VM Security - VMware Communities
VM Security - VMware Communities
VM Security - VMware Communities
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
vnic<br />
vnic<br />
vnic<br />
Isolation in the Architecture<br />
Segment out all non-production<br />
networks<br />
<strong>VM</strong>kernel<br />
• Use VLAN tagging, or<br />
Production<br />
Mgmt<br />
Storage<br />
• Use separate vSwitch (see<br />
diagram)<br />
vSwitch1<br />
vmnic1 2 3 4<br />
Prod<br />
Network<br />
Mgmt<br />
Network<br />
vSwitch2<br />
Strictly control access to<br />
management network, e.g.<br />
• RDP to jump box, or<br />
• VPN through firewall<br />
<strong>VM</strong>ware Infrastructure 3 <strong>Security</strong> Hardening Guide<br />
http://www.vmware.com/resources/techresources/726<br />
vCenter<br />
Other ESX/ESXi<br />
hosts<br />
IP-based<br />
Storage<br />
13