Expert analysis and advice on server virtualization technologies, deployments and management.
Our blogger: Bernard Golden is CEO of consulting firm HyperStratus, which specializes in virtualization, cloud computing and related issues. He is also the author of "Virtualization for Dummies," the best-selling book on virtualization to date.
Virtual Servers in the DMZ Pose Security Risks
PAGE 2
This level of protection makes it impossible for a network attack against the DMZ to pivot directly to any other network on the ESX server unless an administrator purposefully creates a misconfiguration.
Security administrators need to understand the impact of virtualization and be ready to combat any attack on a virtual machine, just as they do for physical machines.
Yet, they cannot ignore the fact the VMware ESX and VMware ESXi provide networking functionality designed to match old-school expectations of physical equipment, but in the virtual space. Security and network administrators need to stop thinking of a VMware ESX host as just a box, and start treating it as a data center whose networks should be managed, monitored and assessed.
If you do not, and you allow a virtualization server within your DMZ, it is most likely has been configured without safeguards that will keep virtual machines from connecting to the vital networks that should have no direct connections to anything within the DMZ.
If this sounds like your approach, stop, disconnect all cables and start over; you are definitely insecure and courting disaster.
Virtualization expert Edward L. Haletky is the author of "VMWare ESX Server in the Enterprise: Planning and Securing Virtualization Servers," Pearson Education (2008.) He recently left Hewlett-Packard, where he worked in the Virtualization, Linux, and High-Performance Technical Computing teams. Haletky owns AstroArch Consulting, providing virtualization, security, and network consulting and development. Haletky is also a champion and moderator for the VMware discussion forums, providing answers to security and configuration questions.
Find out what vendors offer the products you need.
View the Vendor Matrix »


