20.01.2015 Views

VM Security - VMware Communities

VM Security - VMware Communities

VM Security - VMware Communities

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

vnic<br />

vnic<br />

vnic<br />

Isolation in the Architecture<br />

Segment out all non-production<br />

networks<br />

<strong>VM</strong>kernel<br />

• Use VLAN tagging, or<br />

Production<br />

Mgmt<br />

Storage<br />

• Use separate vSwitch (see<br />

diagram)<br />

vSwitch1<br />

vmnic1 2 3 4<br />

Prod<br />

Network<br />

Mgmt<br />

Network<br />

vSwitch2<br />

Strictly control access to<br />

management network, e.g.<br />

• RDP to jump box, or<br />

• VPN through firewall<br />

<strong>VM</strong>ware Infrastructure 3 <strong>Security</strong> Hardening Guide<br />

http://www.vmware.com/resources/techresources/726<br />

vCenter<br />

Other ESX/ESXi<br />

hosts<br />

IP-based<br />

Storage<br />

13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!