ESXi Hyper-V seguro e inseguro!

Olá Senhores,

Only recently teve um evento s por uma Segurança em Recife, wave back palestrantes falou um empresa sober Segurança hypervisors back, na Apresentação ele mostra o quanto o Hyper-V e e seguro o quanto o ESCi e inseguro, disse o ESXi tem so many falhas Segurança e o deixou disappointed as nao e legal dpender tanto Soluções of others.

Não sei exato conteudo do da palestra, had nao fled para o evento mas estavamos talking sober isso no em um Facebook don't post sober vender vender of Hyper-V or Vmware, but or menos isso. ELE go publicar o matter brief em em forma webcast.

MAS ai pergunto: docks series os problemas o Segurança e tem ESXi as tools of others protected-lo para offshore? EU honestly nem m'imagino, sendo ele tao inseguro, por Québec as empresas mundo e but several segmentos adotam Soluções Vmware back offer? Principalmente os major banks e sao many, seria a team of TI e Segurança a lot empresas tao amadores para conhecer estas falhas nao? UO e who ajustam melhorando a Segurança using other solutions?

O Serviço members do hypervisor e sua rede price e da rede das VMS, then quando o host esta com problemas Comunicação of rede, isso nao afeta like VMS, e tem um firewall embutido ESXi o that works muito bem, finally, quero Saber wave o ESXi tanto peca a Segurança, alguem aqui sabe algo?

SDS a todos!

Ivanildo,

Pelo Li na pirates Facebook, um back pontos Aduaneiras a Segurança era o suporte a criptografia discos, wave awesoe than no Alberto Oliveira estava nativo is referindo ao e as BitLocker without Hyper-V e a não suporte nativo para isso we have some Soluções very excellence VMware:

1. enable o BitLocker has nivel comments;

enable as a criptografia a storage level, por exemplo o storage IBM DS8870 excellence nativo suporte a criptografia por padrão em todos os discos, e cabe ao administrator enable or e nao, as transparent e para os servidores e com certeza but performatico o BitLocker.

Outra pirates antiga e a core question: monolithic (ESXi) X microkernel (Hyper-V, Xen)

Resumidamente sober essa guerra, segue some vantagens e of cada modelo:

Monolithic: possui a não dpender uma 'parent partition' hidtorico e por isso, access tem direto ao MATERIAL, very como para cada manufacturer of hardware development ter um pilot device without hypervisor, e como o control da VMware para quem pode joints os device driver e bastante strict (another hidtorico), a list material compativel com o VMware ESXi e bem menor as a Hyper-V for example , mas nem vejo isso como disadvantage, ja than todos os major manufacturers are na lista :-)


Microkernel: os device drivers São instalados na parent partintion e quando os comments access ao precisam material silt acessam through of da parent, e partition como voce ja deve ter percebido, any problema na parent partition pode indisponibilizar todos os invited, e consequentemente is um partition parent of overhead but para o access material through of da. UMA hidtorico e e but easy find manufacturing compativeis com o Hyper-V, POI seja compativel com o sistema operational since da parent partition (No caso Windows Server 2008 or higher) will be compativel com o Hyper-V.

Por fim, tudo tem justificativa para, e as vezes some funcionalidades sao sacrificadas para possibilitar other than offer but benefits that one faith sacrificada, e tenho certeza what ele above esses pontos a VMware, an answering machine to go mesma a todas elas.

Tags: VMware

Similar Questions

  • Virtual ambiente vphere 4.1 and 4.6 to vphere5.1 and discover 5.1 update

    Hola todos hope esten very well,

    Estoy por fornuis mi ambiente virtual vphere 4.1 4.6 discovers a 5.1, pero in the pagina VMware encuentro several versiones

    for example para mi tengo q esta esxi no estoy seguro TR are mas actualizada o the correcta

    ESXi 5.1 = VMware-VIMSetup-all - 5.1.0 - 947939.iso

    para el Virtual center tengo esta

    Vphere 5.1 = VMware-VMvisor-Installer - 5.1.0 - 799733.x86_64.iso

    y ahora part donde mas tengo dudas're para change view del q me he con sown several versiones tengo esta

    View = VMware-viewconnectionserver-x86_64 - 5.2.0 - 987719.exe this version

    y composer 3.0

    Pero don't be TR estas versiones son las mejores mas para usar

    MI empresa tienen a contrato Enterprise liked don't con vmware por lo no hay problemas of licenses por eso quiero instalar mas o mejor para mi actulizacion nueva version

    Saludos is muchas gracias

    Hola

    Esta claro as puedes fornuis esxi y vcenter an esas versiones (actualiza primero y luego cambia version of her license)

    Lo have mirar're para cunatos horizon users discovered tienes license (5.2 of the real are the version) y despues ir doing las plots (primero los connector broker, luego el composer)

    Saludos

  • Materials for workstation boards

    Hello

    I am new to the community and have already searched for this but haven't found the info I need, so apologies if this is a common question.

    I'm about to build a new PC to run Workstation on. I will use it to execute nested ESXi/Hyper-V hosts and a lot of lab for VMware View etc laboratories.

    Currently, I have several old PCs/servers, but would only turn on a PC for my Labs, as my little Home Office becomes so hot.

    Is it worth the wait for the new Ivy Bridge coming processors - any day now - or a current i7 will be fine, if so, what is the best i7 and chipset to use?

    I've read great post of Sammy (http://boerlowie.wordpress.com/2011/12/01/building-the-ultimate-vsphere-lab-part-2-the-hardware/) but I want 32 GB of minimum RAM really because I will be hammering with lots of virtual machines at one time or another.

    Already, I have some SSD and SATA drives more ready, but I was wondering if there is a HCL or similar to nested hosts ESXi/Hpyer-V?

    Does anyone have any other recommendations?

    So, I can't really go wrong when choosing material then?

    Nothing I could think. If the material is supported by the operating system, VMware Workstation should work fine.

    What is the i7 - 2600K or i7 - 2600S?

    It's an i7-2600 3.40 GHz CPU (without "S" or "K"). I currently have a domain controller Windows 2008R2 and vCenter Server (including iSCSI target) and ESXi two hosts 5.0U1 lit in VMware Workstation and the processor is almost empty. (No VM nested under tension).

    Virtualization technology for Directed i/o (VT-d) Intel is important?

    No, what is important is that 'VT - x' and 'Execute Disable Bit' are both enabled in the BIOS and that the processor supports EFA.

    André

  • Convert VMFS partitions/data?

    Hi again!

    IV been playing with Esxi, Hyper-V and Xenserver for some time now. Finally, I decided to go with esxi for my virtualization project but there are 2 questions, I need to get an answer first.

    1. None of my raid cards that I have at the moment are detected by esxi. I read that theres a lack in the nucleus of esxi so that you can't do software raid; is that correct?

    2. I 3xTB drivers where partitions are encrypted with truecrypt, what is the easiest way to convert these VMFS partitions so I can use them in esxi?

    Thanks for your help!

    Hello

    As far as I know, you have two main options:

    (1) create a virtual machine with a normal vdisk (hard) to place the data of truecrypt. Then make a transfer to network on the virtual machine to a system that has access to the unencrypted data. Finally the date of stay to the virtual machine without encryption vdisk

    (2) create a virtual machine and install the truecrypt sotfware. After that add truecrypt disks (perhaps is better to merge all data from a larger drive?) to the esxi machine. The esxi should see the disk (s) connected (s) as LUN SCSI/SATA. Then, create the physical (s) or the discs as raw device mapping (RDM). In my humble VIEW in your scenario is preferable to create RDM in physical mode. Finally using the truecrypt software you should be able to access the encrypted data.

    Here, you can check a few RDM tutorials:

    http://www.avatir.com/HOWTO-RDM-on-local-SATA-disks-in-ESXi/

    http://VM-help.com/esx40i/SATA_RDMs.php

    http://ServerFault.com/questions/105652/assign-and-remove-multiple-LUNs-from-VMs-on-ESXi-4

    It may be useful

    A saludo/best regards,.

    Pablo

    Please consider providing any useful answer. Thank you!! - Por favor considered premiar las useful responses. MUCHAS gracias!

  • SMB need some SAN

    I'd be veru greatfull if someone could suggest the fairly reliable SAN solution for SMEs. We want to use it for ESXi, Hyper-V and test VI3 with 2

    Server boxes. It can be said is that an acceptable transfer rate? IWe have iSCSI Buffalo TeraStation Pro, but I can only copy files to

    it about 18 MB/s on RAID5 using Windows and apparently the device

    only supports Windows only.

    Thanks to advise!

    If you have limited budget and will not buy a special material then you can try Starwind 5.0 HA. It lets you turn any server x 86/_64 classic in SAN with great performance.

    The top of this product version offers 2 active node that is not provided by the products in the same price category. The price of this version is about 6,000 USD.

  • Inc. Dell PowerEdge T310

    Can I install Virtual Machine in T310? Hardware is supported with it?

    Thank you

    Ashu.Prajapati86,

    The T310 supports virtualization, you can install ESXi, Hyper-V or Xenserver according to your preferences.

    Let me know if that answers your question.

  • Network on the VMS problem guests on nested Hyper-V on ESXi 5.5

    Nesting of virtualization is already complicated, now, I hope that my subject of this discussion is not too complicated.

    Server: Dell PowerEdge R730 double E2640

    • External hypervisor: ESXi 5.5.0u2 (Dell custom image, installed on the server), 4 (NIC0, NIC1 in use) network interface cards
      • Management IP address 10.200.200.9/ subnet mask: 255.255.255.0 / Gateway: 10.200.200.1

    • Inner hypervisor: Windows Server 2012 R2 Datacenter, using 2 network cards virtual x E1000E
      • IP 10.200.200.10 (for BONES)
      • IP 10.200.200.11 (for guest virtual machines)


    Basically, I followed the instructions to create a new virtual machine with Virtual hardware version 10, edit the vmx file, allocate and reserve the 64 GB of RAM with 8 vCPU for Windows Server,

    VHV. Enable = "TRUE".

    Hypervisor.CPUID.v0 = "FALSE".

    MCE. Enable = "TRUE".

    At this point, everything works fine- I am able to install the Windows server 2012 R2 with Hyper-V feature. I also installed VMware Tools on this 2012 Windows Hyper-V, datacenter arrived at the field, ran iSCSI to connect to our NAS and restarted the hyper-V without problem on ESXi.



    But when I try to install a new guest VM in Hyper-V, the network does not work properly.

    I install a Windows Standard 2012 on Hyper-V (the inner hypervisor) without problem and the guest that OS Gets a 10.200.200.86 IP address (assigned by DHCP on the same subnet)

    This guest operating system, I am able to ping it's computer Hyper-V host 1st layer (10.200.200.10 and 10.200.200.11) and 2nd ESXi host (10.200.200.9), but the impossibility of joining as a result of gateway (10.200.200.1).

    And of course, I received an exclamation sign on the network icon in the taskbar of the 2012 Windows standard saying 'no internet connection '.

    * I was always able to join this Windows 2012 Std comments to the domain.

    No existingon the same subnet is an another Hyper-V on server physical hosting multiple virtual machines of comments including the controller of field and the DHCP servers, etc.


    I tried using PCIe with the Dell Server NIC3 pass through, but it crashed the ESXi and gave me an IERR (CPU 1 error) error message on my screen front of server Dell

    I ended up not using pass-through PCIe (although I really want to use if this solves my problem), because I learned that it can cause problems with other discussion threads Intel processors.

    Also, does anyone have similar problems? What did you do to fix this? I have been stuck for days not being is not able to connect guest VM in internet...

    My goals for this configuration are

    (1) simplify my strategy of VM backup (backup only the Hyper-V 2012 to capture all the parameters of the virtual machine)

    (2) maintain the real guest VMs on the NAS.

    (3) use this new Hyper-V with another Hyper-V (on another old physical server, are not nested) to provide high availability

    Andrew

    You have activated the Promiscuous Mode on your ESXi host vSphere vSwitch? Have a look here: http://vblog.is/?p=94

  • Hyper-v 2008 R2 for Vmware ESXI 5.5 problem

    Hello world

    We are migrating to Vmware ESXI with HP 3PAR storage we have some important servers as vms on Microsoft Hyperv 2008 R2, I downloaded and installed the VMware vCenter Converter Standalone Client on the host Microsoft hyper-v connected to the localmachine as administrator and also to define the credentials of esxi distance everything works fine until it blocks 33% retried the process several times but without success , I collected the log, if I understand correctly this is something related to timeout or something maybe someone clears me on the issue, thanks a lot

    also a question should I try to install the stand-alone converter on each virtual machine, hyper v or should I install on the computer host and make the conversion?

    is it possible to make the conversion without turning off the virtual machines?

    Thanks in advance

    You do not need to install the converter on each machine, only the converter agent, which is installed automatically when it is not found on the destination computer.

    HTH

  • When the suspension/resumption blue screens Windows Hyper-V VM in ESXi 5.5

    ESX to virtualize ESXi and Windows Hyper-V machines for training scenarios. We have dozens (or even hundreds) of these virtual machines in use in a large farm of ESX host at any given time. Students are able to suspend their virtual machines at any time and come back later. It worked flawlessly on ESXi 5.1. Our troubles started when we went to ESXi 5.5. After the upgrade, Windows Hyper-V guests began to break up with a blue screen during the process of suspension/resumption. We have restored 5.1 on two of our boxes and the problem stopped. We may be forced to return all the servers to 5.1, but are really hoping to find a fix or a workaround. We are opening a case with VMware, but thought we ask here as well.


    Comments

    • We have the latest version of ESXi 5.5, build 1892794.
    • BSOD comments were held on all ESX hosts, we have. We have two server hardware configurations that are very similar (details below) and the BSOD occur with equal frequency on both.
    • BSOD happens in 2012 Windows R2 and Windows 2008 R2 VMs.
    • EDIT: BSOD occur if the two "hypervisor.cpuid.v0 = FALSE" is configured and the Hyper-V role is installed. No BSOD that Hyper-V is deleted or if happen "hypervisor.cpuid.v0 = FALSE" is deleted.
    • The "hypervisor.cpuid.v0 = FALSE" parameter is used to make Hyper-V think it runs on native hardware. Without it, Windows knows it is running in a virtual machine and the BSOD go. But Hyper-V won't start nested VMs. I wish we didn't need the arrangement, but, alas, we do.
    • We have never seen a BSOD that was triggered by a suspension/recovery.
    • Not every interruption/resumption will cause a BSOD. During testing, we see a BSOD about 20% of the time that a suspension/resumption is carried out.
    • This happens on ESXi hosts whether they are occupied or not. We took a server out of rotation of isolated tests and saw the exact same behavior.
    • There are various BSOD messages. The most common is 'IRQL_GT_ZERO_AT_SYSTEM_SERVICE' with a stop of 0x0000004A code. But there are several others.
    • We thought it might have something to do with the bug of processor Intel E5 (http://kb.vmware.com/selfservice/microsites/search.do?language=en_US & cmd = displayKC & externalId = 2073791). However, we use E5 V1 processors, not V2. We have updated to the latest Dell BIOS (2.2.3) just in case. It made no difference.
    • We tried to turn off all the power settings in the BIOS of the server, as well as within ESX. This includes any definition performance max and disabling C States. No difference.
    • We have disabled all of the features available in the BIOS of the virtual machines, including all the caching options. No difference.
    • We use the following parameters to enable nested Virtualization:
      • CPU/MMU hardware
      • VHV. Enable = TRUE
      • Hypervisor.CPUID.v0 = FALSE
    • We tried to use "windowsHyperVGuest" as the identifier for OS invited instead of the above parameters. Nested virtualization has worked well, but the BSOD is still produced at the same rate.
    • EDIT: we tried the upgrade virtual machines since version 9 to version 10 of hardware equipment. This did not help.
    • EDIT: we tried the VMware Tools upgrade from version 9.0.0.782409 to 9.4.6.1770165. This did not help.
    • We tried allowing the CPU performance counter virtualization in virtual machines. No help.
    • We came home two of our servers to 5.1 and the BSOD disappeared completely. No other changes been made to the servers and virtual machines. Just go back to 5.1 fixes the problem.
    • We have noticed a dramatic amount of time difference to both versions of ESXi to suspend these VMs. ESXi 5.1 suspends these VMs within 2-3 seconds, while ESXi 5.5 takes 30 seconds to a minute. Certainly, something very different happens during the process of suspension. Suspend time 5.5 are longer or not a BSOD occurs.

    Our material

    • Dell PowerEdge R720xd OR Dell PowerEdge r.620
    • BIOS version: 2.2.3
    • Processors: 2 - Intel Xeon E5-2670 0 @ 2.60 GHz
    • RAM: 384GB (16 GB (buffered) synchronous DDR3 DIMMS matched Dell 24)
    • Controller: PERC H710P Mini 1 GB memory NVRAM
    • OS disc: 2-240GB S3500 SSD drives in a RAID 1 (Slot 00-01) mirror
    • VM storage drive: 7-480GB S3700 SSD in a RAID5 with a HS spare dedicated (Slot 02-09)
    • 1 - Intel 2 p X 540/2 p I350 rNDC
    • 1 - Intel Gigabit 4 p I350-t adapter

    The obvious solution is to roll back to 5.1. However, we completely independent questions with 5.1 (one topic for another post) that we don't have with 5.5 and prefer to stay with 5.5. But these BSOD is a deal breaker. Help or direction to solve the BSOD will be greatly appreciated!

    In some cases, a single byte stored in the checkpoint file is outdated.  This only affects nested customers.  During the recovery of a Hyper-V OS management from a corrupt checkpoint, a variety of BSOD can result.

    You must file a request for assistance for an express patch with a fix for the PR 1289485.

  • Attempt to start an ESXi host nested of Windows Hyper-V on Windows 8.1

    Hi guys,.

    I would like to start nested 5.5 ESXi hosts in my 5.5 vCenter environment.  I did successfully using 10 Workstation, but I'm having problems trying to do using Windows Hyper-V running on Windows 8.1.  I created a few test servers and tried to start, receive all of them successfully the IP addresses and downloading the image, but they cling to the «travel modules and updated the kernel...» »

    Untitled.jpg

    If somebody has got away?  Any suggestions?

    dbutch1976 wrote:

    As described earlier in this thread, the host crashes to "move the modules and from the kernel.

    I don't think that the host crashes in fact at this point.  Since the FADT ACPI under Hyper-V has revealed that the VGA is not available, the output is redirected to the serial port.  If you can complete the "blind" installation, you should be able to get on the rest of the installation while providing the necessary responses.

    The question is why the FADT ACPI under Hyper-V claims that VGA is not available, when it is clearly.

  • config of memory in esxi with a hyper-v virtual machine on.

    First of all, Thanks for the help.

    I set up a Home Lab with ESXi 5.1.
    J’ai several Linux machines. J’ai a virtual machine Windows Server 2012 Hyper -v.
    I would like to know what the optimal parameters in order to maximize the 32 GB of RAM to the virtual machine Windows. ()when I use this machine do not use any other ESXi virtual machine)
    J’ai not clear that if administered dynamically memory for this VM in ESXi when you manage Hyper v, dynamic Management of memory will be use all the RAM.

    Thank you for everything, I hope that I have explained.

    How much memory is your ESXi has? If you have not set up a special configuration for the virtual Windows machine, the ESXi Server uses the common techniques of overcommitment with the virtual machine. If you have more than 32 GB of RAM on your box of ESXi, you'll never overcommited (assuming that your other virtual machines are turned off). So the ESXi will give access to the physical to your Windows virtual machine memory as long as she asks for.

    You can also ensure the physical to the virtual machine by using reservations memory, if you want to.

  • no uninstall option to integration services Hyper-V before converting to ESXi

    Hello

    before the conversion to virtual machines in Hyper-v in ESXi, I wanted to uninstall Integration services but is surprised because there is not GOING to do it in the traditional way.

    Services int are not not in the programs (control Panell).

    There is no such thing as a command line switch on some blogs on the net. It must be the installer / uninstaller. But the installer has only 2 switches: calm and restart.

    Any suggestion?

    Don't want to mess with the services of another platform after conversion.

    I reinstall the servers own as much as possible. But some of them have fairly complex config.

    Thank you.

    I noticed the same thing - but then, I also found that there is no need to uninstall anything

  • VMware ESXi 5.1 can run Microsoft Hyper-V Server 2012 SMV also, nice!

    I created a detailed instructions (with screenshots and video) using GA-level code here:

    http://tinkertry.com/ESXi-5-1-running-hyper-v-Server-2012

    using the "basic" version of the new Hyper-V, with tips and ideas from these forums and other sites on the previous beta tests.

    Here's the gist:

    • Create a "Microsoft Windows Server 2012 (64-bit)" VM, using the default Configuration
    • Right click on the new virtual machine and material virtual upgrade to Version 9
    • twist the VMX, adding these 4 lines:

    MCE. Enable = TRUE

    Hypervisor.CPUID.v0 = FALSE
    featMask.vm.hv.capable = Min:1″ «»
    VHV.enable = TRUE

    • Remember, it is assigned to a network where the vSwitch is Promiscuous Mode to Accept
    • Turn on the new machine virtual of Hyper-V
    • perform the default installation and configure Hyper-v, hard IP-code if you wish, create an Admin user and password name that matches a customer's system
    • create a Windows 8 'customer' VM, as the Hyper-V Manager takes just a few seconds to add
    • Difficulty of COM security on the client system
    • use Hyper - V Manager this virtual machine to connect to Hyper-V, and then...
    • create a Hyper-V hosted Virtual Machine, can connect you and turn it on to test

    I'm looking forward to suggestions or alternative methods, but for the moment, it was the only way I could get it to work in my own laboratory, thought that others might not want to try to replicate this exercise.

    Windows Hyper-V (not supported) is a selection of OS comments available through the user interface in Workstation 9.  It defines the guestOS to 'winhyperv '.  Although the selection of the BONES of Hyper-V is not available through the user interface of 5.1 ESXi, I understand that support it is always there.

  • Convert computer virtual Hyper-V on ESXi 4.1

    Hello

    I'll be using vCenter Converter Enterprise 4.2.1 to convert a few Hyper-V virtual machines to ESXi 4.1. Converter

    has an option for Hyper-V and see the virtual machine. These convert motor on or off? Any gotcha in this process?

    You convert Hyper v (2008) or Hyper-V 2.0 (2008 R2).  If you use Hyper-V (2008) then you want to remove your integration components before the conversion.  Depending on your operating system, you may need to change your network driver.  The only other requirements is to go into your virtual machine once converted and remove all ghost devices in DevMgr.  You can do that by typing the following in a command prompt form:

    Set devmgr_show_nonpresent_devices = 1
    Start devmgmt.msc

    Go to the file menu, expand the view and select Show hidden devices.

    Good luck.  Ive done much P2Vs of Hyper-V with great success.

  • Hyper-V for ESXi conversion not transfer information from IP address

    I made a successful conversion of a VM Windows 2003 Hyper-V to ESXi 4.1 using Converter 4.3. It seems that IP information are not reported on the destination vNIC VM VMWare. This is expected behavior?

    Hello.

    Yes, this is the expected behavior.  I usually run a "ipconfig/all > C:\ipinfo.txt" command before the P2V, while I have the old information ready in the new virtual machine.

    Good luck!

Maybe you are looking for

  • hidden clip?

    For some reason, this happened, which seems to do, I don't know, 'hide' the clip, and the clip also showed no during playback. How do cancel you and how I did it in the first place, just so I can avoid it when it happens again!

  • Time Machine Mens on the size of my disk :(

    I have an external hard drive connected to a MacMini running OSX server, the most recent version. This drive has a directory which is Time Machine turned on. My MacBook Pro has been save to that drive for-like-ever. A couple of years. A month ago, I

  • can I go back to firefox 6

    I seem to be in the beta channel. I think for my busy lifestyle, having too many problems of incompatibility with Add ons and extensions. I don't have time to keep the conclusion and the expectation of new solutions and improvements of your developer

  • Need drivers for Windows XP Home edition on the Russian language for Satellite M35x-s149

    Help, please. Can not find the drivers for windows XP SP3 or SP2 on the Russian language for TOSHIBA Satellite M35X-S149.

  • Very slow DVD recording on my Satellite M30

    Hello I have a satellite M30 with a burner DVD Teac dv-w28e. Engraving on takes (8 x) DVD 1 hour and a half to 4 GB, even if the burning program indicates the speed is 8 x and the estimated time is 10 minutes.So, what's the problem?