VMware Cloud Community
Nelsom
Contributor
Contributor
Jump to solution

TrendMicro Deep Security 8 with vCenter 4.1 / ESX4.1?

For some reasons we will continue to use the vCenter 4.1 / ESX(i) 4.1 environment for a while.

My questions are:

  1. Can I use TrendMicro Deep Security 8 SP1 with vSphere 4.1 or do I need to use Deep Security 7.5? I noticed I can use vShiled 5.0 with vSphere 4.1 (http://esupport.trendmicro.com/solution/en-us/1060131.aspx)
  2. if Deep Security 8 SP1 is not possible and we need to use Deep Security 7.5, can I manage and monitor physical systems with the Trend Agent installed in the same Deep Security Manager I use for my virtual machines (agentless)?
  3. what features will we miss by using Deep Security 7.5 / vSphere 4.1 compared to Deep Security 8 / vSphere 5?

Thanks,

Nelcon.

0 Kudos
1 Solution

Accepted Solutions
JonathanG
Enthusiast
Enthusiast
Jump to solution

You can use Deep Security 8 with vCenter/ESx 4.1, but you must use vShield 5

ESX must be on patch 3 (build 702113) http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=201986...

so that guest VMs can install Endpoint from VMtools (yes guests have to upgrade VMtools)

(full disclosure I work for Trend Micro)

Jonathan

View solution in original post

0 Kudos
4 Replies
JonathanG
Enthusiast
Enthusiast
Jump to solution

You can use Deep Security 8 with vCenter/ESx 4.1, but you must use vShield 5

ESX must be on patch 3 (build 702113) http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=201986...

so that guest VMs can install Endpoint from VMtools (yes guests have to upgrade VMtools)

(full disclosure I work for Trend Micro)

Jonathan

0 Kudos
Arrow1
Enthusiast
Enthusiast
Jump to solution

Hi,

As far as I'm aware, this could works however I deployed DS8 SP1 after upgrading my vCenter to 5 managing esx 4.1 hypervisors.

At this time, I have following:

One ESXi 5 running both

  • vCenter 5 (5.0.0 build 455964)
  • vShield manager 5  (5.0.2 build 791471)

2 ESXi 4.1 (4.1.0 build 721871 which should be close Update2) with vShield Endpoint activated (installed) running

  • a dsva virtual appliance (one per ESX)
  • several protected machines

All 3 ESXs are managed by the vCenter 5.

In each protected machine;

  • I have installed vmware tools (VMware-tools-8.6.0-446312-x86_64) downloaded from http://packages.vmware.com/tools/esx/5.0p01/windows/index.html
  • During installation I have fololwed "To install the Endpoint vShield drivers" as documented in "Deep Security™ 8.0 Getting Started and Installation Guide" (page 42) so that to make sure Endpoint drivers as installed
  • I have also installed DS Notifier (DeepSecurity 8 Notifier-Windows-8.0.0-1733.i386).
    This is not mandatory but this provide feedback to user in case a virus or something is detected.
    See "Installing the Deep Security Notifier" on page 82 of the above referenced DS8 started guide.
    Here is a video I made : http://youtu.be/KMheWEYvrac 

This done, all DS8 features well work (anti-malware, web reputation, firewall...) only Log inspection is not available unless you also deploy DS agent in a VM (this is named coordinated approach).

My DS8 manager (Deep Security Manager ( )) and the SQL database are both located on another Vmware environment.

Hope this will help

Regards

Bernard

Regards Bernard
Nelsom
Contributor
Contributor
Jump to solution

Thank you for your quick response Jonathan, my questions are answered.

I will use:

  • Deep Security Manager 8 SP1
  • vShield 5 Endpoint 5.0.2
  • DSVA 8 SP1
  • vCenter 4.1 U0 (current) or U2
  • ESX4.1 U2 + patch 3 (build 702113)
  • In Windows vm: DeepSecurity 8 Notifier-Windows-8.0.0-1733.i386

Regards,

Nelcon.

0 Kudos
Nelsom
Contributor
Contributor
Jump to solution

..and thank you Bernard, your detailed information is very helpfull. I wasn't aware of the DS Notifier, we will use that one for sure.

Regards,

Nelcon.

0 Kudos