Book Image

VMware vCloud Security

Book Image

VMware vCloud Security

Overview of this book

Security is a major concern, in particular now that everything is moving to the cloud. A private cloud is a cloud computing platform built on your own hardware and software. The alternative is to deploy the services you need on a public cloud infrastructure provided by an external supplier such as Amazon Web Services, Rackspace Cloud, or HP Public Cloud. While a public cloud can afford greater flexibility, a private cloud gives you the advantage of greater control over the entire stack. "VMware vCloud Security" focuses on some critical security risks, such as the application level firewall and firewall zone, virus and malware attacks on cloud virtual machines, and data security compliance on any VMware vCloud-based private cloud. Security administrators sometimes deploy its components incorrectly, or sometimes cannot see the broader picture and where the vCloud security products fit in. This book is focused on solving those problems using VMware vCloud and the vCloud Networking and Security product suite, which includes vCloud Networking and Security App, vShield Endpoint, and vCloud Networking and Security Data Security. Ensuring the security and compliance of any applications, especially those that are business critical, is a crucial step in your journey to the cloud. You will be introduced to security roles in VMware vCloud Director, integration of LDAP Servers with vCloud, and security hardening of vCloud Director. We'll then walk through a hypervisor-based firewall that protects applications in the virtual datacenter from network-based attacks. We'll create access control policies based on logical constructs such as VMware vCenter Server containers and VMware vCloud Networking and Security security groups but not just physical constructs, such as IP addresses. You'll learn about the architecture of EPSEC and how to implement it. Finally, we will understand how to define data security policies, run scans, and analyze results.
Table of Contents (13 chapters)
VMware vCloud Security
Credits
Foreword
About the Author
Acknowledgement
About the Reviewers
www.PacktPub.com
Preface
Index

Foreword

Security is the biggest concern in cloud environments for end users as well as cloud administrators. VMware has security solutions that try to solve all the security concerns.

Prasenjit is a technical evangelist who has authored some books that help readers to understand the key concepts and design considerations. Prasenjit provides the technical guidance in implementing VMware's cloud datacenters.

This book gives readers a step-by-step guide to install, configure, and understand the security in vCloud datacenters. The book starts with the basic architecture of vCloud Director and key concepts associated with it, and goes on to explain the setup and configuration of the vCloud Director. After installing vCloud Director, the book talks about how to secure the interior of your virtual datacenter using vCloud Networking and Security App. There are good details on how to manage the vCloud Networking and Security App firewall. The book then talks about how vShield Endpoint strengthens security for virtual machines by offloading antivirus and anti-malware agent processing to a dedicated Security Virtual Appliance. The book also has details about how to protect the sensitive data using VMware vCloud Networking and Security Data Security.

I believe this book would be very useful for the novice as well as the experienced reader. This is not yet another how-to book. The author has written the book based on his experience when implementing VMware's cloud datacenter, so he is aware of the challenges and issues faced when designing cloud datacenters. I hope that readers will get a thorough understanding of the cloud security configuration and that would eventually make cloud computing more secure.

Harish Chilkoti