VMware Cloud Community
Skolnick2011101
Contributor
Contributor

vShield Endpoint Questions (Deep Security Purposes)

Hello everyone,

I've recently tried my hand at the Deep Security solution. And as you all know vShield Endpoints are required to make the solution work. I've been having some problems with updating a Test VM i have set up and also mentions of Out of Sync Interfaces on this same machine. But to cut the story short, I was checking out the vShield tab on my vCenter and realized that my Test VM has a status of "UNPROTECTED". Does this mean that the vShield Endpoint was installed incorrectly on this machine? Or something else entirely? Any help would be greatly appreciated, thank you.

0 Kudos
7 Replies
JonathanG
Enthusiast
Enthusiast

interfaces out of sync usually means that the vShield or Deep Security cannot communicate with the Endpoint driver on the guest VM

"unproctected" in the vShield console may mean there are no vShield policies on the VM

0 Kudos
Skolnick2011101
Contributor
Contributor

I can ping the Test machine from both the vShield Appliance and the DSM, is there any other way to test the communication with the endpoint driver specifically?

Actually I just noticed that in the vShield Endpoints Health and Alarms all the stats say (0) 100% Normal. This is probably the issue. But now I ask, I installed the Vmware vShield Endpoint Driver, and installed the vShield Endpoint on the the ESXi. Is there anything else I had to do? Anything I can double-check?

0 Kudos
Skolnick2011101
Contributor
Contributor

Sorry to add another reply, but I also noticed in the Host Information Tab below Endpoint Enabled that it says No,does this mean that the Endpoint didn't actually install on my host?

0 Kudos
AlbertKramer
Contributor
Contributor

is Vshield for endpoint properly licensed? Is the vshield component installed on the ESX host? furthermore are you using the latest version of Deep Security (2011-10-24)?

0 Kudos
GreatWhiteTec
VMware Employee
VMware Employee

0 Kudos
JonathanG
Enthusiast
Enthusiast

"DVDMorera"

The patch you sent applies to ESXi 5.0 & Endpoint 5.0 for which Deep Security 8 is the required version.

I believe that "Skolnick" is using DeepSecurity 7.5 which is compatible with ESX 4.1 and Endpoint 1.0

Skolnick2011101
Contributor
Contributor

It was a compatibility issue at the end indeed. I downloaded all the new DS/vShield Manager software but didn't bother to check compatibility with my ESXi, everything is good now. The DS anti-malware is working excelently! Thank you all for your help and replies.

0 Kudos