RE: ESX Vmware Physically connected to different segments

From: Derek Chamorro (derek.chamorro@gmail.com)
Date: Fri Jan 25 2008 - 15:09:43 EST


Search for the case study regarding NASA's VMWare design for their DMZ virtualization project.

-----Original Message-----
From: "Albert R. Campa" <abcampa@gmail.com>
To: pen-test@securityfocus.com
Sent: 1/24/2008 4:41 PM
Subject: ESX Vmware Physically connected to different segments

We have some admins setting up some VMs on an ESX server and they have
the idea of setting up 1host server with multiple VMs and on some of
these VMs they want physical NICs connected to our main LAN and other
VMs they want physical wires connected to a DMZ lan.

Normally this would be almost bridging the two networks and bad
practice overall. An explanation from an SA is that virtual switches
are used on the ESX host and this seperates the physical connection to
our main LAN and this DMZ lan.

This does not sound like good practice but is there documentation to
back that up or in your experience have you been able to exploit this
type of configuration?

Saludos

Albert

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:22 EDT