VMware

Security & vShield Zones

Security & regulatory compliance, and VMware® vShield Zones

Hide This Message

A New Generation of vShield Security Products by Charu at Jul 26, 2010 2:07 PM

We are pleased to announce the availability of beta for two new vShield products:

  • vShield App 1.0 dynamically protects applications within the virtual data center (vDC) from internal threats by ensuring proper segmentation and enforcing rules on business-defined Security Groups.
  • vShield Edge 1.0 provides a set of perimeter services akin to a DMZ, protecting a customer virtual datacenter or organization and intended to be the boundary between the Service Provider (internal or public) and a tenant organization. vShield Edge also provides network services such as DHCP, VPN, NAT and load balancing.

VMware vShield App is a hypervisor-based, application-aware firewall for virtual data centers (vDCs) which runs on vSphere™ 4 hosts. vShield App protects against web based threats and reduces the risk of policy violations within the vDC with essential security capabilities:
  • Application aware firewall with deep packet inspection
  • Flow monitoring to analyze inter-VM traffic to dynamically enforce security policies
  • Security Groups to simplify policy definition based on business needs
  • Stateful firewall: basic connection control based on source/destination IP address

vShield App reduces the need for physical firewalls and addresses blind spots by enforcing security policies for inter-VM traffic. Once created, firewall rules accompany VMs dynamically. This change-aware protection prevents sprawl of firewall rules. The hypervisor-based firewall provides introspection of all traffic at the hypervisor layer and eliminates the need for VM connection control using host-based firewalls. This approach improves performance and provides centralized control over all inter-VM traffic.

vShield Edge eliminates sprawl in hardware and static firewall rules, while also reducing costs and complexity. The distributed architecture drives vDC traffic to its own dedicated network security gateway eliminating performance bottlenecks. vShield Edge accelerates IT compliance and satisfies audit requirements through detailed logging of edge security events and by enabling appropriate views and controls to different administrative groups.

Both vShield App and vShield Edge are managed using vShield Manager and integrate tightly with VMware vSphere and VMware vCenter Server.

vShield App and vShield Edge are now in a widespread public beta and may be obtained at the following URLs:

If you have recently participated in VMware betas (vSphere 4.1, etc.): http://communities.vmware.com/community/beta/vshield_edge_10_public

If you are an EXISTING community user without beta access: http://www.vmware.com/publicbeta/vShield-Edge-Beta

If you are NEW community user (don’t have a community account): http://www.vmware.com/publicbetanew/vShield-Edge-Beta

We welcome you to try out these products and provide us your feedback.

Documents

Statistics: Documents: 6
Items per page Filter: RSS feed of this list

Latest Poll

Have you hardened your ESX/VI3 Server? Yes, use of esxcfg-firewall only (26%) Yes, use linux hardening script (3%) Yes, use ESX specific hardening script (11%) No, behind a firewall (37%) No, I feel safe with defaults (24%) Votes 38 - Full Results

VMware Beta Programs

Want to be Considered for Future Beta Programs?

Learn More

VMware Developer

Download SDKs, APIs, videos,
training, and more in the Developer community.

Learn More

Developer
Sample Code

Increase your developer productivity with VMware API sample code.

Learn More

VMworld
Sessions & Labs

Online access to the latest VMworld Sessions & Labs and online services.

Learn more

Purchase PSO Credits Online

Purchase credits to redeem training and consulting services online.

Buy Now

Community Hardware Software

View reported configurations or report your own.

Learn More

Only VMware ... Delivers Nexus 1000V

Ensure consistent, policy-based network capabilities to virtual machines across your data center.

Learn More

Top Members

Communities