<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:clearspace="http://www.jivesoftware.com/xmlns/clearspace/rss" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:opensearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>VMware Communities : Unanswered Threads - Security &amp; vShield Zones</title>
    <link>http://communities.vmware.com/community/vmtn/general/security?view=discussions&amp;filter=open</link>
    <description>Unanswered Discussion Threads in Security &amp; vShield Zones</description>
    <language>en</language>
    <pubDate>Mon, 23 Nov 2009 16:05:18 GMT</pubDate>
    <generator>Clearspace 1.10.12 (http://jivesoftware.com/products/clearspace/)</generator>
    <dc:date>2009-11-23T16:05:18Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>vShield - No cluster option</title>
      <link>http://communities.vmware.com/thread/243307</link>
      <description>&lt;br /&gt;
Hopefully this is a simple one......  &lt;img class="jive-emoticon" border="0" src="http://communities.vmware.com/images/emoticons/happy.gif" alt=":)" /&gt;   &lt;br /&gt;
&lt;p /&gt;
I have 3xESXi  4.0 hosts in a DRS cluster. I have followed the VMware instructions as much as possible but im obvisouly doing something wrong.&lt;br /&gt;
&lt;p /&gt;
I have installed vShield manually (on a distributed switch) and vShield manager (is currently located on a vSwitch) and am getting connectivity ok. However, when doing a manual install through vShield Manager. I ONLY have the option &lt;b&gt;"Standalone"&lt;/b&gt; in the Clustering Settings. In the guide it  says I should have a  "&lt;b&gt;Add to Cluster"&lt;/b&gt; option - which just isnt visible. This obviously just leaves me with 1 host being protected.&lt;br /&gt;
&lt;p /&gt;
 Any ideas?!</description>
      <pubDate>Thu, 19 Nov 2009 15:13:08 GMT</pubDate>
      <author>Mickoni</author>
      <guid>http://communities.vmware.com/thread/243307</guid>
      <dc:date>2009-11-19T15:13:08Z</dc:date>
      <clearspace:dateToText>2 days, 19 hours ago</clearspace:dateToText>
      <clearspace:messageCount>5</clearspace:messageCount>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>vShield agent scan interface</title>
      <link>http://communities.vmware.com/thread/241754</link>
      <description>Hi,&lt;br /&gt;
&lt;br /&gt;
Am testing out the vShield addon in our local environment and have hit a snag I hope someone knows the answer to.  My vShield agent has a management IP address outside of the subnet of VMs that I wish to scan for services.  According to the documentation I should enable the scan interface from the CLI and give it an ip address in the range of my VMs which makes sense......but life is never simple.  Within the configuration option of the CLI I can only see 3 interfaces which are: mgmt, u0 and p0 so the command to enable the scan interface is clearly missing a step.  I am assuming that adding another vNic is the way to go but am wondering what I will need to do after this.&lt;br /&gt;
&lt;br /&gt;
Any help much appreciated.&lt;br /&gt;
&lt;p /&gt;
Mike</description>
      <pubDate>Tue, 10 Nov 2009 18:01:49 GMT</pubDate>
      <author>mike lim</author>
      <guid>http://communities.vmware.com/thread/241754</guid>
      <dc:date>2009-11-10T18:01:49Z</dc:date>
      <clearspace:dateToText>2 weeks, 1 day ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>vSphere STIG and DoD Discussion</title>
      <link>http://communities.vmware.com/thread/234840</link>
      <description>&lt;p /&gt;
&lt;span style="color:#000080"&gt;I started the new thread so that others can contribute. &lt;br /&gt;
Hopefully, we can use this thread to advise interested users when the vSphere STIG will be in draft or and final mode.:^0 &lt;br /&gt;
&lt;br /&gt;
I have been following the thread about the ESX script to pass DISA Security Review which provided good info for ESX 3.5.&lt;br /&gt;
&lt;br /&gt;
We may be installing vSphere 4.0 in the upcoming months in a DoD facility and will be required to use a DIACAP process to receive an ATO to allow the systems to be connected to a classified network.&lt;br /&gt;
&lt;br /&gt;
I am interested in the process that our DAA will need to investigate. &lt;br /&gt;
&lt;br /&gt;
I am assuming the ESX Stig will be a starting point as we start down the path for receiving our ATO?&lt;/span&gt;</description>
      <pubDate>Fri, 02 Oct 2009 19:05:36 GMT</pubDate>
      <author>stanj</author>
      <guid>http://communities.vmware.com/thread/234840</guid>
      <dc:date>2009-10-02T19:05:36Z</dc:date>
      <clearspace:dateToText>1 month, 1 week ago</clearspace:dateToText>
      <clearspace:messageCount>8</clearspace:messageCount>
      <clearspace:replyCount>7</clearspace:replyCount>
    </item>
    <item>
      <title>VM Firewalls</title>
      <link>http://communities.vmware.com/thread/229176</link>
      <description>&lt;br /&gt;
Anyone have any experience with Altor Networks Virutal Firewalls?&lt;br /&gt;
&lt;p /&gt;
 Just looking from some feedback as we are looking to implement in our environment.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Thanks,&lt;br /&gt;
&lt;p /&gt;
Kevin</description>
      <pubDate>Tue, 01 Sep 2009 15:02:39 GMT</pubDate>
      <author>boatrke1</author>
      <guid>http://communities.vmware.com/thread/229176</guid>
      <dc:date>2009-09-01T15:02:39Z</dc:date>
      <clearspace:dateToText>2 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:messageCount>7</clearspace:messageCount>
      <clearspace:replyCount>6</clearspace:replyCount>
    </item>
    <item>
      <title>VM Flow shows "No Data Found"</title>
      <link>http://communities.vmware.com/thread/227521</link>
      <description>We're just tinkering with vShield and Cisco N1000V independently and together in the lab as we prepare to deploy vSphere.&lt;br /&gt;
&lt;br /&gt;
The current configuration in our lab is this:&lt;br /&gt;
&lt;p /&gt;
&lt;ol&gt;
&lt;li&gt;The public side of a vShield VM is connected to an N1000V Port Group&lt;/li&gt;
&lt;li&gt;The private side of the vShield VM is connected to a local vSwitch Portgroup with Promiscuous mode permitted. (It's not a dV Port group, but do recognize this would be needed as we evolve the lab)&lt;/li&gt;
&lt;li&gt;We have servers on the public side and one server on the protected port group, and can transfer data to and from all these servers from another computer outside the ESX environment.&lt;/li&gt;
&lt;li&gt;The protected server is shown as protected in the vShield Manager&lt;/li&gt;
&lt;li&gt;I have a script running elsewhere that is generating traffic to and from the protected server. The vShield Manager Status for that vShield is showing all the expected traffic in both the p0 and u0 status.&lt;/li&gt;
&lt;li&gt;But, the VMFlow stats for the protected server and its roll-ups shows "No Data Found"&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
Some questions&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;I was unable to get the protected Port Group working as an N1000V port group, and have since found information here confirming that. Is the failure to display VMFlow stats related to the fact the public side doesn't really support promiscuous mode? (since it's a N1000V port group)&lt;/li&gt;
&lt;li&gt;Is there some other misconfiguration I've done that is preventing the VMFlow data from showing?&lt;/li&gt;
&lt;li&gt;Again with the promiscuous issue, am I unlikely to get a second computer in the protected side to work?&lt;/li&gt;
&lt;li&gt;I saw a reference to reversing my configuration: Put the public side on a vNetwork switch with uplinks, and put the protected side as an N1000V port group. Is this likely to work better?&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
I understand Cisco is working on a solution to this problem, but we did want to put in as much "end-state" infrastructure as possible as we prepare for deployment, and doing the uplink side using N1000V seems to make more sense to me.&lt;br /&gt;
&lt;br /&gt;
Thanks for this.</description>
      <category domain="http://communities.vmware.com/tags?communityID=2004">vshield</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">n1000v</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">cisco</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">vmflow</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">vshield_zones</category>
      <pubDate>Fri, 21 Aug 2009 18:56:19 GMT</pubDate>
      <author>SCampbell</author>
      <guid>http://communities.vmware.com/thread/227521</guid>
      <dc:date>2009-08-21T18:56:19Z</dc:date>
      <clearspace:dateToText>3 months, 6 days ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>vShield Port Groups management</title>
      <link>http://communities.vmware.com/thread/222718</link>
      <description>Hello ,&lt;br /&gt;
&lt;br /&gt;
Designing an architecture based on ESX4 and implementing a model with multiple remote administrators (on independant VLANs) was the easy task. The next step was to offer each remote admin a virtual data center on the platform to create his own machines and connect them to his port group.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
The security problem we are having is restraining each admin to his port group or vlan while creating his machine. In the documentation, dvPorts is a managable object but I can't seem to be able to correctly assign each admin in my active directory to a port group on the vswitch.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Can it be done? Can we create privileges on a vSwitch's port groups directly?&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
If that is not possible, can we create a mandatory template to connect the VM with the port group already specified?&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Thanks for all the help!&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Charbel&lt;br /&gt;
&lt;p /&gt;
PS: Reference VSphere Basic System Administration p221-222</description>
      <pubDate>Fri, 24 Jul 2009 09:07:18 GMT</pubDate>
      <author>CharbelZ</author>
      <guid>http://communities.vmware.com/thread/222718</guid>
      <dc:date>2009-07-24T09:07:18Z</dc:date>
      <clearspace:dateToText>4 months, 5 days ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>Strange numbers in VM Flow report</title>
      <link>http://communities.vmware.com/thread/219974</link>
      <description>I have VM with Windows File Server and a couple of iSCSI LUNs on external array connected via software initiator from windows.&lt;br /&gt;
So, traffic for this file server should be approx 50/50 in/out.&lt;br /&gt;
&lt;br /&gt;
But VM Flow report shows 196GB in / 1.8TB out. How can that be? Almost all outbound traffic is to port 3260, iSCSI.&lt;br /&gt;
&lt;br /&gt;
I have antivirus on this VM, so traffic difference can be explained by antivirus that checks a lot of files. But I suppose there should reverse situation, inbound traffic above outbound. Or I just understand inbound / outbound wrong?&lt;br /&gt;
&lt;br&gt;---&lt;br /&gt;
VMware vExpert '2009&lt;br /&gt;
&lt;a class="jive-link-external" href="http://blog.vadmin.ru"&gt;http://blog.vadmin.ru&lt;/a&gt;</description>
      <pubDate>Wed, 08 Jul 2009 13:02:15 GMT</pubDate>
      <author>Anton V Zhbankov</author>
      <guid>http://communities.vmware.com/thread/219974</guid>
      <dc:date>2009-07-08T13:02:15Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>Any tools to retrieve local windows 2003 account credentials?</title>
      <link>http://communities.vmware.com/thread/217906</link>
      <description>&lt;br /&gt;
Hi All,&lt;br /&gt;
&lt;p /&gt;
 I need some help with any tools available to retrieve or backup bunch of local windows 2003 account credentials (username/passwords).  I've tried to google but have no luck with a tool that can do so especially reading the user's password for archival purpose. &lt;br /&gt;
&lt;br /&gt;
If you found this information useful, please consider awarding points for "Correct" or "Helpful". Thanks!!! &lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Stefan Nguyen&lt;br /&gt;
VMware vExpert 2009&lt;br /&gt;
iGeek Systems Inc.&lt;br /&gt;
VMware, Citrix, Microsoft Consultant</description>
      <pubDate>Thu, 25 Jun 2009 15:29:48 GMT</pubDate>
      <author>azn2kew</author>
      <guid>http://communities.vmware.com/thread/217906</guid>
      <dc:date>2009-06-25T15:29:48Z</dc:date>
      <clearspace:dateToText>5 months, 3 days ago</clearspace:dateToText>
      <clearspace:messageCount>5</clearspace:messageCount>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Any security concerns with adding VMkernel IP's to DNS?</title>
      <link>http://communities.vmware.com/thread/212281</link>
      <description>&lt;br /&gt;
Quick background:  We have a large ESX shop (200+), and we use a NAS for build scripts, config files and ESX backup.  We have to switch over to a new NAS.  Problem is that the new NAS (Celerra) has a 2048 character limit, so we cannot add all of the current hosts.  EMC found a possible solution by defining netgroups.  This works like a host file.&lt;br /&gt;
&lt;p /&gt;
Service Console IP's and FQDN are in DNS, as they should be.&lt;br /&gt;
&lt;p /&gt;
Issue:  We have the VMkernel in isolated VLAN's.  Storage guys would like to add the IP's for VMkernel into DNS, of course with different name (ex: hostname-vmk).  This ensure that they we won't have to continue to add them in the netgroup.&lt;br /&gt;
&lt;p /&gt;
Question: Are there any security concerns with adding VMkernel IP's to DNS?&lt;br /&gt;
&lt;p /&gt;
Thanks in advance.&lt;br /&gt;
&lt;p /&gt;
Scott</description>
      <pubDate>Thu, 28 May 2009 14:14:25 GMT</pubDate>
      <author>Nashwood</author>
      <guid>http://communities.vmware.com/thread/212281</guid>
      <dc:date>2009-05-28T14:14:25Z</dc:date>
      <clearspace:dateToText>6 months, 1 day ago</clearspace:dateToText>
      <clearspace:messageCount>4</clearspace:messageCount>
      <clearspace:replyCount>3</clearspace:replyCount>
    </item>
    <item>
      <title>2-factor authentication for ESX and vCenter management (VIC and ssh)</title>
      <link>http://communities.vmware.com/thread/210805</link>
      <description>&lt;br /&gt;
Hi,&lt;br /&gt;
&lt;p /&gt;
HyTrust is working on implementing 2-factor authentication for ESX  and vCenter as part of HyTrust Appliance's access management capabilities for our upcoming 1.1 release.  This is for both vCenter and direct-to-host management connections using Virtual Infrastructure Client or ssh.  We are currently looking at implementing support for RSA SecureID, smart card, Radius and kerberos.  &lt;br /&gt;
&lt;p /&gt;
We are interested in getting additional input on our use cases/workflow for supporting 2-factor authentication as well as beta sites.  Let me know if you have an interest in participating.&lt;br /&gt;
&lt;p /&gt;
For those that don't know about us, HyTrust Appliance provides control and visibility for virtual infrastructure.  The HyTrust Appliance is a single-point-of-control for access management, audit logging, and consistent hypervisor configuration.  The Community Edition of HyTrust Appliance is a full-featured version of the product protecting up to 3 ESX hosts and is totally free to the Community -- download your copy today at &lt;a class="jive-link-external" href="http://www.hytrust.com/community"&gt;http://www.hytrust.com/community&lt;/a&gt;.&lt;br /&gt;
&lt;p /&gt;
Please contact me if you have an interest in working with us on 2-factor authentication.&lt;br /&gt;
&lt;p /&gt;
Thanks, &lt;br /&gt;
&lt;br /&gt;
&lt;div&gt;&lt;span style="font-size:2"&gt;Eric Chiu&lt;br /&gt;
650.681.8111 direct&lt;br /&gt;
&lt;/span&gt;&lt;span style="font-size:2"&gt;echiu@hytrust.com&lt;br /&gt;
&lt;/span&gt;&lt;span style="font-size:2"&gt;www.hytrust.com&lt;br /&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;p /&gt;</description>
      <category domain="http://communities.vmware.com/tags?communityID=2004">access</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">3.5</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">esx3.5</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">hardening</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">rsa</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">security</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">virtual_center</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">vmware</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">network</category>
      <pubDate>Tue, 19 May 2009 23:41:10 GMT</pubDate>
      <author>echiu</author>
      <guid>http://communities.vmware.com/thread/210805</guid>
      <dc:date>2009-05-19T23:41:10Z</dc:date>
      <clearspace:dateToText>6 months, 1 week ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Kon-boot</title>
      <link>http://communities.vmware.com/thread/210502</link>
      <description>Kon-boot is a boot-cd or floppy.&lt;br /&gt;
You boot a real metal system or VM with it, It shows a logo at boot-up and then continues loading  the installed system from harddisk.&lt;br /&gt;
You can then log in without knowing the password on Windows or with password "kon-usr" for root-accounts on Linux&lt;br /&gt;
Works on some Linux and on most Windows.&lt;br /&gt;
&lt;br /&gt;
It works alarmingly good - if you are interested in Security you really should know it.&lt;br /&gt;
&lt;br /&gt;
&lt;a class="jive-link-external" href="http://www.piotrbania.com/all/kon-boot/"&gt;http://www.piotrbania.com/all/kon-boot/&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
___________________________________&lt;br /&gt;
&lt;br /&gt;
description of vmx-parameters: &lt;a class="jive-link-external" href="http://sanbarrow.com/vmx.html"&gt;http://sanbarrow.com/vmx.html&lt;/a&gt;&lt;br /&gt;
VMware-liveCD: &lt;a class="jive-link-external" href="http://sanbarrow.com/moa.html"&gt;http://sanbarrow.com/moa.html&lt;/a&gt;</description>
      <pubDate>Mon, 18 May 2009 13:16:28 GMT</pubDate>
      <author>continuum</author>
      <guid>http://communities.vmware.com/thread/210502</guid>
      <dc:date>2009-05-18T13:16:28Z</dc:date>
      <clearspace:dateToText>6 months, 1 week ago</clearspace:dateToText>
      <clearspace:messageCount>6</clearspace:messageCount>
      <clearspace:replyCount>5</clearspace:replyCount>
    </item>
    <item>
      <title>VMware vShield Zones Private Beta running now</title>
      <link>http://communities.vmware.com/thread/201527</link>
      <description>&lt;br /&gt;
Recently at VMworld Europe 2009 in February, VMware announced a new vSphere offering called VMware vShield Zones that provides network monitoring and firewalling for security and compliance of VM's.  We just kicked off a private beta open to vSphere 4 beta customers that will be running for the next few weeks.  I'd like to extend an invitation for additional beta testers to the Security and Compliance forum as well.  If you are interested, please send me a private message and I will work on manually enrolling you into the vShield Zones beta community to get access to the software, documentation, and beta forum. &lt;br /&gt;
&lt;p /&gt;
You can learn more about VMware vShield Zones at the product page here:  &lt;a class="jive-link-external" href="http://www.vmware.com/products/vshield-zones/"&gt;http://www.vmware.com/products/vshield-zones/&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Regards,&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Warren Wu&lt;br /&gt;
&lt;p /&gt;
VMware Product Management</description>
      <pubDate>Wed, 25 Mar 2009 18:41:03 GMT</pubDate>
      <author>wwu123</author>
      <guid>http://communities.vmware.com/thread/201527</guid>
      <dc:date>2009-03-25T18:41:03Z</dc:date>
      <clearspace:dateToText>8 months, 5 days ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>Does anyone have any experience with using LogRhythm to consolidate and manage ESX logs?</title>
      <link>http://communities.vmware.com/thread/201466</link>
      <description>&lt;br /&gt;
We have the LogRhythm product for consolidation and management of Windows logs and I know that it can receive syslogs from ESX, however I don't know how to filter the ESX syslogs once it is in LogRhythm.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Does anyone have any experience with this product?  I really don't want to re-invent the wheel if someone already has an ESX specific template.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Gene</description>
      <category domain="http://communities.vmware.com/tags?communityID=2004">log</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">consolidation</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">log</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">management</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">esx3.5</category>
      <pubDate>Wed, 25 Mar 2009 15:40:27 GMT</pubDate>
      <author>Gene H</author>
      <guid>http://communities.vmware.com/thread/201466</guid>
      <dc:date>2009-03-25T15:40:27Z</dc:date>
      <clearspace:dateToText>8 months, 5 days ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>ServerView agents for VMware ESX Server 3.5 Update 2</title>
      <link>http://communities.vmware.com/thread/175440</link>
      <description>&lt;br /&gt;
Hi,&lt;br /&gt;
&lt;p /&gt;
I am using ServerView for managing my Fujitsu Siemens servers, but i have to install serverview agents to every server that i want to be managed.&lt;br /&gt;
&lt;p /&gt;
Is it possible to install ServerView agents for VMware ESX Server 3.5 Update.&lt;br /&gt;
&lt;p /&gt;
Can anybody send me links, or some books for this.&lt;br /&gt;
&lt;p /&gt;
I have found some manuals and RPM files, but i doubt that i could use them for esx server 3.5 Update 2.&lt;br /&gt;
&lt;p /&gt;
Thanks &lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;</description>
      <pubDate>Wed, 22 Oct 2008 08:16:06 GMT</pubDate>
      <author>Aleksandar_Macedonia</author>
      <guid>http://communities.vmware.com/thread/175440</guid>
      <dc:date>2008-10-22T08:16:06Z</dc:date>
      <clearspace:dateToText>1 year, 1 month ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>VIM account password was changed on host...</title>
      <link>http://communities.vmware.com/thread/172836</link>
      <description>&lt;br /&gt;
VIM account password was changed on host&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Anyone know what this is? Saw it in my Cluster Task &amp;#38; Events.  Thanks</description>
      <pubDate>Tue, 07 Oct 2008 20:36:56 GMT</pubDate>
      <author>heybuzzz</author>
      <guid>http://communities.vmware.com/thread/172836</guid>
      <dc:date>2008-10-07T20:36:56Z</dc:date>
      <clearspace:dateToText>4 months, 2 weeks ago</clearspace:dateToText>
      <clearspace:messageCount>10</clearspace:messageCount>
      <clearspace:replyCount>9</clearspace:replyCount>
    </item>
    <item>
      <title>Objection from security folks to open 445, 139 and 902 for P2V</title>
      <link>http://communities.vmware.com/thread/169690</link>
      <description>&lt;br /&gt;
Folks,&lt;br /&gt;
&lt;p /&gt;
Why I'm getting objections to open these ports for P2V projects from DMZ servers -&amp;gt;VCMS-&amp;gt;ESX Hosts? I need some justifications to my reasons.  I told them its the ports required but not approve.  Any other reasons?&lt;br /&gt;
&lt;br /&gt;
If you found this information useful, please consider awarding points for "Correct" or "Helpful". Thanks!!! &lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Stefan Nguyen&lt;br /&gt;
iGeek Systems Inc.&lt;br /&gt;
VMware, Citrix, Microsoft Consultant</description>
      <pubDate>Fri, 19 Sep 2008 18:15:47 GMT</pubDate>
      <author>azn2kew</author>
      <guid>http://communities.vmware.com/thread/169690</guid>
      <dc:date>2008-09-19T18:15:47Z</dc:date>
      <clearspace:dateToText>1 year, 2 months ago</clearspace:dateToText>
      <clearspace:messageCount>10</clearspace:messageCount>
      <clearspace:replyCount>9</clearspace:replyCount>
    </item>
    <item>
      <title>FTP Account on ESX hosts</title>
      <link>http://communities.vmware.com/thread/163438</link>
      <description>&lt;br /&gt;
Hello people,&lt;br /&gt;
&lt;p /&gt;
 We are running security scans  against our hosts and came up with a vulnerability.   It is related to the ftp account on the esx host.  Is this account necessary?&lt;br /&gt;
&lt;p /&gt;
 Also have the following accounts;&lt;br /&gt;
&lt;p /&gt;
halt, sync, shutdown, ntp, nfsnobody.  Are these accounts necessary?&lt;br /&gt;
&lt;p /&gt;
Thanks in advance,&lt;br /&gt;
&lt;p /&gt;
Andy</description>
      <pubDate>Fri, 15 Aug 2008 19:22:09 GMT</pubDate>
      <author>Andy_Imm</author>
      <guid>http://communities.vmware.com/thread/163438</guid>
      <dc:date>2008-08-15T19:22:09Z</dc:date>
      <clearspace:dateToText>1 year, 3 months ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>ConfigCheck for ESX 3.0</title>
      <link>http://communities.vmware.com/thread/157319</link>
      <description>Just wanted to let you all know that Tripwire released a new version of ConfigCheck, the free utility to assess the Hypervisor against the VMware hardening guidelines, that can now monitor ESX version 3.0. The initial release only monitored 3.5 but after many requests from the community, we've added 3.0 support.&lt;br /&gt;
&lt;br /&gt;
Here is the &lt;a class="jive-link-external" href="http://www.tripwire.com/press/press_release/pr.cfm?prid=371"&gt;official announcement&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
Here is a &lt;a class="jive-link-external" href="http://www.tripwire.com/blog/?p=84"&gt;blog post&lt;/a&gt; on the subject&lt;br /&gt;
&lt;p /&gt;
Download the latest version from &lt;a class="jive-link-external" href="http://www.tripwire.com/configcheck"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;p /&gt;
Please let us know if you have any issues or comments on this latest release by replying to this post.&lt;br /&gt;
&lt;p /&gt;
Gavin Millard &amp;brvbar; Tripwire Inc.</description>
      <category domain="http://communities.vmware.com/tags?communityID=2004">configcheck;.3.0.2;</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">hardening;</category>
      <category domain="http://communities.vmware.com/tags?communityID=2004">security;</category>
      <pubDate>Mon, 21 Jul 2008 16:12:38 GMT</pubDate>
      <author>GavinMillard</author>
      <guid>http://communities.vmware.com/thread/157319</guid>
      <dc:date>2008-07-21T16:12:38Z</dc:date>
      <clearspace:dateToText>1 year, 4 months ago</clearspace:dateToText>
      <clearspace:messageCount>6</clearspace:messageCount>
      <clearspace:replyCount>5</clearspace:replyCount>
    </item>
    <item>
      <title>Virtual Center and SSHD</title>
      <link>http://communities.vmware.com/thread/155454</link>
      <description>&lt;br /&gt;
Is there any reason why my VirtualCenter server would be attempting to establish a SSHD connection to my hosts servers using the Windows Administrator account?  I've recently configured syslog to point to a SPLUNK server and have been noticing a lot of "Illegal user Administrator from x.x.x.x" errors where x.x.x.x is the IP address of the VirtualCenter/License server.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Jason</description>
      <pubDate>Wed, 09 Jul 2008 11:30:41 GMT</pubDate>
      <author>JDLangdon</author>
      <guid>http://communities.vmware.com/thread/155454</guid>
      <dc:date>2008-07-09T11:30:41Z</dc:date>
      <clearspace:dateToText>1 year, 4 months ago</clearspace:dateToText>
      <clearspace:messageCount>2</clearspace:messageCount>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>vmware-config and SELinux</title>
      <link>http://communities.vmware.com/thread/154976</link>
      <description>Hi,&lt;br /&gt;
&lt;br /&gt;
So far I've only tested this with a fedora host and vmware-server 1.x&lt;br /&gt;
&lt;br /&gt;
At times when you update a kernel, you'll have to recompile the kernel modules using the /usr/bin/vmware-config.pl script.&lt;br /&gt;
This is fine, however as it appears one of the things it touches is the /etc/services file.&lt;br /&gt;
If your host has SELinux enabled and enforced, then you'll get SELinux issues.&lt;br /&gt;
&lt;br /&gt;
At the end of the /etc/services file I see a vmware part:&lt;br /&gt;
&lt;pre class="jive-pre"&gt;&lt;code class="jive-code jive-plain"&gt;# Beginning of the block added by the VMware software
vmware-authd 904/tcp
# End of the block added by the VMware software
&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;
&lt;br /&gt;
It is known that we only need to relabel the file using&lt;br /&gt;
&lt;pre class="jive-pre"&gt;&lt;code class="jive-code jive-plain"&gt; restorecon -v /etc/services
&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;
&lt;br /&gt;
So here is a challenging idea, could this be made part of the reconfigure process? &lt;br /&gt;
Just so that you do not need to lower your security to "permissive" or patch up things afterwards in order to get it working again.&lt;br /&gt;
&lt;br /&gt;
thanks.&lt;br /&gt;
Wil</description>
      <pubDate>Fri, 04 Jul 2008 15:04:39 GMT</pubDate>
      <author>wila</author>
      <guid>http://communities.vmware.com/thread/154976</guid>
      <dc:date>2008-07-04T15:04:39Z</dc:date>
      <clearspace:dateToText>1 year, 4 months ago</clearspace:dateToText>
      <clearspace:messageCount>5</clearspace:messageCount>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Something really dum</title>
      <link>http://communities.vmware.com/thread/143937</link>
      <description>&lt;br /&gt;
Ok, ive gone and done something really done,  We have a new installation of VC, basically starting from scratch with new infrastructure.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Ive gone and added domain users into the no access security group, very smart i know.  &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
How do i reset permissions on VC?&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
Scott.T</description>
      <pubDate>Mon, 05 May 2008 01:38:18 GMT</pubDate>
      <author>Scott.T</author>
      <guid>http://communities.vmware.com/thread/143937</guid>
      <dc:date>2008-05-05T01:38:18Z</dc:date>
      <clearspace:dateToText>1 year, 6 months ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>If the Service Console and VMs are on different vlans (for Security) - where best to put the VC server?</title>
      <link>http://communities.vmware.com/thread/139869</link>
      <description>Hiya,&lt;br /&gt;
&lt;br /&gt;
I am just designing a secure ESX environment to be placed in a DMZ and be PCI compliant.&lt;br /&gt;
&lt;br /&gt;
I realise that the vmotion vlan should be inaccessible from both the SC and the VM vlans.&lt;br /&gt;
&lt;br /&gt;
I also realise that the SC vlan should ideally be isolated from the VM vlans.&lt;br /&gt;
&lt;br /&gt;
I'm less clear on where to put the VC server.&lt;br /&gt;
&lt;br /&gt;
I was initially thinking that it would be best on the same VLAN as the SC - with no access from that vlan to the VM vlans (as a VM that is able to access the VC, would presumably give rise to similar risks as a VM that can access the SC directly)?&lt;br /&gt;
&lt;br /&gt;
I then started to wonder if any VC specific functionality actually requires direct network access to the VMs themselves?&lt;br /&gt;
&lt;br /&gt;
Has anyone tried this - or does anyone know what (if any) requirements there are for VC to directly access the VMs via the VM vlans?&lt;br /&gt;
&lt;br /&gt;
The one thing that I was wondering about specifically was VCB (using a SAN). I know by default VCB will act on the IP address of the VM and then take the snapshots of the VMs via VC. I wasn't sure if they were completely separate activities though?&lt;br /&gt;
&lt;br /&gt;
i.e. is it just the VCB server that needs IP access to the VMs - or would the VC server also need it? Or is it all handled over the san based VCB LUN driver - so neither need access?&lt;br /&gt;
&lt;br /&gt;
If the VC server does need access for VCB - might it be possible to use the VM uids instead - or would this still require IP access to the VM vlans?&lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
&lt;br /&gt;
Dinny</description>
      <pubDate>Thu, 17 Apr 2008 10:20:07 GMT</pubDate>
      <author>dinny</author>
      <guid>http://communities.vmware.com/thread/139869</guid>
      <dc:date>2008-04-17T10:20:07Z</dc:date>
      <clearspace:dateToText>1 year, 7 months ago</clearspace:dateToText>
      <clearspace:messageCount>5</clearspace:messageCount>
      <clearspace:replyCount>4</clearspace:replyCount>
    </item>
    <item>
      <title>Any good for IBM codename "Phantom" to secure ESX hypervisor world at all?</title>
      <link>http://communities.vmware.com/thread/138131</link>
      <description>Has anyone familiar with IBM codename "Phantom" at all?  I'm curious what this project will do and help secure virtualization world especially ESX hypervisor and that's going to hit big next with security in the ESX.  How good is vmSafe any feedbacks would be nice to know.&lt;br /&gt;
&lt;br /&gt;
If you found this information useful, please consider awarding points for "Correct" or "Helpful". Thanks!!! &lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Stefan Nguyen&lt;br /&gt;
iGeek Systems LLC.&lt;br /&gt;
VMware, Citrix, Microsoft Consultant</description>
      <pubDate>Wed, 09 Apr 2008 12:14:21 GMT</pubDate>
      <author>azn2kew</author>
      <guid>http://communities.vmware.com/thread/138131</guid>
      <dc:date>2008-04-09T12:14:21Z</dc:date>
      <clearspace:dateToText>1 year, 7 months ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Is VI3 ESX 3.0.2 and VC 2.0.2 are EAL 2+ Certified?</title>
      <link>http://communities.vmware.com/thread/117401</link>
      <description>&lt;br /&gt;
Hi all,&lt;br /&gt;
&lt;p /&gt;
Is anyone know VI3 ESX 3.0.1 and VC 2.0.1 are EAL2+ certified? If so, is there a link to the document. Thanks.&lt;br /&gt;
&lt;p /&gt;
From the link below they are being reviewed for certification for EAL4+ certification. So, I assumed they have to be cerified at least with EAL 2+, but could not find any document to confirm that.&lt;br /&gt;
&lt;p /&gt;
&lt;a class="jive-link-external" href="https://exchange.x-feds.com/exchweb/bin/redir.asp?URL=http://www.cse-cst.gc.ca/services/common-criteria/ongoing-evals-e.html"&gt;https://exchange.x-feds.com/exchweb/bin/redir.asp?URL=http://www.cse-cst.gc.ca/services/common-criteria/ongoing-evals-e.html&lt;/a&gt;&lt;br /&gt;
&lt;p /&gt;
Cheers, &lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;br /&gt;</description>
      <pubDate>Fri, 14 Dec 2007 04:11:43 GMT</pubDate>
      <author>BacMan</author>
      <guid>http://communities.vmware.com/thread/117401</guid>
      <dc:date>2007-12-14T04:11:43Z</dc:date>
      <clearspace:dateToText>1 year, 11 months ago</clearspace:dateToText>
      <clearspace:messageCount>2</clearspace:messageCount>
      <clearspace:replyCount>1</clearspace:replyCount>
    </item>
    <item>
      <title>Windows Licensing Compliance &amp;#38; Hardware</title>
      <link>http://communities.vmware.com/thread/117190</link>
      <description>I've read a number of the forum discussion on Windows and licensing, as well as some of the provided links, but it seems they address issues for much more complex situations. We're a small company, and I'd like to have one server running three Windows 2003 R2 VMs. I always understood that with Microsoft, the OS is tied to the hardware. The discussions seem to imply that's not the case, but I haven't been able to locate the reference to this in Microsoft's licensing publications. Maybe I'm looking in the wrong place. &lt;br /&gt;
&lt;br /&gt;
*We wont' be using VMotion.&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
*We don't have applications that span servers&lt;br /&gt;
&lt;p /&gt;
*We'll only move the VM's once thelease for the hardware we're using is up and we replace it.&lt;br /&gt;
&lt;p /&gt;
&lt;p /&gt;
&lt;p /&gt;
So, which edition or licensing structure for Windwos 2003 R2 do I need to get so that it isn't tied to the hardware?&lt;br /&gt;
&lt;p /&gt;
&lt;br /&gt;
Does anyone have a link to a decent resource on the basics of Microsoft's licensing structure. It seems like every result I find through Microsoft is geared towards enterprise solutions.</description>
      <pubDate>Thu, 13 Dec 2007 00:36:59 GMT</pubDate>
      <author>cduncan</author>
      <guid>http://communities.vmware.com/thread/117190</guid>
      <dc:date>2007-12-13T00:36:59Z</dc:date>
      <clearspace:dateToText>1 year, 11 months ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>Application Licensing</title>
      <link>http://communities.vmware.com/thread/110288</link>
      <description>&lt;br /&gt;
Anyone out there familiar with Data Direct or other software vendors who license products by hardware processors? There is a hook in the application that interrogates the hardware to see how many processors and it is reporting the actual number of physical processors in the box even though we only dedicate one virtual processor to the app. We are trying to negotiate licensing with them to just go after virtual processors but they really don't seem to understand virtualization. Any suggestions?</description>
      <pubDate>Wed, 31 Oct 2007 14:53:03 GMT</pubDate>
      <author>ejsegrav</author>
      <guid>http://communities.vmware.com/thread/110288</guid>
      <dc:date>2007-10-31T14:53:03Z</dc:date>
      <clearspace:dateToText>2 years, 3 weeks ago</clearspace:dateToText>
      <clearspace:messageCount>6</clearspace:messageCount>
      <clearspace:replyCount>5</clearspace:replyCount>
    </item>
    <item>
      <title>ANNOUNCE: Catbird V-Agent, ESX Server Security System</title>
      <link>http://communities.vmware.com/thread/97666</link>
      <description>Hello:&lt;br /&gt;
&lt;br /&gt;
Do you know &lt;b&gt;anyone currently running VMware ESX Server&lt;/b&gt;, and seeking a security solution for their virtual infrastructure?&lt;br /&gt;
&lt;br /&gt;
I work for Catbird Security, and we have recently announced our Catbird V-Agent. &lt;br /&gt;
&lt;br /&gt;
For more details, please visit:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;  &lt;a class="jive-link-external" href="http://www.vmware.com/appliances/directory/953"&gt;http://www.vmware.com/appliances/directory/953&lt;/a&gt;&lt;br /&gt;
  &lt;a class="jive-link-external" href="http://www2.catbird.com/our_services/vagent_s.shtml"&gt;http://www2.catbird.com/our_services/vagent_s.shtml&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;V-Agent offers security services for ESX Server environments&lt;/b&gt;, and I am seeking to work with a few local users who would be interested in getting a free year of service, in exchange for your real-world testing and feedback. It is not a requirement that you go public with your use of our technology, but of course we would be happy to discuss any mutual interest in such.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;V-Agent High-level features include:&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
  -Network Access Control&lt;br /&gt;
  -Intrusion Detection/Prevention&lt;br /&gt;
  -Vulnerability Assessment&lt;br /&gt;
  -Windows Policy &amp;#38; Trusted Scan&lt;br /&gt;
&lt;br /&gt;
Additional External Security Services are also available.&lt;br /&gt;
&lt;br /&gt;
If you or a buddy are interested, and have an ESX Server (or many), please get in touch.&lt;br /&gt;
&lt;br /&gt;
The Eval process involves downloading and powering up our V-Agent (Certified VMware Virtual Machine), and running some internal discovery and scanning. Estimated time from power-up to results is about an hour.&lt;br /&gt;
&lt;br /&gt;
Thanks in advance!&lt;br /&gt;
&lt;br /&gt;
Howard Fried&lt;br /&gt;
Director, Sales Engineering&lt;br /&gt;
Catbird.com&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
PS This is a somewhat limited offer, and may expire soon, depending upon response. Thanks!&lt;/i&gt;</description>
      <pubDate>Thu, 09 Aug 2007 01:28:01 GMT</pubDate>
      <author>howardcat</author>
      <guid>http://communities.vmware.com/thread/97666</guid>
      <dc:date>2007-08-09T01:28:01Z</dc:date>
      <clearspace:dateToText>1 year, 5 months ago</clearspace:dateToText>
      <clearspace:messageCount>3</clearspace:messageCount>
      <clearspace:replyCount>2</clearspace:replyCount>
    </item>
    <item>
      <title>FIPS 140-2 Compliancy</title>
      <link>http://communities.vmware.com/thread/96814</link>
      <description>Is there any documentation out there regarding VI3 and FIPS 140-2?&lt;br /&gt;
&lt;br /&gt;
Thanks in advance.</description>
      <pubDate>Fri, 03 Aug 2007 18:40:10 GMT</pubDate>
      <author>langonej</author>
      <guid>http://communities.vmware.com/thread/96814</guid>
      <dc:date>2007-08-03T18:40:10Z</dc:date>
      <clearspace:dateToText>2 years, 3 months ago</clearspace:dateToText>
      <clearspace:messageCount>1</clearspace:messageCount>
    </item>
    <item>
      <title>Securing Sprawling Virtual Machines from Vulnerability-based Attacks</title>
      <link>http://communities.vmware.com/thread/69024</link>
      <description>Does anyone have any thoughts on the impact of virtualization on server security?  I was chatting with a security expert (who will be apparently speaking on an Interop panel in May) and he was genuinely concerned with the security impacts of: decoupled software and hardware; VM sprawl; software updates; and complex server stacks.&lt;br /&gt;
&lt;br /&gt;
He also said that HIPS/NIPS/Firewalls were never designed to protect these kinds of sprawling (hard to manage) environments.  Some of their functionality will continue to function, but any features tied to hardware-based signature processing (very common in mature security solutions) would be rendered "virtually irrelevant."&lt;br /&gt;
&lt;br /&gt;
Anyone have any thoughts?  Suggestions?</description>
      <pubDate>Sat, 20 Jan 2007 01:07:46 GMT</pubDate>
      <author>SecurityJunkie</author>
      <guid>http://communities.vmware.com/thread/69024</guid>
      <dc:date>2007-01-20T01:07:46Z</dc:date>
      <clearspace:dateToText>2 years, 8 months ago</clearspace:dateToText>
      <clearspace:messageCount>10</clearspace:messageCount>
      <clearspace:replyCount>9</clearspace:replyCount>
    </item>
  </channel>
</rss>

