VMware Cloud Community
handian08
Enthusiast
Enthusiast
Jump to solution

Ransomware Protection

Hello,

What can we do to improve our esxi from ransomware attack?

Labels (1)
Reply
0 Kudos
1 Solution

Accepted Solutions
pmichelli
Hot Shot
Hot Shot
Jump to solution

1: Close SSH access to all your ESXi servers and vCenter. Only enable when necessary

2: Do not expose your ESXi or vCenter to the internet. Use a VPN to access them

3: Stop joining your VC and ESXi to Active Directory.  If your AD gets hacked, they will move with domain credentials to your VMware environment.  

This is a good start

View solution in original post

3 Replies
pmichelli
Hot Shot
Hot Shot
Jump to solution

1: Close SSH access to all your ESXi servers and vCenter. Only enable when necessary

2: Do not expose your ESXi or vCenter to the internet. Use a VPN to access them

3: Stop joining your VC and ESXi to Active Directory.  If your AD gets hacked, they will move with domain credentials to your VMware environment.  

This is a good start

scott28tt
VMware Employee
VMware Employee
Jump to solution

Apply patches and updates.

The attacks in the press at the moment are only applicable to hosts that have not been updated in the last 2 years or more.

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
Reply
0 Kudos
depping
Leadership
Leadership
Jump to solution


@pmichelli wrote:

1: Close SSH access to all your ESXi servers and vCenter. Only enable when necessary

2: Do not expose your ESXi or vCenter to the internet. Use a VPN to access them

3: Stop joining your AD and ESXi to Active Directory.  If your AD gets hacked, they will move with domain credentials to your VMware environment.  

This is a good start


I think these are probably the best start. Other thing to mention, have a separate management network for ESXi. Make sure that you provide service accounts (backup etc) the correct roles, to often people use Admin accounts for those purposes.

 

Reply
0 Kudos