vShield Suite

1,711 views

Published on

High level overview about vShield Suite of products.

Published in: Technology
0 Comments
0 Likes
Statistics
Notes
  • Be the first to comment

  • Be the first to like this

No Downloads
Views
Total views
1,711
On SlideShare
0
From Embeds
0
Number of Embeds
3
Actions
Shares
0
Downloads
81
Comments
0
Likes
0
Embeds 0
No embeds

No notes for slide

vShield Suite

  1. 1. vShield<br />
  2. 2. VMware® vShield is a suite of security virtual appliances built for protecting virtualized datacenters from attacks and misuse<br />vShield Components<br />vShield Manager<br />vShield Zones<br />vShield App<br />vShield Edge<br />vShield End Point<br />
  3. 3. vShield Manager<br />The vShield Manager is the centralized network management component of vShield suite and is installed from OVA as a virtual machine by using the vSphere Client.<br />Using the vShield Manager user interface, administrators install, configure, and maintain vShield components<br />
  4. 4. vShield Zones<br /><ul><li>vShield Zones, included with the vShield Manager, provides firewall protection for traffic between virtual machines
  5. 5. vShield App</li></ul>vShield App is an interior, vNIC‐level firewall that allows you to create access control policies regardless of network topology. A vShield App monitors all traffic in and out of an ESX host, including between virtual machines in the same port group. vShield App includes traffic analysis and container‐based policy creation.<br /><ul><li>vShield Edge</li></ul>vShield Edge provides network edge security and gateway services to isolate the virtual machines in a port group, vDS port group, or Cisco® Nexus 1000V.<br />Common deployments of vShield Edge include in the DMZ, VPN Extranets, and multi‐tenant Cloud environments where the vShield Edge provides perimeter security for Virtual Datacenters (VDCs).<br /><ul><li>vShield End Point</li></ul>vShield Endpoint delivers an introspection‐based antivirus solution. vShield Endpoint uses the hypervisor to scan guest virtual machines from the outside without a bulky agent<br />
  6. 6.
  7. 7. vShield Zones<br />
  8. 8.
  9. 9.
  10. 10.
  11. 11.
  12. 12. Firewall Rules<br />
  13. 13. vShield App<br />vShield App is an interior, vNIClevel firewall that allows you to create access control policies regardless of network topology. A vShield App monitors all traffic in and out of an ESX host, including between virtual machines in the same port group. vShield App includes traffic analysis and container‐based policy creation.<br />
  14. 14. vShield App<br />VMware vShield App, part of the VMware vShield family of virtualization security products, protects as applications in the virtual datacenter from network based threats. vShield App gives organizations deep visibility into network communications between virtual machines and enables granular policy enforcement with security groups. The solution also eliminates the hardware and policy sprawl associated through traditional measures, resulting in a cost-effective solution that helps customers to go beyond the limitations of physical security.<br />
  15. 15. Key Benfits<br /> Increase visibility and control over network communications between virtual machines.<br /> Eliminate the need for dedicated hardware<br />and VLANs to separate security groups from one another.<br /> Optimize hardware resource utilization while maintaining strong security.<br /> Simplify compliance with comprehensive logging of all virtual machine network activity.<br />
  16. 16. Vshield App enables Granular Policy Enforcement Using Security Groups<br />
  17. 17. vShield Edge<br />vShield Edge provides network edge security and gateway services to isolate the virtual machines in a port group, vDS port group, or Cisco® Nexus 1000V.<br />Common deployments of vShield Edge include in the DMZ, VPN Extranets, and multi‐tenant Cloud environments where the vShield Edge provides perimeter security for Virtual Datacenters (VDCs).<br />
  18. 18.
  19. 19. Consolidate edge security hardware: Provision edge security services, including firewall and VPN, using existing vSphere resources, eliminating the need for hardware-based solutions.<br />
  20. 20. Ensure performance and availability of web services: Efficiently manage inbound web traffic across virtual machine clusters with web load balancing capabilities<br />
  21. 21. Accelerate IT compliance: Get increased visibility and control over security at the network edge, with the logging and auditing controls you need to demonstrate compliance with internal policies and external regulatory requirements<br />
  22. 22. vShield End Point<br />vShield Endpoint delivers an introspection‐based antivirus solution. vShield Endpoint uses the hypervisor to scan guest virtual machines from the outside without a bulky agent<br />
  23. 23.
  24. 24. Streamline antivirus and anti-malware deployment: Deploy enterprise antivirus engine and signature file to a single security virtual machine instead of each and every individual virtual machine on a vSphere host<br />
  25. 25. Improve virtual machine performance: Securely achieve higher consolidation ratios by the same offload mechanism as described above<br />
  26. 26. Prevent antivirus storms and bottlenecks: Prevent antivirus storms and bottlenecks associated with multiple simultaneous antivirus and anti-malware scans and updates<br />
  27. 27. Protect antivirus security software from attack: Deploy and run the antivirus and anti-malware client software in a hardened security virtual machine to prevent targeted attacks<br />

×