VMware Cloud Community
jof
Enthusiast
Enthusiast

DMZ virtualization - vShield required?

Hi,

Just looking for some thoughts on this subject.

I know there has been a lot of discussion around the virtualization of DMZs but i am wondering what model are people generally seeing for this currently.

Some of the ones I have come across are:

1) Separate vSphere hosts for the DMZ (question arises about the loaction of vCenter, internal zone or in the DMZ)

2) Separate vSwitch and pNIC for the DMZ

3) Use of VLANs and port groups to segragate the DMZ

In particular for scenario's 2 & 3 above does the addition of vShield App provide any additional benefit in segrating the DMZ VMs from the Internal VMs. Or would a better approach be to use vShield Edge to isolate the trust zones from each other.

Any thoughts welcome.

Thanks.

0 Kudos
2 Replies
danx1000
Contributor
Contributor

You could do the 3rd option with a software based router (such as Vyatta) running in a VM instead of vShield Edge.

0 Kudos
logiboy123
Expert
Expert

This is really a risk management issue rather then a design best practice. There are a lot of ways to ensure proper segmentation and/or isolation of the DMZ from Production systems.

I have built perfectly secure solutions where DMZ VMs run on the same hardware (including physical switches) that Production uses.

It really depends on (to name but a few considerations);

1) Budget.

2) Corporate Policies.

3) Network Topology .

If we start with the concept that the business is not comfortable sharing hardware with Prod (typically old school thinking), then I pitch the following idea;

Build a DMZ cluster connected to seperate physical switches for VM Networking. For Managment, vMotion and Storage use the same infrastructure as Production systems. There is no "VM bleed through" between the physical and virtual layer unless the vSphere platform is built incorrectly. There are plenty of good vSphere Consultants who can help you build a safe and secure design solution. In this situation the question of vShield become redundant, unless you would like to have segmentation within the DMZ itself, in which case there is a good usage case for vShield App.

Regards,

Paul

0 Kudos