can now pin the VMDK into the flash storage. From now on the data blocks of this VMDK that were in flash, will remain in flash even if in normal use VMstore would start moving those blocks back to the SATA disks. Any extra blocks of this VMDK that are moved from SATA to flash, will also be kept in flash for as long as the VMDK is pinned.</p>
<p><a href="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-virtual_disk_page_graph.png"><img class="aligncenter size-medium wp-image-1795" title="Tintri virtual_disk_page_graph" src="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-virtual_disk_page_graph-300x195.png" alt="" width="300" height="195" /></a></p>
<p>&nbsp;</p>
<h2>Managing VMstore</h2>
<p>The goal was to create storage that would need hardly any management and indeed, all the management you have on the VMstore is decisions on whether to pin or not pin a VM into your flash cache and maybe some day replace a disk.</p>
<p>VMstore has a very intuitive web interface in which you can quickly see how your storage is performing. Again, performance is key here, so the view that shows you how much capacity is left, is telling you about “Performance reserves”.</p>
<p><a href="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-next-gen-dashboard-with-latency.png"><img class="aligncenter size-medium wp-image-1793" title="Tintri next gen dashboard with latency" src="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-next-gen-dashboard-with-latency-300x234.png" alt="" width="300" height="234" /></a></p>
<p>&nbsp;</p>
<h2>Seeing latency at VM level</h2>
<p>A very powerful tool is seeing the latency at VM or VMDK level. In just a few clicks you can see how your VM is performing. Normally you had to first check at storage level what LUN was having high latency, then find out which VMs are running on it and try to figure out which one is the one with the high latency. No more need for that, just open the VMstore web interface.</p>
<p><a href="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-per-VM-latency-end-to-end.png"><img class="aligncenter size-medium wp-image-1794" title="Tintri per VM latency end-to-end" src="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/Tintri-per-VM-latency-end-to-end-300x179.png" alt="" width="300" height="179" /></a></p>
<p><a href="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/latency.png"><img class="aligncenter size-medium wp-image-1792" title="latency" src="http://www.gabesvirtualworld.com/wp-content/uploads/2011/08/latency-300x185.png" alt="" width="300" height="185" /></a></p>
<p>&nbsp;</p>
<h2>Competition</h2>
<p>VMstore is aiming at enterprise customers, since you need to have a certain workload on your storage before you’re running into performance bottlenecks caused by storage configurations. A small environment with just a few IOPS and looking for a lot of room to store data is not the customer that will benefit from a VMstore.</p>
<p>To give you an idea what Tintri is aiming for: They claim a VMstore can outperform an EMC Clariion with 250 spindles. Right now Tintri is testing the VMstore with 65/35 R/W workloads and claims to be able to hit a 50.000 IOPS.</p>
<p>A VMstore with 8.5TB storage should sell for around $65,000 &#8211; $68,000 list price.</p>
<h2>Any drawbacks?</h2>
<p>After listening to the presentation and discussing some topics, there remain some points that should be improved I think.</p>
<ul>
<li>There is just one controller (dual nic though) for the current box. You can choose for a RJ45 connection or 10Gbit connection, but it is still just one controller that connects the VMstore to your VMware infrastructure. This seems a big point for Enterprise ready storage. The 2<sup>nd</sup> generation Vmstore, which will be presented at Vmworld, will contain two controllers.</li>
</ul>
<ul>
<li>Another Enterprise feature that is missing right now and will probably available in the next release is replication. Right now there is no replication at all. Plans for Tintri are to add a-sync replication in the next release.</li>
</ul>
<ul>
<li>In the current release there is no support for VMware VAAI yet, which means especially when offloading storage workloads from the hypervisor to the storage, you would gain some extra performance. However you won’t use VAAI that often during normal operation and the performance bennefit isn’t that big. In vSphere 5 VAAI for NFS will be introduced and Trinti is planning to include this in their next release.</li>
</ul>
<ul>
<li>I’m not sure yet on the concept of just one model: 8.5TB. If you run out of space, you need to buy a second 8.5TB box. Think data growth within the company has to be really huge to justify buying 8.5TB at once.</li>
</ul>
<ul>
<li>And then there of course is the point of real world performance. How will the VMstore handle a lot a random reads and writes? When will workloads be generating cache misses and how will the SATA disks perform in this scenario. We’ll have to wait till we get more real life data from customers.</li>
</ul>
<p>Overall I very much liked what I saw. Of course I can’t comment on performance at all, but the presentation convinced me that VMstore will lower the cost of implementing and managing your storage, if VM storage is the only storage you need.</p>
<p>The view on latency at VM and VMDK level and the auto-alignment are fantastic. The complete absence of difficult storage management is a big big plus for the VMstore.  I think with the coming new version of the VMstore, it will be a real Enterprise ready device.</p>
<div class="shr-publisher-1790"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Ftintri-vmstore-vm-only-storage-appliance%2F' data-shr_title='Tintri+VMstore+-+VM+only+storage+appliance'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Ftintri-vmstore-vm-only-storage-appliance%2F' data-shr_title='Tintri+VMstore+-+VM+only+storage+appliance'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/tintri-vmstore-vm-only-storage-appliance/">Tintri VMstore &#8211; VM only storage appliance</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/tintri-vmstore-vm-only-storage-appliance/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>About ESXi lockdown mode</title>
		<link>http://www.gabesvirtualworld.com/about-esxi-lockdown-mode/</link>
		<comments>http://www.gabesvirtualworld.com/about-esxi-lockdown-mode/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 19:56:29 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[esxi]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtual Center]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[admin tasks]]></category>
		<category><![CDATA[administrator rights]]></category>
		<category><![CDATA[api]]></category>
		<category><![CDATA[client connections]]></category>
		<category><![CDATA[down]]></category>
		<category><![CDATA[drs]]></category>
		<category><![CDATA[hosts]]></category>
		<category><![CDATA[locked]]></category>
		<category><![CDATA[locked down]]></category>
		<category><![CDATA[lockeddown]]></category>
		<category><![CDATA[mode]]></category>
		<category><![CDATA[root user]]></category>
		<category><![CDATA[security reasons]]></category>
		<category><![CDATA[virtual infrastructure]]></category>
		<category><![CDATA[vms]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vsphere]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=829</guid>
		<description><![CDATA[<p>When you build your virtual infrastructure with only ESXi hosts that you also lock down for security reasons, you might be in for a little surprise when you want to get your VI up and running again after major maintenance or a failure. First thing to do after the virtual infrastructure has been down, is [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/about-esxi-lockdown-mode/">About ESXi lockdown mode</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>When you build your virtual infrastructure with only ESXi hosts that you also lock down for security reasons, you might be in for a little surprise when you want to get your VI up and running again after major maintenance or a failure. First thing to do after the virtual infrastructure has been down, is to get vCenter up and running again. In a previous post &#8220;<a href="http://www.gabesvirtualworld.com/?p=114" target="_blank">How to quickly recover from disaster</a>&#8221; I already explained the idea of running vCenter always on the first host in your cluster. In case of failure you don&#8217;t have to search where DRS left your vCenter VM, you just connect the VI Client to the first host and start the vCenter VM. Don&#8217;t forget you need your Active Directory and SQL database before starting vCenter.<span id="more-829"></span></p>
<p>With an all ESXi environment and locked down hosts, you cannot use the VI Client to connect and start the necessary VMs, at least that is what many think, but this isn&#8217;t completely true. The Locked down mode does NOT prevent direct VI Client connections as many think, it does however prevent direct VI Client connetions made with the root-user account. The same goes for PowerCLI, vCLI, vMA, or any of the other public APIs. In locked down mode the root user has no direct access. You can however create an extra user on your ESXi install and assign this user administrator rights. Then, after enabling locked down mode, you can still make a direct VI Client connection to your ESXi box and perform some admin tasks like starting VMs.</p>
<p>Another option would be to just get access to the console of the ESXi host using ILO, KVM, DRAC or similar techniques and disable lockdown mode. After disabling lockdown mode, you can then again make root access using the VI Client.</p>
<p>To summarize:<br />
- Lockdown mode for ESXi <strong>does prevent</strong> root access using VI Client, PowerCLI, vMA, API&#8217;s etc.<br />
- Lockdown mode for ESXi <strong>does NOT prevent</strong> other users accessing the ESXi host using above mentioned tools. Just be sure to first create this user.<br />
- Procedure in an enterprise to create that local user on all ESXi hosts, would be to use (for example) PowerShell to create that admin user and then enable the lockdown mode.</p>
<div class="shr-publisher-829"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fabout-esxi-lockdown-mode%2F' data-shr_title='About+ESXi+lockdown+mode'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fabout-esxi-lockdown-mode%2F' data-shr_title='About+ESXi+lockdown+mode'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/about-esxi-lockdown-mode/">About ESXi lockdown mode</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/about-esxi-lockdown-mode/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
		</item>
		<item>
		<title>So you have that talk with your security officer again&#8230;</title>
		<link>http://www.gabesvirtualworld.com/so-you-have-that-talk-with-your-security-officer-again/</link>
		<comments>http://www.gabesvirtualworld.com/so-you-have-that-talk-with-your-security-officer-again/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 13:08:05 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=98</guid>
		<description><![CDATA[<p>Every now and then, you get that same talk over and over again about ESX security. Bottomline always is that they think ESX (or virtualization at a whole) is not secure enough, but they can never explain why it isn&#8217;t or are just biased because of old security rules and thoughts.The only way to try [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/so-you-have-that-talk-with-your-security-officer-again/">So you have that talk with your security officer again&#8230;</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Every now and then, you get that same talk over and over again about ESX security. Bottomline always is that they think ESX (or virtualization at a whole) is not secure enough, but they can never explain why it isn&#8217;t or are just biased because of old security rules and thoughts.The only way to try to convince them is to have a set of whitepapers and atricles at hand that give some good insight on ESX security.</p>
<p>Below is a number of links that can help you in this situation. Should you have some good links to share, please add them in the comments.<span id="more-98"></span></p>
<p>VMware Infrastructure Earns Common Criteria EAL4+ Certification <a href="http://blogs.vmware.com/security/2008/06/vmware-infrastr.html" target="_blank">http://blogs.vmware.com/security/2008/06/vmware-infrastr.html</a> This post talks about the very high Certification VMware has earned. Although it is only for ESX 3.0.2, one can be assured that ESX is designed with security high on the priority list.</p>
<p>Good starting point on your search for security related docs: <a href="http://viops.vmware.com/home/community/security" target="_blank">http://viops.vmware.com/home/community/security</a>.</p>
<p>Two posts about the &#8220;Blue Pill&#8221; infection that had everybody scared, but turned out to be not so scarry: <a href="http://www.vmware.com/vmtn/blog/2006/08/#bluepillpoppers" target="_blank">http://www.vmware.com/vmtn/blog/2006/08/#bluepillpoppers</a> and <a href="http://www.vmware.com/vmtn/blog/2006/08/#slashdot_followup" target="_blank">http://www.vmware.com/vmtn/blog/2006/08/#slashdot_followup</a>.</p>
<p>Also read this <a href="http://rationalsecurity.typepad.com/blog/2008/04/an-open-letter.html" target="_blank">post by Christofer Hoff</a>, an open letter to Joanna Rutkowska who researched the Blue Pill exploit. Joanna&#8217;s response can be found here <a href="http://theinvisiblethings.blogspot.com/2008/04/research-obfuscated.html" target="_blank">http://theinvisiblethings.blogspot.com/2008/04/research-obfuscated.html</a>. And a last response by Chris: <a href="http://rationalsecurity.typepad.com/blog/2008/04/perception-vs-v.html" target="_blank">http://rationalsecurity.typepad.com/blog/2008/04/perception-vs-v.html</a></p>
<p>Great doc: <a href="http://viops.vmware.com/home/docs/DOC-1141" target="_blank">20 Questions from security professionals</a>. Steve Chambers (VMware) has put the 20 most asked questions from security professionals in writing and answers them.</p>
<p>This document discusses the architecture of VMware Infrastructure 3, focusing on the security aspects of the design: <a href="http://www.vmware.com/resources/techresources/727" target="_blank">Security Design of the VMware Infrastructure 3 Architecture</a>.</p>
<p>Do have a look at <a href="http://www.vmware.com/security/" target="_blank">VMware&#8217;s Security Center</a>.</p>
<p>Some articles about ESX in the DMZ: <a href="http://www.vmware.com/resources/techresources/1052" target="_blank">DMZ virtualization with VI3</a> and <a href="http://rationalsecurity.typepad.com/blog/2008/08/all-your-virtua.html" target="_blank">All Your Virtualized Storage Are Belong To Us</a>.</p>
<div class="shr-publisher-98"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fso-you-have-that-talk-with-your-security-officer-again%2F' data-shr_title='So+you+have+that+talk+with+your+security+officer+again...'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fso-you-have-that-talk-with-your-security-officer-again%2F' data-shr_title='So+you+have+that+talk+with+your+security+officer+again...'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/so-you-have-that-talk-with-your-security-officer-again/">So you have that talk with your security officer again&#8230;</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/so-you-have-that-talk-with-your-security-officer-again/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Montego Networks &#8211; Virtual Security Switch</title>
		<link>http://www.gabesvirtualworld.com/montego-networks-virtual-security-switch/</link>
		<comments>http://www.gabesvirtualworld.com/montego-networks-virtual-security-switch/#comments</comments>
		<pubDate>Thu, 27 Mar 2008 13:09:12 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VirtualSwitches]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=62</guid>
		<description><![CDATA[<p>Today I stumbled upon a new product from Montego Networks, called HyperSwitchTM. With HyperSwitchTM it will be possible to integrate virtual network policies and access control with a high-availability virtual security switch. Some of the features: Virtual machine partitioning, 802.1Q VLANs and port-based security Secure VM-to-VM communications High-availability, policy-based switching Virtual network discovery, visibility and [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/montego-networks-virtual-security-switch/">Montego Networks &#8211; Virtual Security Switch</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Today I stumbled upon a new product from Montego Networks, called HyperSwitchTM.  With HyperSwitchTM it will be possible to integrate virtual network policies and access control with a high-availability virtual security switch. Some of the features:</p>
<p><span id="more-62"></span></p>
<ul type="disc">
<li>Virtual machine       partitioning, 802.1Q VLANs and port-based security</li>
<li>Secure VM-to-VM       communications</li>
<li>High-availability,       policy-based switching</li>
<li>Virtual network       discovery, visibility and rogue detection</li>
<li>Policy-based       access control and auditing (L2-L4, Identity and Content Firewalls)</li>
<li>Load balancing, 802.1D       Spanning Tree, traffic mirroring and QoS</li>
<li>Interoperable delivery       of third-party security applications</li>
</ul>
<p>HyperSwitchTM will be available in two versions, a starter edition and an enterprise edition. The starter edition is FREE, where as the enterprise edition will cost USD $495. The software will be released in April 2008 and will support VMware. Support for Citrix, Virtual Iron and Microsoft virtual environments will follow in Q3-2008.</p>
<p>Be sure to check out the website: <a href="http://www.montegonetworks.com/" target="_blank">http://www.montegonetworks.com/</a></p>
<p><a href="http://192.168.0.123/wp-content/uploads/2008/03/hypernet.png" title="MontegoNetworks"><img src="http://192.168.0.123/wp-content/uploads/2008/03/hypernet.png" alt="MontegoNetworks" /></a></p>
<div class="shr-publisher-62"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fmontego-networks-virtual-security-switch%2F' data-shr_title='Montego+Networks+-+Virtual+Security+Switch'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fmontego-networks-virtual-security-switch%2F' data-shr_title='Montego+Networks+-+Virtual+Security+Switch'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/montego-networks-virtual-security-switch/">Montego Networks &#8211; Virtual Security Switch</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/montego-networks-virtual-security-switch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>VMSafe, what is it exactly?</title>
		<link>http://www.gabesvirtualworld.com/vmsafe-what-is-it-exactly/</link>
		<comments>http://www.gabesvirtualworld.com/vmsafe-what-is-it-exactly/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 12:06:47 +0000</pubDate>
		<dc:creator>Gabrie van Zanten</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[VMsafe]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://www.gabesvirtualworld.com/?p=58</guid>
		<description><![CDATA[<p>Everybody must have already heard about VMware&#8217;s new feature called VMsafe. On day 2 of VMworld Europe, in the keynote speech, VMware founder and chief scientist Mendel Rosenblum announced VMsafe and gave an explanation of what VMsafe can do. To me it was a bit general and I tried to find some more background info [...]</p><p>See full post at: <a href="http://www.gabesvirtualworld.com/vmsafe-what-is-it-exactly/">VMSafe, what is it exactly?</a></p>]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Everybody must have already heard about VMware&#8217;s new feature called VMsafe. On day 2 of VMworld Europe, in the keynote speech, VMware founder and chief scientist Mendel Rosenblum announced VMsafe and gave an explanation of what VMsafe can do. To me it was a bit general and I tried to find some more background info on it and strip the marketing talk. I&#8217;ve merged information from a number of sources and added my own thoughts to it.</p>
<p><span id="more-58"></span><strong>How do I install/activate VMsafe protection?</strong><br />
<em>&#8220;VMsafe is a capability inherent within VMware Infrastructure and specifically within ESX Server. Once utilized and integrated with security partner solutions, customers need only purchase integrated solutions that will be available from partners. Solutions that integrate with VMsafe will be installed as virtual machines.&#8221;</em></p>
<p>So the VMsafe API will always be included in the default ESX installation and security products can talk to the API that is available on the ESX host. This API can only be used by a VM, running a third-party security product. This seems to me as a strong point, because malicious software first has to get into a VM before it could even abuse the API to get access to other VMs. And by having to go this way, malicious software first has to bypass that same API (or security software using the API) before it could get control.</p>
<p><strong>What does VMsafe protect?</strong><br />
<em> &#8220;VSAFE enables partners to build a virtualization-aware security solution in the form of a security virtual machine that can access, correlate and modify information based on the following virtual hardware:<br />
1. Memory and CPU: VMsafe provides introspection of guest VM memory pages and cpu states.<br />
2. Networking: Network packet-filtering for both in-hypervisor and within a Security VM.<br />
3. Process execution (guest handling): in-guest, in-process APIs that enable complete monitoring and control of process execution.<br />
4. Storage: Virtual machine disk files (VMDK) can be mounted, manipulated and modified as they persist on storage devices.&#8221;</em></p>
<p>In the physical world, malware first had to enter memory, disk or I/O before it would be detected and (hopefully) stopped. By using VMsafe, the malware can now be stopped before it enters the OS. Its like watching the whole block around a bank building for robbers instead of posting a security guard at every door and hoping you&#8217;re not missing a door.</p>
<p>By stopping the malware before it enters the guest, it can&#8217;t effect the guest in anyway, it is unable to run at the same privilege level as the guest security software, which sometimes enables the malware to kill the security software and take complete control. Having no OS the malware can run on makes it completely isolated.</p>
<p>Still, I&#8217;m wondering what the Security VM guest OS will be and if it will be impossible for malware to abuse the API and slip into the security VM. According to George Heron, chief science officer McAfee, this will not pose to be an issue. Quoting him from the VMworld News paper that was handed out to all attendees at VMworld Europe:</p>
<p><em>&#8220;Probably the most radical aspect of the VMsafe initiative is not the technology specifications, but the fact that VMware has made the bold decision to provide secure, third-party access to the information seen by the core of its technology &#8211; the hypervisor. Security purists and VMware&#8217;s competitors will undoubtedly argue that providing access to the hypervisor, albeit in a highly controlled manner, increases the risk of the hypervisor&#8217;s own integrity being compromised, and with it the security of every virtual machine that runs on top of it. VMsafe is architected in a manner that eliminates this threat by having the security product run in an isolated space outside of the context of the hypervisor.&#8221;</em></p>
<p>Ok, but still&#8230;. there is some talk between Security VM &lt;-&gt; ESX API &lt;-&gt; Guest VM. So how does this isolation work? I haven&#8217;t been able to figure this out yet, but I guess within short time there will be more articles and white papers available explaining things in detail.</p>
<p>Reading a lot of articles and press releases about VMsafe, I&#8217;m convinced that VMsafe is a great step into a safer enterprise environment. Being able to stop malware before it ever reaches the VM is really great. VMsafe will not just work outside the guest, it can also work at a deeper level then other security software could do before in a virtualized environment. And let&#8217;s not just look at anti-virus products, but on firewall level / network level there are great opportunities to.  A lot of security products could not  Already over 20 major leading security vendors have been talking with VMware to join their VMsafe program. With this step, VMware is painting a new vision on security in the data center.</p>
<p>Sources:</p>
<p><a href="http://www.vmware.com/overview/security/vmsafe/faq.html" target="_blank"> VMware VMsafe Security Technology</a><br />
<a href="http://rationalsecurity.typepad.com/blog/2008/03/vmwares-vmsafe.html" target="_blank">VMware&#8217;s VMsafe: Security Industry Defibrillator&#8230;.Making Dying Muscle Twitch Again.</a><br />
<a href="http://gregness.wordpress.com/" target="_blank">Archimedius</a></p>
<p>edit:<br />
Duncan from <a href="http://www.yellow-bricks.com/" target="_blank">http://www.yellow-bricks.com/</a> pointed me to a possible explanation of the technique used by VMsafe, Virtual Machine Communication Interface (VMCI). Read more about it here: <a href="http://pubs.vmware.com/vmci-sdk/VMCI_intro.html" target="_blank">http://pubs.vmware.com/vmci-sdk/VMCI_intro.html</a></p>
<div class="shr-publisher-58"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fvmsafe-what-is-it-exactly%2F' data-shr_title='VMSafe%2C+what+is+it+exactly%3F'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fwww.gabesvirtualworld.com%2Fvmsafe-what-is-it-exactly%2F' data-shr_title='VMSafe%2C+what+is+it+exactly%3F'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic --><p>See full post at: <a href="http://www.gabesvirtualworld.com/vmsafe-what-is-it-exactly/">VMSafe, what is it exactly?</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.gabesvirtualworld.com/vmsafe-what-is-it-exactly/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: www.gabesvirtualworld.com @ 2012-02-04 06:40:22 -->
