Re: VM Host with guests on the Internal and DMZ networks



On 6/11/07, Megan Kielman <megan.kielman@xxxxxxxxx> wrote:
Security Folks,

We want to have a VMWare host (VMWare Server) that has guest systems
on the DMZ and Internal LAN. To accomplish this the host would have
two interfaces, one on each network. Is this a really bad idea from
a security perspective?

Probably, but it really depends on a lot of things, some of which
include:

* your policies regarding on hosts being dual homed to different
trust zones
* the VMWare host OS/device

Perhaps the best way to answer that question would be to leave VMWare
out of it and ask yourself whether you would allow any other host to
have an interface in the DMZ and internal LAN.


What are some ways to mitigate the risks?

It sounds like you're planning on installing VMWare on a host (as
opposed to a VMWare supplied device, etc.). If that's the case,
it would likely be a good idea to select an OS which offers robust and
flexible routing/firewall/logging configurations, so that you could properly
seperate traffic on the host OS.

Alternatively, it may make sense to simply put some form of a dedicated
firewall appliance in front of the VMWare host and connect to that ...

Either way, it would probably be wise to ensure logging on the host was
properly configured and reviewed, but these are things which should
be determined by your own company (or personal) policies.

My 2 bits =)

--
jason



Relevant Pages

  • RE: Re: Re: VM Host with guests on the Internal and DMZ networks
    ... So are you saying that you should put your HOST in the DMZ. ... NIC and then add and IP Address that would work on the inside network while ... I would question the sysadmins level of competency. ...
    (Security-Basics)
  • Re: DMZ Arguments....
    ... A DMZ is used with a firewall, ... link to the rest of the network. ... A common approach for an attacker is to break into a host that's vulnerable ... the case of a web server, unauthenticated and untrusted users might be ...
    (Security-Basics)
  • [NEWS] SMC Barricades Dodgy "DMZ" Feature
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... hosts in a DMZ should not be ... able to initiate connections to internal LAN hosts. ... DMZ host be compromised (from having its connected-to-from-the-internet ...
    (Securiteam)
  • Re: DNS inside the DMZ on an 877
    ... the dmz to refer to external DNS servers for hosts outside the DMZ ... any host outside the DMZ. ... permit tcp host 192.168.168.2 host 10.0.0.10 eq 636 ... match access-group name adam ...
    (comp.dcom.sys.cisco)
  • RE: VM Host with guests on the Internal and DMZ networks
    ... DMZ and internal thus crossing our internal firewall....but with vmware ... VM Host with guests on the Internal and DMZ networks ... Attacks local to the guest allow the guest to attack the host. ...
    (Security-Basics)