<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>2vcps and a Truck &#187; vShield Zones</title>
	<atom:link href="http://www.2vcps.com/tag/vshield-zones/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.2vcps.com</link>
	<description></description>
	<lastBuildDate>Mon, 23 Jan 2012 15:33:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="search"
           href="http://www.2vcps.com/opensearch"
           type="application/opensearchdescription+xml"
           title="Content Search" /><xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>vSheild Zones My First Look</title>
		<link>http://www.2vcps.com/2009/07/02/vsheild-zones-my-first-look/</link>
		<comments>http://www.2vcps.com/2009/07/02/vsheild-zones-my-first-look/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 18:20:00 +0000</pubDate>
		<dc:creator>Jon Owings</dc:creator>
				<category><![CDATA[vShield]]></category>
		<category><![CDATA[vsphere]]></category>
		<category><![CDATA[vShield Zones]]></category>

		<guid isPermaLink="false">http://2vcps.com/2009/07/02/vsheild-zones-my-first-look/</guid>
		<description><![CDATA[So my first experience trying to deploy the new vShield Zones security product included in VMware&#8217;s vSphere. First vShield Zones is different than VMsafe. The way I understand it is the vShield Zones is like your border security but inside &#8230; <a href="http://www.2vcps.com/2009/07/02/vsheild-zones-my-first-look/">Continue reading <span class="meta-nav">&#8594;</span></a>
Related posts:<ol>
<li><a href='http://www.2vcps.com/2009/11/09/upgrade-to-vsphere-already/' rel='bookmark' title='Upgrade to vSphere already'>Upgrade to vSphere already</a></li>
<li><a href='http://www.2vcps.com/2009/02/10/secure-to-the-hosted-vm/' rel='bookmark' title='Secure to the Hosted VM'>Secure to the Hosted VM</a></li>
<li><a href='http://www.2vcps.com/2009/04/01/esx-commands-esxcfg-firewall/' rel='bookmark' title='ESX Commands &#8211; esxcfg-firewall'>ESX Commands &#8211; esxcfg-firewall</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>So my first experience trying to deploy the new vShield Zones security product included in VMware&#8217;s vSphere.</p>
<p>First vShield Zones is different than VMsafe. The way I understand it is the vShield Zones is like your border security but inside of the vSphere. It divides and segregates networks and virtual machines. The VMsafe is end point protection built into the kernel. <a href="http://reflexsystems.com">Reflex</a> has the first VMsafe certified appliance but I have not had a chance to try it yet. (Need more hardware hint hint)</p>
<p>The <a href="http://www.vmware.com/support/pubs/vsz_pubs.html">User Guide</a> talks about downloading an appliance but you actually download an ISO then run an installer that unzips a folder with the 2 appliances. One is the vShield Zones Manager and the other is the actual firewall. The extra step of using the ISO image was annoying buy I guess I am just a whiner. On a super basic level, (I am not here to re-write the <a href="http://www.vmware.com/support/pubs/vsz_pubs.html">user guide</a>) Import the appliance for the manager then import the firewall. Convert the firewall into a template. The Manager appliance takes care of the rest. Note: Internet Explorer 8 and the Manager Web UI don&#8217;t work. I used IE 7 just fine.</p>
<ol>
<li>You won&#8217;t get this far in IE8 <img src='http://www.2vcps.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> <a href="http://4.bp.blogspot.com/_Ynay7ILHK2U/Skz8f9Q6dtI/AAAAAAABFFM/zu7F2ghXJKI/s1600-h/vShieldLogin.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5353931682988324562" src="http://4.bp.blogspot.com/_Ynay7ILHK2U/Skz8f9Q6dtI/AAAAAAABFFM/zu7F2ghXJKI/s400/vShieldLogin.jpg" border="0" alt="" /></a></li>
<li>Deploying the vShield is straight forward. It creates new vSwitches and port groups and the Manager UI indicates which network is protected and unprotected. This is not in Virtual Center still in the Web Interface.<a href="http://2.bp.blogspot.com/_Ynay7ILHK2U/Skz8JFSDTsI/AAAAAAABFE0/_3sPGeqTPrs/s1600-h/InstallvShieldappliance.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5353931290003590850" src="http://2.bp.blogspot.com/_Ynay7ILHK2U/Skz8JFSDTsI/AAAAAAABFE0/_3sPGeqTPrs/s400/InstallvShieldappliance.jpg" border="0" alt="" /></a></li>
<li><a href="http://1.bp.blogspot.com/_Ynay7ILHK2U/Skz8f6YP0nI/AAAAAAABFFU/vUkT6BvHJzY/s1600-h/vShieldnetworkconfig.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5353931682213778034" src="http://1.bp.blogspot.com/_Ynay7ILHK2U/Skz8f6YP0nI/AAAAAAABFFU/vUkT6BvHJzY/s400/vShieldnetworkconfig.jpg" border="0" alt="" /></a></li>
<li> As you deploy the vShield enjoy watching the tasks in vCenter.<br />
<a href="http://1.bp.blogspot.com/_Ynay7ILHK2U/Skz8fdddC_I/AAAAAAABFE8/r_3Muxgt3-4/s1600-h/tasksInstall.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5353931674450988018" src="http://1.bp.blogspot.com/_Ynay7ILHK2U/Skz8fdddC_I/AAAAAAABFE8/r_3Muxgt3-4/s400/tasksInstall.jpg" border="0" alt="" /></a></li>
</ol>
<p>All things considered it is a good product I don&#8217;t have enough throughput on my little lab machine to really test any impact using vShields would have on performance. If you are a Service Provider I think it would be a great add on to ensure some separation of virtuals.</p>
<p>Related posts:<ol>
<li><a href='http://www.2vcps.com/2009/11/09/upgrade-to-vsphere-already/' rel='bookmark' title='Upgrade to vSphere already'>Upgrade to vSphere already</a></li>
<li><a href='http://www.2vcps.com/2009/02/10/secure-to-the-hosted-vm/' rel='bookmark' title='Secure to the Hosted VM'>Secure to the Hosted VM</a></li>
<li><a href='http://www.2vcps.com/2009/04/01/esx-commands-esxcfg-firewall/' rel='bookmark' title='ESX Commands &#8211; esxcfg-firewall'>ESX Commands &#8211; esxcfg-firewall</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.2vcps.com/2009/07/02/vsheild-zones-my-first-look/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

