Book Image

VMware View Security Essentials

By : Daniel Langenhan
Book Image

VMware View Security Essentials

By: Daniel Langenhan

Overview of this book

Most people associate security with network security and focus on firewalls and network monitoring. However, there is more to security than that. Security starts with the establishment of a stable environment, protecting this environment not only from intrusion, but also from malicious intent. It is about tracking the issue and recovering from it. These elements of security are what this book aims to address. VMware View Security Essentials addresses the topic of security in the corporate environment in a new way. It starts with the underlying virtual infrastructure and then delves into securing your base, your connection, and your client. This is not only a “how-to” book, but is also a book that explains the background and the insights of View security for the experienced professional's desktop virtualization. This book takes you through the four major View security areas. Each area deals with all the aspects of security and explains the background as well as laying out simple-to-follow recipes to implement a higher security standard. We start at the Virtualization base and work our way through the various View server types. We will then dive into the problems and issues of securing a connection before we address the security of the desktop itself. We conclude with a look into the backing up of our View installation and preparing for disaster recovery.
Table of Contents (12 chapters)

Server connection


We now will look into how the various View servers need to be connecting with each other.

View uses Java Message System (JMS and JMSIR) and Apache JServ protocol version 1.3 (AJP13) to transport this information.

Usage

From

To

Protocol

Port

Client connectivity

Client

Security or Connection

TCP

80443

JMSIR

Security

Connection

TCP

4100

JMS

Security

Connection

TCP

4001

AJP13

Security

Connection

TCP

8009

JMSIR

Replica

Connection

TCP

4100

JMS

Replica

Connection

TCP

4001

vCenter connection

Connection

vCenter

TCP

80443

View composer connection

Connection

Composer

TCP

18443

Additional ports if there is a NAT or an IPSec firewall between the security and the connect server IPSec.

Usage

From

To

Protocol

Port

IPSec negotiation

Security

Connection

UDP

500

AJP13 forward

Security

Connection

UDP

4500

The following diagram shows the structure clearly:

View connect and security firewall rules

During the installation...