<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>VMware Communities: Message List - ESX 3.5 Behind a Firewall</title>
    <link>http://communities.vmware.com/community/vmtn/general/security?view=discussions</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    <pubDate>Sat, 27 Jun 2009 14:12:10 GMT</pubDate>
    <generator>Clearspace 1.10.12 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-06-27T14:12:10Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Re: ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1296598?tstart=0#1296598</link>
      <description>Hello&lt;br /&gt;
&lt;br /&gt;
Moved to Security Forum.&lt;br /&gt;
&lt;br /&gt;
Ideally you want something like this:&lt;br /&gt;
&lt;br /&gt;
Home &amp;lt;-&amp;gt; Internet &amp;lt;-&amp;gt; FW &amp;lt;-&amp;gt; DMZ &amp;lt;-&amp;gt; FW &amp;lt;-&amp;gt; Production &amp;lt;-&amp;gt; FW &amp;lt;-&amp;gt; Management Network (VC + SC + VIC workstation)&lt;br /&gt;
&lt;br /&gt;
Yes you want that many firewalls. The idea is that you use a VPN to cross the boundaries as necessary. You NEVER want to place your SC/VC/VIC within your DMZ or out on the internet.  You could do something like the following to gain the access you need.&lt;br /&gt;
&lt;br /&gt;
Home &amp;lt;-&amp;gt; VPN &amp;lt;-&amp;gt; Management Network&lt;br /&gt;
&lt;br /&gt;
Check out &lt;a class="jive-link-external" href="http://www.vmware.com/files/pdf/dmz_virtualization_vmware_infra_wp.pdf"&gt;http://www.vmware.com/files/pdf/dmz_virtualization_vmware_infra_wp.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br&gt;Best regards, &lt;br /&gt;
Edward L. Haletky VMware Communities User Moderator, VMware vExpert 2009, &lt;a class="jive-link-external" href="http://www.virtualizationpractice.com"&gt;Virtualization Practice Analyst&lt;/a&gt;&lt;br&gt;Now Available: &lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security"&gt;'VMware vSphere(TM) and Virtual Infrastructure Security: Securing the Virtual Environment'&lt;/a&gt;&lt;br&gt;Also available &lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"&gt;'VMWare ESX Server in the Enterprise'&lt;/a&gt;&lt;br&gt;&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Blog_Roll"&gt;SearchVMware Pro&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/blog"&gt;Blue Gears&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links"&gt;Top Virtualization Security Links&lt;/a&gt;|&lt;a class="jive-link-external" href="http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcast"&gt;Virtualization Security Round Table Podcast&lt;/a&gt;</description>
      <pubDate>Sat, 27 Jun 2009 14:12:10 GMT</pubDate>
      <author>Texiwill</author>
      <guid>http://communities.vmware.com/message/1296598?tstart=0#1296598</guid>
      <dc:date>2009-06-27T14:12:10Z</dc:date>
      <clearspace:dateToText>5 months, 1 day ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1286973?tstart=0#1286973</link>
      <description>You're welcome.&lt;br /&gt;
&lt;br /&gt;
Andre</description>
      <pubDate>Wed, 17 Jun 2009 15:57:13 GMT</pubDate>
      <author>AndreTheGiant</author>
      <guid>http://communities.vmware.com/message/1286973?tstart=0#1286973</guid>
      <dc:date>2009-06-17T15:57:13Z</dc:date>
      <clearspace:dateToText>5 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Re: ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1286429?tstart=0#1286429</link>
      <description>Thanks your opinion that i will now be considering. Much appreciated</description>
      <pubDate>Wed, 17 Jun 2009 07:39:17 GMT</pubDate>
      <author>ejking</author>
      <guid>http://communities.vmware.com/message/1286429?tstart=0#1286429</guid>
      <dc:date>2009-06-17T07:39:17Z</dc:date>
      <clearspace:dateToText>5 months, 1 week ago</clearspace:dateToText>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Re: ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1283366?tstart=0#1283366</link>
      <description>Hi,&lt;br /&gt;
&lt;br /&gt;
You should really not open any of those  ports to the internet.&lt;br /&gt;
Use VPN as Andre suggest or SSH to forward your  ports to the host instead using an external firewall.&lt;br /&gt;
&lt;br /&gt;
If you cannot add an external firewall for whatever reason, then you  could set up a firewall VM, have it autostart with the host and route your traffic through there.&lt;br /&gt;
&lt;br&gt;&lt;br&gt;--&lt;br /&gt;
Wil&lt;br /&gt;
_____________________________________________________ &lt;br /&gt;
Visit the VMware developers wiki at &lt;a class="jive-link-external" href="http://www.vi-toolkit.com"&gt;http://www.vi-toolkit.com&lt;/a&gt;</description>
      <pubDate>Sun, 14 Jun 2009 15:20:17 GMT</pubDate>
      <author>wila</author>
      <guid>http://communities.vmware.com/message/1283366?tstart=0#1283366</guid>
      <dc:date>2009-06-14T15:20:17Z</dc:date>
      <clearspace:dateToText>5 months, 2 weeks ago</clearspace:dateToText>
    </item>
    <item>
      <title>Re: ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1283363?tstart=0#1283363</link>
      <description>I suggest you to use a VPN system.&lt;br /&gt;
I more secure and you have (usually) open a single port.&lt;br /&gt;
&lt;br /&gt;
Andre&lt;br /&gt;
**if you found this or any other answer useful please consider allocating points for helpful or correct answers</description>
      <pubDate>Sun, 14 Jun 2009 15:08:19 GMT</pubDate>
      <author>AndreTheGiant</author>
      <guid>http://communities.vmware.com/message/1283363?tstart=0#1283363</guid>
      <dc:date>2009-06-14T15:08:19Z</dc:date>
      <clearspace:dateToText>5 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>3</clearspace:replyCount>
    </item>
    <item>
      <title>ESX 3.5 Behind a Firewall</title>
      <link>http://communities.vmware.com/message/1281029?tstart=0#1281029</link>
      <description>&lt;br /&gt;
Requirement&lt;br /&gt;
&lt;p /&gt;
ESX server is on DMZ to be on HP hardware and VC(2.5) on the internal LAN. Server based licensing to be used and the Flex lic server is on the same server as VC&lt;br /&gt;
&lt;p /&gt;
Ability to deploy software on ESX by use of ILO by Admins (both Console &amp;#38; Virtual media access)&lt;br /&gt;
&lt;p /&gt;
Ability for the app support to remote to VM's in DMZ to manage VM's only and deploy sofware. Preferably if app support can load the app themselves and if not possible admin does if for them. mstsc/landesk/sms/dameware,etc is not allowed.&lt;br /&gt;
&lt;p /&gt;
Ability to deploy software from Altiris RDP server which is inside the internal LAN&lt;br /&gt;
&lt;p /&gt;
DNS name resolution to be allowed.&lt;br /&gt;
&lt;p /&gt;
Company operates a strict policy and ports need to be kept to a bare minimum&lt;br /&gt;
&lt;p /&gt;
******************************************************************************************************************************************************************************************************&lt;br /&gt;
&lt;p /&gt;
Current Ports to be opened and solution that i can think off&lt;br /&gt;
&lt;p /&gt;
ESX to Flex lic server (27000 &amp;#38;27010), ESX to Vcenter/Web (443 and 903/UDP), VI to ESX(902&amp;#38;903), ILO to ESX(23 &amp;#38;17988), DNS(53 TCP/UDP)&lt;br /&gt;
&lt;p /&gt;
&lt;b&gt;Other than adding IP helper ipaddresses on Switches is there any ports required for altiris RDP server VM deployment? Is the risk of using RDP more than the benefit?&lt;/b&gt;&lt;br /&gt;
&lt;p /&gt;
App support team to be given access via "Generating Remote Console URL" for VM's on VC. And admin teams put the software for them on VM's. Is there a better solution to this?&lt;br /&gt;
&lt;p /&gt;
If we used host based licensing, would 27000 and 27010 still needs to be open on the firewall&lt;br /&gt;
&lt;p /&gt;
Suggest any ports that can be added or removed, or anything else usefull. Thanking you&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;</description>
      <pubDate>Thu, 11 Jun 2009 17:15:14 GMT</pubDate>
      <author>ejking</author>
      <guid>http://communities.vmware.com/message/1281029?tstart=0#1281029</guid>
      <dc:date>2009-06-11T17:15:14Z</dc:date>
      <clearspace:dateToText>5 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:replyCount>5</clearspace:replyCount>
    </item>
  </channel>
</rss>

