VMware Cloud Community
Dgray1906
Contributor
Contributor

product suggestions

Hello,

Due to security concerns, we recently have been told that we need to build and migrate to a new network. Currently we a running 3 hosts all with direct storage on a vDS and  a total of 40 servers between them. Our network is extremely simple, one internal subnet and a DMZ with another subnet. Could we benefit from EVO:rails or NSX and if so, how do we go about getting the right gear for our new network?

5 Replies
Texiwill
Leadership
Leadership

Hello,

With that simple of a setup, I am not sure you need more than you already have actually. First we would need to know:

     * What Security Concerns there are?

     * What Security you already have in place?    

  

I run a simple but layered network with DMZ + various other trustzones using nothing but VDS and properly placed security controls. you may need to just beef up those controls, rearrange some others. You may not even need anything more than you already have. There is a lot of misinformation about Security these days, do not make the mistake of thinking there is something you need that you do not already have. Again we need the answer to the first two questions.


BTW, I have built a Secure Hybrid Cloud Reference Architecture (currently being updated) that is a good guide for virtualization and security. Send a private message if you wish to chat more on this.

Best regards,
Edward L. Haletky
VMware Communities User Moderator, VMware vExpert 2009-2015

Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.

Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
Dgray1906
Contributor
Contributor

We are a nonprofit and were told that we have to meet DoD  regulations because of the type of data we have. It was just easier to build new than to correct all the issues. I agree that we could probably handle much of this without anything additional, but we have 2 months to get the new network up and accredited.

0 Kudos
Texiwill
Leadership
Leadership

Hello,

Yes, DoD requirements are different, but that does not imply you cannot meet them. The real question is what do you currently have and what are the failings, then we can see what is required to bring up the level of security to where it is needed.

There is literally NO product that will do that. There are tools that comprise a solution but nothing that says, install me and you are magically certified.

It will most likely take less time to change/reconfigure than reinstall, move, and re-configure/change the new base. EVO Rail for example has all the serious issues that every other virtual environment has, it just needs a different style of configuration. NSX out of the box, for example is NOT DoD certified, it needs pretty hefty configuration to get you there.

So the key is to know where you are, where you have to go and get there. BTW, if you have to pass the DISA STIG for example, the tool they have is ludicrous and difficult to use, there are others that are much easier and will show you what you need to clear up. BTW, the STIG is really from VMware's own hardening guide. You just wan the most secure configuration. Yet that is compliance not necessarily security.

Send me a private message, let's arrange a time to at least chat.

Best regards,
Edward L. Haletky
VMware Communities User Moderator, VMware vExpert 2009-2015

Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.

Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos
Dgray1906
Contributor
Contributor

I'm new to vmware communities and I'm not sure how to send direct messages on here. I would like to see the guide.

0 Kudos
Texiwill
Leadership
Leadership

Hello,

Hover over my name and you will see the ability to send a message.

Best regards,

Edward

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos