Re: VMware ESX
- From: "Tyler Reguly" <ht@xxxxxxxxxxxxxxxxxxx>
- Date: Mon, 21 Apr 2008 23:49:30 -0400
Greetings,
My Advice could be to *NOT* do this...
This depends, somewhat, on the version of ESX you are running... ESXi
is 32MB and presents a much smaller attack surface that ESX. I would
never advise implementing ESX itself on both the internal network and
the DMZ, but I can't say for sure about implementing ESXi...
However keep this Microsoft Advisory in mind --
http://www.microsoft.com/technet/security/Bulletin/MS07-049.mspx
It is VirtualPC and VirtualServer but think about that.. Admin access
to any single guest, gives you access to all other guests and the
host... Who knows if that exists for VMWare and just hasn't been
stumbled across yet.
Tyler.
On Mon, Apr 21, 2008 at 6:54 PM, TVB NOC <tvbnoc@xxxxxxxxxxxxxxxxxxxxxx> wrote:
Actually,
I used to work at a company that did it... Because the VMware instances
are not aware of each other inside the host, its not a bad solution..
However, if I were going to implement it, I would not do VLANs and
Trunking (tagging) between the virtual switch and the physical switch. I
would add an additional quad card or other physical network card and
physically separate the VM host, plugging each isolated VMhost network
connection them directly into the physical switch...
Hope this helps... sorry for the grammatical errors too...
On Mon, Apr 21, 2008 at 5:23 AM, Paul Heywood
<Paul.Heywood@xxxxxxxxxxxxxxxxxxxx> wrote:
Hi forum,network. Our server team want to extend this to include some DMZ
we've got a VMware ESX group of servers running on the inside of our
servers. How vulnerable would this leave the internal network ? Am I
correct in thinking that if the VMware cluster was hacked, this would
give them access to the internal network
**********************************************************************
The information in this e-mail is confidential and may be legallyprivileged.
It is intended solely for the addressee. Access to this email byanyone else
is unauthorised. If you have received it in error, please notify usimmediately
by replying to this e-mail and then delete it from your system.presence of
This note confirms that this email message has been swept for the
computer viruses, however we advise that in keeping with good ITpractice the
recipient should ensure that the e-mail together with any attachmentsare virus
free by running a virus scan themselves. We cannot accept anyresponsibility for
any damage or loss caused by software viruses.Road, West Byfleet, Surrey UK KT14 6EZ.
The Unity Partnership Ltd, registered in England at West Hall, Parvis
Registered No : 5916336. VAT No : 903761336.**********************************************************************
--
"Dear God, save us from the people who believe in you." -- post-9/11
graffiti
- Follow-Ups:
- RE: VMware ESX
- From: TVB NOC
- RE: VMware ESX
- References:
- Re: VMware ESX
- From: Captain Quirk
- RE: VMware ESX
- From: TVB NOC
- Re: VMware ESX
- Prev by Date: RE: Tutorial on Wireless packet sniffing
- Next by Date: Re: Firewall for Windows Server 2003
- Previous by thread: RE: VMware ESX
- Next by thread: RE: VMware ESX
- Index(es):
Relevant Pages
|