« Top Ten Strategic Security Metrics | Main | Mozilla-mania and Security Metrics »

VMware and Virtual DMZs

Chris Hoff posts about VMware's recently released DMZ whitepaper. It shows three different approaches to DMZ architectures and discusses their strengths and weaknesses:

  1. Partially collapsed with physical zone separation. In this architecture, you put VMs of the same trust level on the same physical boxes and separate them using traditional firewalls.
  2. Partially collapsed with virtual zone separation. In this architecture, you put VMs of different trust levels (across DMZ zones) all on the same box, then pump the traffic in and out physical NICs and through physical firewalls accordingly.
  3. Fully collapsed puts everything in the virtual environment.

As is par for the course these days, VMware makes an outlandish security claim that there are no "significant" changes to the topology (errr, adding a separate management/control zone and creating virtual networks seem topologically different to me...). Other than that, it is a pretty decent review of the options.

Here are some tips for thinking about virtual DMZs. (For those who have been reading along, immutable laws 3 and 4 apply here).

  1. If you are moving from no zone separation to virtual zone separation, you are better off (law 3). This is unlikely simply because most folks already have zoned architectures.
  2. If you have your physical DMZ components all hanging off the same switch, you are probably at about the same risk level as option 2 above, where you still have physical firewalls.
  3. The only real benefit between option 2 above and option 3 is that the attack vector through the the firewalls is not factored into the virtualized environment risk. This is fairly minor in my book.
  4. The added hypervisor attack surface is the real question mark (ooops, there's law 2 as well). Probably not a big deal right now, but with still unknown future ramifications.

More on this and other security implications as they come up.



TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345207f669e200e5539c25508834

Listed below are links to weblogs that reference VMware and Virtual DMZs:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment