{"id":79,"date":"2011-05-25T10:10:23","date_gmt":"2011-05-25T08:10:23","guid":{"rendered":"http:\/\/www.virtualementvotre.ch\/blog\/?p=79"},"modified":"2014-07-13T16:00:15","modified_gmt":"2014-07-13T14:00:15","slug":"lanti-virus-dans-une-infrastructure-vmware","status":"publish","type":"post","link":"https:\/\/www.virtualementvotre.ch\/blog\/2011\/05\/25\/lanti-virus-dans-une-infrastructure-vmware\/","title":{"rendered":"L&#8217;anti-virus dans une infrastructure VMware"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><strong>vShield Endpoint<br \/>\n<\/strong><\/p>\n<p>La famille <strong>vShield<\/strong> (Plus r\u00e9cemment nomm\u00e9e <strong>VMware vCloud Networking and Security<\/strong>) s\u2019est passablement \u00e9toff\u00e9e avec la version vSphere 4.1.<\/p>\n<p>Premi\u00e8rement, le <strong>vShield Manager <\/strong>qui est l\u2019outil centralis\u00e9 permettant d\u2019activer et d\u2019installer les diff\u00e9rents \u00e9l\u00e9ments que compose la famille vShield.<\/p>\n<p>C\u2019est une simple VA Linux sous forme d\u2019ovf que l\u2019on download sur le site de VMware.<\/p>\n<p>Les \u00e9l\u00e9ments permettant de s\u00e9curiser votre infrastructure virtuelle sont :<\/p>\n<p><strong>vShield zone<\/strong>: premier <strong>vAPI<\/strong> de s\u00e9curisation, d\u00e9livr\u00e9 par VMware, permettant d\u2019int\u00e9grer un pare-feu directement dans l\u2019infrastructure VMware et de segmenter les r\u00e9seaux \u00e0 l\u2019int\u00e9rieur de l\u2019Hyperviseur.<\/p>\n<p><strong>vShield Edge<\/strong>: Permet la s\u00e9curisation p\u00e9rim\u00e9trique de l\u2019infrastructure virtuelle int\u00e9grant du VPN, du DHCP, du load balancing (seulement http pour l\u2019instant), de la journalisation et de l\u2019audit.<\/p>\n<p>Il est principalement utilis\u00e9 avec la solution <strong>vCloud Director<\/strong> et ses multi-locataires (Multi-Tenant).<\/p>\n<p><strong>vShield app<\/strong>: s\u00e9curisation au niveau des applications h\u00e9berg\u00e9 par vos VMs il fait du firewalling applicatif.<\/p>\n<p>Le dernier est celui qui nous int\u00e9resse.<\/p>\n<p><strong>vShield Endpoint<\/strong>:<\/p>\n<p>vShield Endpoint offre des fonctionnalit\u00e9s <strong>anti-malware, firewall et DPI (Deep Packet inspection)<\/strong> directement dans l\u2019infrastructure virtuelle, \u00e9vitant l\u2019ajout d\u2019agent \u00e0 l\u2019int\u00e9rieur des Virtual Machines.<\/p>\n<p>Afin d\u2019analyser les flux r\u00e9seau, CPU et m\u00e9moire, vShield Endpoint s&#8217;int\u00e8gre directement \u00e0 vSphere et se compose d&#8217;une machine virtuelle de s\u00e9curit\u00e9 (fournie par les partenaires de VMware) et d&#8217;un pilote permettant de d\u00e9lester les machines virtuelles des \u00e9v\u00e9nements de fichiers et du <strong>module de noyau chargeable (LKM)<\/strong> de <strong>VMware Endpoint Security (EPSEC)<\/strong>.<\/p>\n<p>Il existe deux composants principaux VMware VMsafe :<\/p>\n<p>VMsafe Memory &amp; CPU API <strong>(VMsafe-Mem\/CPU)<\/strong> utilis\u00e9 par le firewall et anti-malware<\/p>\n<p>VMsafe Network Packet Inspection API <strong>(VMsafe-Net)<\/strong> utilis\u00e9 par le DPI<\/p>\n<p>Tous ces composants renvois les flux directement \u00e0 la Virtual Appliance de s\u00e9curit\u00e9 qui a toutes les paternes.<\/p>\n<p>Le gros avantage est que l\u2019on ne conserve qu\u2019un seul paterne par serveur ESXi. Cela soulage le r\u00e9seau lors de mise \u00e0 jour des paternes.<\/p>\n<p><strong>VMsafe Virtual Disk Development Kit (VDDK)<\/strong>, troisi\u00e8me composant permettant le scan et nettoyage d\u2019un vmdk \u00e0 chaud et \u00e0 froid (VM arr\u00eat\u00e9e).<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/VMsafeNetwork.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-280\" src=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/VMsafeNetwork-300x211.png?resize=300%2C211\" alt=\"\" width=\"300\" height=\"211\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/VMsafeMemCPU.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-279\" src=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/VMsafeMemCPU-300x184.png?resize=300%2C184\" alt=\"\" width=\"300\" height=\"184\" \/><\/a><\/p>\n<p>Actuellement, <del>seul<\/del> <strong>TrendMicro Deep security, <\/strong>technologie issue du rachat de <strong>Third Brigade<\/strong>, fonctionne avec vShield Endpoint.<\/p>\n<p><strong>Mise \u00e0 jour 10.01.2013<\/strong>: <strong><a href=\"http:\/\/support.kaspersky.com\/8288\">Kaspersky<\/a>, <a href=\"http:\/\/www.bitdefender.com\/sve\">McAfee<\/a>, <a href=\"http:\/\/www.symantec.com\/endpoint-protection\">Symantec <\/a>et <a href=\"http:\/\/www.bitdefender.com\/news\/bitdefender-integrates-with-vmware-vshield-5-endpoint-2379.html\">Bitdefender<\/a><\/strong> ont \u00e9galement sorti leurs moutures, mais qui font g\u00e9n\u00e9ralement uniquement de anti-malware<\/p>\n<p>Afin de pouvoir l\u2019utiliser, il faut :<\/p>\n<p>1) Installer\/Upgrader vers <strong>vCenter<\/strong> 4.1u1 et plus, <strong>ESXi<\/strong> 4.1u1 et plus et d\u00e9ployer <strong>vShield Manager<\/strong><\/p>\n<p>2) D\u00e9ployer le driver<strong> LKM (Loadable Kernel Module)<\/strong> Espec via le vShield Manager sur les ESXi<\/p>\n<p>3) Installer <strong>Deep Security Manager<\/strong> et d\u00e9ployer la<strong> Virtual Appliance de securit\u00e9<\/strong> (DSVA)<\/p>\n<p>4) Pr\u00e9parer les ESXi via Deep Security Manager (<strong>FilterDriver<\/strong>) =&gt; seulement pour Trend Micro<\/p>\n<p>5) D\u00e9ployer le <strong>vShield Thin Agent<\/strong> (<del>prochainement int\u00e9gr\u00e9 dans les VMware tools<\/del>) dans les templates et VMs de l\u2019infrastructure. (Depuis la version <strong>vSphere 5.0<\/strong>, il faut faire une full installation des VMware Tools)<\/p>\n<p>Voici l&#8217;architecture finale, de notre solution anti-virus, int\u00e9gr\u00e9e \u00e0 nos serveurs ESXi<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/vShieldEnpoint.png\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-278\" src=\"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/05\/vShieldEnpoint-300x126.png?resize=300%2C126\" alt=\"\" width=\"300\" height=\"126\" \/><\/a><\/p>\n<p>La bonne nouvelle est que les<strong> licences vShield EndPoint<\/strong> sont int\u00e9gr\u00e9es, avec un support actif, d\u00e8s la licences <strong>VMware vSphere 5.1 Essentials Plus et vCloud Networking and Security 5.1<\/strong> sans co\u00fbts suppl\u00e9mentaires.<\/p>\n<p>Vous trouverez plus d&#8217;infos sur les compatibilit\u00e9s et supports des upgrades dans la KB qui suit:<\/p>\n<p>&nbsp;<\/p>\n<p>http:\/\/kb.vmware.com\/selfservice\/microsites\/search.do?language=en_US&#038;cmd=displayKC&#038;externalId=2036875<\/p>\n<p>&nbsp;<\/p>\n<p>Egalement voici un document regroupant tous les partenaires utilisant cette technologie:<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/www.vmware.com\/files\/pdf\/products\/vcns\/VMware-Integrated-Partner-Solutions-Networking-Security.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Click to access VMware-Integrated-Partner-Solutions-Networking-Security.pdf<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; vShield Endpoint La famille vShield (Plus r\u00e9cemment nomm\u00e9e VMware vCloud Networking and Security) s\u2019est passablement \u00e9toff\u00e9e avec la version vSphere 4.1. Premi\u00e8rement, le vShield Manager qui est l\u2019outil centralis\u00e9 permettant d\u2019activer et d\u2019installer les diff\u00e9rents \u00e9l\u00e9ments que compose la famille vShield. C\u2019est une simple VA Linux sous forme d\u2019ovf que l\u2019on download sur le site de VMware. Les \u00e9l\u00e9ments <a class=\"more-link\" href=\"https:\/\/www.virtualementvotre.ch\/blog\/2011\/05\/25\/lanti-virus-dans-une-infrastructure-vmware\/\">Continue reading <span class=\"screen-reader-text\">  L&#8217;anti-virus dans une infrastructure VMware<\/span><span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[6,9,3],"tags":[28,38,31,34,33,35,36,37,32,604,27,30,29],"class_list":["post-79","post","type-post","status-publish","format-standard","hentry","category-securite","category-virtualisation","category-vmware","tag-anti-virus","tag-bitdefender","tag-deep-security","tag-deep-security-8","tag-epsec","tag-kaspersky","tag-mcafee","tag-symantec","tag-trendmicro","tag-vmware","tag-vshield","tag-vshield-endpoint","tag-vshield-manager"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p4KzU1-1h","jetpack-related-posts":[{"id":101,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2011\/10\/06\/la-beta-de-trend-micro-deep-security-8-est-disponible\/","url_meta":{"origin":79,"position":0},"title":"La beta de Trend Micro Deep Security 8 est disponible","author":"Cedric Megroz","date":"06\/10\/2011","format":false,"excerpt":"Bonjour, \u00a0 Trend Micro vient de sortir la Beta de leur produit VMSafe, Deep Security 8. \u00a0 Elle est compos\u00e9e de : Deep Security Manager\u2122, outil de configuration et management centralis\u00e9, pour toute votre infrastructure virtuelle et physique. Elle permet de d\u00e9ployer les Deep Security Virtual Appliance et Deep Security\u2026","rel":"","context":"In &quot;SECURITE&quot;","block_context":{"text":"SECURITE","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/securite\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/10\/schemaDSEC.jpg?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/10\/schemaDSEC.jpg?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/10\/schemaDSEC.jpg?resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/10\/schemaDSEC.jpg?resize=700%2C400 2x, https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/10\/schemaDSEC.jpg?resize=1050%2C600 3x"},"classes":[]},{"id":81,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2011\/07\/13\/vsphere-5-whats-new\/","url_meta":{"origin":79,"position":1},"title":"vSphere 5 What&#8217;s new","author":"Cedric Megroz","date":"13\/07\/2011","format":false,"excerpt":"Bonjour, VMware a annonc\u00e9 les premi\u00e8res updates de logiciels li\u00e9s \u00e0 l\u2019arriv\u00e9e de vSphere 5. Premiers produits annonc\u00e9s : VMware Site Recovery Manager 5 Outil de DRP, pour une reprise rapide de votre production virtualis\u00e9e, il propose comme nouvelles fonctionnalit\u00e9s : VMware vSphere Replication qui supprime l\u2019utilisation de la r\u00e9plication\u2026","rel":"","context":"In &quot;VIRTUALISATION&quot;","block_context":{"text":"VIRTUALISATION","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/virtualisation\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/07\/44-1024x569.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/07\/44-1024x569.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/07\/44-1024x569.png?resize=525%2C300 1.5x"},"classes":[]},{"id":176,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2013\/10\/28\/vsphere-5-5-go-no-go\/","url_meta":{"origin":79,"position":2},"title":"vSphere 5.5 Go \/ No Go ?","author":"Cedric Megroz","date":"28\/10\/2013","format":false,"excerpt":"Bonjour, \u00a0 Cela fait quelques semaines que la version vSphere 5.5 est sortie et il est temps de faire le point sur les compatibilit\u00e9s, afin de valider un GO \/ NO GO, pour la migration ou l\u2019installation d\u2019une nouvelle infrastructure, avec la nouvelle mouture. \u00a0 Premi\u00e8rement bien valider la compatibilit\u00e9\u2026","rel":"","context":"In &quot;VIRTUALISATION&quot;","block_context":{"text":"VIRTUALISATION","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/virtualisation\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.virtualementvotre.ch\/blog\/wp-content\/uploads\/2013\/10\/vsphereMatrix.png?fit=766%2C624&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.virtualementvotre.ch\/blog\/wp-content\/uploads\/2013\/10\/vsphereMatrix.png?fit=766%2C624&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.virtualementvotre.ch\/blog\/wp-content\/uploads\/2013\/10\/vsphereMatrix.png?fit=766%2C624&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.virtualementvotre.ch\/blog\/wp-content\/uploads\/2013\/10\/vsphereMatrix.png?fit=766%2C624&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":950,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2015\/04\/13\/vsphere-6-go-no-go\/","url_meta":{"origin":79,"position":3},"title":"vSphere 6 Go \/ No Go","author":"Cedric Megroz","date":"13\/04\/2015","format":false,"excerpt":"Bonjour, Cela fait quelques semaines que la version vSphere 6 est sortie et il est temps de faire le point sur les compatibilit\u00e9s, afin de valider un GO \/ NO GO, pour la migration ou l\u2019installation d\u2019une nouvelle infrastructure. Premi\u00e8rement, bien valider la compatibilit\u00e9 entre les produits VMware, mais aussi\u2026","rel":"","context":"In &quot;SECURITE&quot;","block_context":{"text":"SECURITE","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/securite\/"},"img":{"alt_text":"vSphere6-209x300","src":"https:\/\/i0.wp.com\/www.virtualementvotre.ch\/blog\/wp-content\/uploads\/2015\/04\/vSphere6-209x300-209x300.jpg?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":93,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2011\/09\/18\/la-securite-dans-une-infrastructure-vsphere\/","url_meta":{"origin":79,"position":4},"title":"La s\u00e9curit\u00e9 dans une infrastructure vSphere","author":"Cedric Megroz","date":"18\/09\/2011","format":false,"excerpt":"Bonjour, La s\u00e9curit\u00e9 de votre infrastructure virtuelle est tr\u00e8s importante, selon le degr\u00e9 d\u2019exposition auquel vous la soumettez. Avec l\u2019arriv\u00e9e des cartes 10GB, on est souvent oblig\u00e9 de faire passer, sur les m\u00eames cartes r\u00e9seau, autant les r\u00e9seaux priv\u00e9s, les DMZ, que Internet. Cela exige un niveau d\u2019expertise et d\u2019audit\u2026","rel":"","context":"In &quot;SECURITE&quot;","block_context":{"text":"SECURITE","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/securite\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/09\/SecuCompCheck-1024x593.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/09\/SecuCompCheck-1024x593.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/www.virtualgeek.ch\/blog\/wp-content\/uploads\/2011\/09\/SecuCompCheck-1024x593.png?resize=525%2C300 1.5x"},"classes":[]},{"id":107,"url":"https:\/\/www.virtualementvotre.ch\/blog\/2011\/10\/19\/nouveaux-produits-vmware-au-vmworld\/","url_meta":{"origin":79,"position":5},"title":"Nouveaux produits VMware au VMworld","author":"Cedric Megroz","date":"19\/10\/2011","format":false,"excerpt":"Bonjour, VMware a annonce trois nouveaux produits lors de la general session de vmworld europe 2011. Premier produit, VCenter operation manager suite 5.0 Outil permettant d analyser les performances, la capacit\u00e9 et la configuration de votre infrastructure vSphere vFabric application manager suite 5.0 Outil de provisioning, d\u00e9ploiement et monitoring d'infrastructure.\u2026","rel":"","context":"In &quot;VIRTUALISATION&quot;","block_context":{"text":"VIRTUALISATION","link":"https:\/\/www.virtualementvotre.ch\/blog\/category\/virtualisation\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/posts\/79","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/comments?post=79"}],"version-history":[{"count":2,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/posts\/79\/revisions"}],"predecessor-version":[{"id":698,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/posts\/79\/revisions\/698"}],"wp:attachment":[{"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/media?parent=79"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/categories?post=79"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.virtualementvotre.ch\/blog\/wp-json\/wp\/v2\/tags?post=79"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}