Vmware Vsan Security Zone Solution Overview
Vmware Vsan Security Zone Solution Overview
Vmware Vsan Security Zone Solution Overview
VMware vSAN
Security Zone Deployment
One of the most significant threats to security in any environment is misconfiguration. Complexity
increases the possibility of misconfiguration, which could lead to potential security incidents.
VMware vSphere® uses “bare-metal” virtualization, so the hypervisor interfaces directly with
server hardware without the need for a more complex, general operating system. This approach
reduces the attack surface and helps safeguard from OS-related vulnerabilities making it the most
robust and secure virtualization platform in the industry—an excellent platform for running
workloads in security zones.
Examples of workloads typically found in security zones include web servers, email gateways, and
proxy services. It is very common for these workloads to have high availability requirements.
Features such as vSphere High Availability, vSphere Fault Tolerance, and vSphere Distributed
Resource Scheduler™ help protect virtualized applications and services from downtime
associated with hardware failures and resource contention. These features require shared storage,
which means access to internally hosted storage networks (SAN and NAS) are commonly
extended to security zones. This potentially opens up additional options for hackers to gain
access to internal resources and leads to more complex firewall configurations. Another option is
a dedicated storage appliance contained within the security zone, but this solution can be
expensive and add management overhead.
Compute and storage resources for a security zone are ideally very secure, simple to implement,
cost-effective, and provide the performance and availability levels necessary to run and protect
critical, external-facing workloads. vSphere and VMware vSAN™ provide the hyper-converged
infrastructure (HCI) best suited to meet these requirements.
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by US and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
VMware vSAN
Security Zone Deployment
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by US and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
VMware vSAN
Security Zone Deployment
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by US and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
VMware vSAN
Security Zone Deployment
A variety of data protection solutions are available to back up and recover virtual machines and
applications in a vSAN cluster. Check with your data protection vendor to verify support and look
for the “VMware Ready for vSAN” logo. Virtual machine replication solutions such as Dell EMC
RecoverPoint® for Virtual Machines and VMware vSphere Replication™ works seamlessly with
vSAN to enable rapid, reliable per-virtual machine recovery.
vSAN Performance
vSAN is uniquely embedded in the vSphere hypervisor kernel and sits directly in the I/O data
path. It can deliver the highest levels of performance without taxing the CPU or consuming high
amounts of memory resources, as compared to other virtual storage appliances that run
separately on top of the hypervisor. All-flash vSAN configurations provide excellent performance
with predictable, low latencies. A combination of magnetic and solid state drives can be used to
enable flash-accelerated hybrid configurations.
Specific rules such as “Number of disk stripes per object” and “Flash read cache reservation (%)”
can be used to accelerate read-intensive workloads—especially in hybrid vSAN configurations.
With vSAN, it is possible to apply policies with precision. For example, database servers are
commonly deployed with the guest OS on one virtual disk and databases on other virtual disks. A
storage policy that reserves a higher percentage of flash read cache could be assigned
specifically to the virtual disks containing databases to help guarantee performance.
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by US and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
VMware vSAN
Security Zone Deployment
vRealize Operations features predictive analytics and smart alerts to help ensure optimum
performance and availability of applications and infrastructures. vRealize Operations Manager
enables administrators to monitor several factors such as read and write IOPS, throughput,
latency, cache hits, write buffer utilization, and capacity.
Capacity utilization and time remaining metrics are also included. vRealize Operations analyzes
consumption trends and provides estimates on the amount of time remaining before resources
are exhausted. This makes it easier for administrators to procure additional capacity in a timely
manner to avoid project delays and more serious issues such as application downtime due to lack
of free space.
Summary
vSAN and vSphere provide the best HCI platform for running virtual machine workloads requiring
predictable performance and availability in secure environments. vSphere has achieved multiple
security certifications and has a proven track record. vSphere and vSAN is the first and only HCI
solution that is part of a DISA STIG. The integration of vSAN with vSphere reduces risk through
policy-based management and role-based access control. Important services such as external-
facing web sites, email, and employee remote access can benefit from shared storage without the
cost and complexity of dedicated storage hardware. Virtual machine-centric storage policies are
created, assigned, and modified, as needs change in the environment. Maintenance windows are
easier to schedule and there are features such as vSphere HA and vSphere Replication to enable
rapid recovery from unplanned downtime. vSAN health monitoring is included and, optionally,
vRealize Operations Management Pack for Storage Devices provides multiple vSAN dashboards
for proactive alerting, heat maps, device and cluster insights, and streamlined issue resolution.
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2017 VMware, Inc. All rights reserved. This product is protected by US and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.