Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Firewalls
virtual firewalls -- compliance May 08 2008 07:37PM
Terry (td3201 gmail com) (10 replies)
Re: virtual firewalls -- compliance Jun 11 2008 12:40PM
styler (styler1974 gmail com) (1 replies)
RE: virtual firewalls -- compliance Jun 12 2008 03:29AM
Craig Wright (Craig Wright bdo com au)
Re: virtual firewalls -- compliance May 12 2008 07:37AM
Babu.N (babun intoto com)
Re: virtual firewalls -- compliance May 11 2008 01:35AM
David M. Zendzian (dmz dmzs com)
Re: virtual firewalls -- compliance May 10 2008 11:18PM
Erik Harrison (eharrison gmail com) (1 replies)
Re: virtual firewalls -- compliance May 13 2008 05:25AM
Chris Brenton (cbrenton chrisbrenton org)
Re: virtual firewalls -- compliance May 10 2008 02:08PM
Ron Brown (brownr mmc org)
Re: virtual firewalls -- compliance May 10 2008 02:02PM
Chris Clymer (chris chrisclymer com)
Re: virtual firewalls -- compliance May 10 2008 12:00AM
Joseph Jenkins (maillist breathe-underwater com)
RE: virtual firewalls -- compliance May 09 2008 11:51PM
Craig Wright (Craig Wright bdo com au) (1 replies)
RE: virtual firewalls -- compliance May 12 2008 04:53PM
Dan Lynch (DLynch placer ca gov) (1 replies)
RE: virtual firewalls -- compliance May 12 2008 09:24PM
Craig Wright (Craig Wright bdo com au) (1 replies)
Re: virtual firewalls -- compliance May 20 2008 01:23PM
David M. Zendzian (dmz dmzs com) (1 replies)
Re: virtual firewalls -- compliance May 20 2008 10:19PM
David M. Zendzian (dmz dmzs com)
RE: virtual firewalls -- compliance May 09 2008 11:34PM
Srinivasa Addepalli (srao intoto com)
Re: virtual firewalls -- compliance May 09 2008 11:30PM
Jeremiah Cornelius (jeremiah nur net)
I have done this - where the various firewall interfaces are bridged to
real, isolated nics, and to virtual internal networks that connect to VMs
with specific services.

The mistake is to think of VMware as an additional security measure. It can
be configured in a way to enforce a security architecture or policy - but is
not itself a mitigating factor.

It is a good way to partition a server for multiple Internet workloads -
SMTP Smarthost on one VM, SSL Webserver on another, WebMail server on a
third, and the firewall on a fourth. No one connects to the Internet except
through the firewall. No VM connects to another except through vnets that
the firewall enforces policy on.

At the cost of a couple of NICs, you can assign a specific DMZ to each of
these hosts - not a bad strategy, if clearly planned.

As a technology I view its use similarly to chrooted environments.
Policy-based isolation - but extending to the network, not just the
filesystem.

-- Jeremiah

--------------------------------------------------
From: "Terry" <td3201 (at) gmail (dot) com [email concealed]>
Sent: Thursday, May 08, 2008 12:37 PM
To: <firewalls (at) securityfocus (dot) com [email concealed]>
Subject: virtual firewalls -- compliance

> Hello all,
>
> I am throwing around the idea of using linux firewalls in vmware for
> customer environments. The customers may or may not have
> HIPAA/PCI/sOX/etc requirements. This is in the planning stages. Any
> of you have experience heading down this route? PCIDSS doesn't
> explicitly state problems with virtual firewalls, it seems to focus on
> the logic of the rules.
>
> Thanks!
>

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus