Serial port support - would it be a threat to security?

Our customer wants to virtualize a physical machine running an application using a modem connected to the serial port. Users dial-in to this modem to access the application. They are aware that HA or Vmotion is not possible if the server is virtualized, because the modem will be connected to one of the ESX hosts, but they still want to virtualize it.

Is virtualization possible in this case, the consequences - is there a threat to the security of the ESX host and can appear any other problem?

Hello

Is there a threat of a series of device connected to an ESX host? He must not like there should be nothing listening on the serial port connections. If there was, IE. a console series, then Yes. There is a possible risk.

I would like to use a serial or usb to the device of the IP to move the risk in the networking arena where it is easier to firewall and that direct control attached to a serial port. This move also risks of "composition of war" outside the hypervisor and its own device. Plus, you get the ability to use VMotion.

Best regards

Edward L. Haletky

VMware communities user moderator

====

Author of the book "VMWare ESX Server in the enterprise: planning and securing virtualization servers, Copyright 2008 Pearson Education.»

Blue gears and other Blogs: http://www.astroarch.com/wiki/index.php/Blog_Roll

Tags: VMware

Similar Questions

  • Several Modbus with shared serial port

    I know that Lookout lets do you cool things like have several protocols series that share the same serial port hardware.

    I asked where I might like Lookout to simulate a network of Modbus Devices for some tests. In this case, I want to implement multiple Modbus slave, all with different node addresses Modbus objects and have all listen to the same serial port. Would this be possible? Each received Modbus message will include the number of slaves in there. Multiple objects can listen on port and only the selected one respond?

    Thank you

    Max

    Yes, slave modbus Lookout can work this way.

    But the ethernet mode does not support.

  • Access to the serial port in BeOS R5 invited?

    Hi all

    It is a long shot, but I figure, it can't hurt to ask... I've got BeOS R5 race as a guest under VMWare Fusion 3.1.0 operating system and (more or less), it works as expected.

    The only thing I would do in the BeOS VM that I cannot use my Keyspan USB <>- serial adapter as a serial port, so that I can use a BeOS to communicate via a RS232 line program.  Is there a secret way to get my adapter series Keyspan to appear as/dev/serial1 in BeOS?

    Thank you

    Jeremy

    Mapping to series host equipment does not support the merger, but you can use a pipe mechanism to create a virtual serial device to present to your guest operating system.  Others have connected Keyspans to Windows, Ubuntu and other guests supported OS popular with different results.  Here are a couple of old son to read, these refer to others threads with more information is a bit recursive.

    USB Serial Port a little work

    Serial port support - please?

    The index of google for forums of Fusion has several more hits, but they are similar.  These two threads should give you an idea of what is possible with pipes and macports.

  • Physical serial ports are supported in ESXi?

    Physical serial ports are supported in ESXi?  I install Windows 2008 SBS on a HP Proliant ML350 G6 ESXi (version of stick USB HP) running. The server comes with a serial port on board.  I was hoping that connect an external modem and expose it to the virtual server, Windows SBS 2008 to serve as a network fax.  Is this possible? Alternatives if not supported?

    It would be a no.

    There are TCP/IP USB devices, do not know if there are similar devices for the series, but NO physical devices, sound cards, usb, parallel, series can be transmitted to a virtual machine.  That's because ESX uses vmotion, and it was designed to let the virtual machine move between machines, so allowing physical connections so would interfere with this operation.

    http://www.tacticalsoftware.com/products/dialoutez.htm

    However, who should be a solution for you.

  • Is - this windows 7 professional support serial ports?

    I have 6 older machines which connects to the pc through port series and I was wondering if I should get a usb serial Hub. All 6 machines to connect to the same pc

    Some hardware supports Win7 installation supports win7.

    The question is whether your material, these unknown machines are compatible win7.

    Usually if you have a desktop computer without serial ports, the option preferred is to use a card series pci as usb/serial converters can be problomatic.

  • Taken serial port redirection supported with PCoIP?

    Does anyone know if the serial port redirection is supported when connecting through the PCoIP Protocol?

    This works if you are using the RDP Protocol, but not of PCoIP.

    Connection of Windows Embedded Standard View 4 customer via View 4 build 233023 XP SP3 server computer virtual resource.

    No, only USB ports can now be redirected with PCoIP

    Best regards

    Linjo

    If you find this information useful, please give points to "correct" or "useful".

  • ESXi 4.1 supports the transmission of serial port?

    I'm having a bit to find this information...

    My ESXi server has a serial port that I want to be available to a virtual machine (guest).  Is this possible?

    I don't want to share the serial port or do anything "fancy".  I just want it to be accessible.

    Thank you!

    Starting with ESXi 4.1, you can go through a serial port.  Simply add a port series to virtual hardware for the virtual machine and choose the option 'Use the physical serial port'.

  • dc7800mt: dc7800 10 Windows 64 b PCI Simple Communications and PCI Serial Port drivers missing

    Can't seem to find the drivers for a dc7800 upgraded to Windows 10 64 b for PCI Simple Communications Controller and PCI Serial Port devices.  Any help would be greatly appreciated.  Paul_Tikkanen, are you still there?

    Hello:

    Yes, I'm still here, and Yes, I know what drivers you need...

    You need this for the PCI of Simple Communications controller:

    This package contains the device driver Intel Active Client Manager Host Embedded Controller Interface (HECI) for desktop models and operating systems supported.

    FTP://ftp.HP.com/pub/SoftPaq/sp46001-46500/sp46137.exe

    PCI serial port:

    This package contains the Intel Local Management Service (LMS) and the support of Serial - over - LAN (SOL) for Intel Active Management Technology (AMT) for the supported desktop models and operating systems. This software is part of the Intel Digital Office Initiative.

    FTP://ftp.HP.com/pub/SoftPaq/sp46001-46500/sp46134.exe

    And let me give you a bonus tip... Install the audio driver Soundmax ADI W7.

    I found that works much better than W10 installed.

    You install it, then select multistreaming in adi Control Panel, restart again and go to manage audio devices in the Control Panel, and then select the PC speakers, but of course install the W7 audio driver is optional, and it is up to you...

  • Can not read the serial port VISA without MAX

    Hello

    I'm trying to build an application that will interface with a Black Cat Systems GM-10 radiation detector.

    The app works fine on my computer (with the full development system OR) but when I install it on another computer, without LabView, the application cannot see the serial port!

    I checked that the driver is installed correctl and Windows can see the device, but when I run my program, he can't seem to access the serial ports.

    I then tried to install MAX on the second computer, how the application worked well, but as I install this app in other places, I don't really have the ability to install MAX everywhere (software must be autonomous).

    Any help would be appreciated!

    Z

    I would have joined the project file, but the forums seem to not want to allow me to download that big of a file.

    What version of LabVIEW are you using? With 8.x, the installer is very able to install the runtime of NI-VISA and MAX. If you are using an older version of LabVIEW, there is an option to include the series VISA support. Install just MAX will do nothing to make the available ports. This is the VISA that does this.

  • Error: The property node (arg 8) visa to configure the Serial Port

    I'm trying to control 8 USB to R232 via a HUB of 10 ports Tripp-Lite (model U222-010-R) and do not have consistent results.  Just after rebooting my computer, I have no problem in running the following program: (I tried to download the VI directly but without success, so here's the extract)

    I made sure that the COM ports that I select are that one is available on both the Device Manager and in the NOT-MAX.  But after awhile, it does not work or if the HUB is unplugged and replugged in (even if the names are correct and up-to-date in devices and NOR-MAX Manager) I get the error code "property Node (arg 8) visa set up a Serial Port (Instr) .vi" I want to be able to see these ports consistantly more without having to restart my computer all the time.  Is there a better Setup for this? The previous installation of the computer has a PCI card for it and we have not had any problems with the code, but are facing problems with our upgrade.  The old computer ran Windows XP and had cards PCI and the new computer that I am using a Windows 8 and the USB HUB.  Thanks for any help you can give!

    Mr says:

    Jeff,

    It is a one off lines from specifications Tripp-lite:

    -On bus power, 500mA from the USB 2.0 computer port is shared between hub ports

    This would be in support of what I need or not necessarily?

    -Mr

    No! That's the 50mA by port not 500mA.  an order of magnitude full powered USB (if you want reliable - if you want real problems which appears irratically each time only and is a headache to track down which would)

  • Serial Port problems - carriage return and use as an executable file

    Hello

    I developed an application to send a few simple commands on the serial port and read the corresponding answers of a device that I am in communication with.  I have been using logical Port to watch the line TX of the serial port.

    By using the Visa configure Serial Port I set the stop character property allow true and used the hexadecimal value D trying to make the termination a carriage return characters.  When I sent the order, I'll send the cmd followed by Enter.  No matter if this property is set to true or the hexadecimal value is set to D for carriage return or line break is, the serial port would always send a line break.

    Then I got crafty and the string constant under normal display to hexadecimal display.  The ONLY way I could send a carriage return was manually putting 0x0D after ordering.  So my question is, why the Visa set up the Serial Port is not working correctly, and is there a better way to send a carriage return?

    My next issue is facing the construction of executable files.  I'm using LabVIEW 8.2 and wrote this program for another employee to use on his laptop computer.  I did install runtime Labview 8.2 and led to the executable that I generated.  I did-> the executable by clicking Tools build the executable.  The problem I noticed was that the executable would open and will work perfectly, but it would not send any data the serial port.  I then ran the executable on my laptop (which contains the full version of LabVIEW 8.2) and the serial port has worked well.  I guess my question is... Are there plug-ins that must be installed to use the serial port with the Labview runtime engine?  Or y at - it a step that I failed to do?

    Thank you

    Gary Still

    Not immerse in the first issue. The Knight will probably be galloping until shortly.

    For your second question, after building the executable, you must build the installer and includes support for the VISA. VISA is required for serial communication, and it does not accept American Express.

    It may be useful

    -AK2DM

  • Name of resource VISA get does not have USB serial ports

    We built an application on a computer that had a built-in serial port - COM1.  We have the option to change the COM port in the application.  We have installed the application built on a computer that has no serial port, but installed a USB serial Converter which records as COM3.  LabView does not see this port, even with a test application to return only the names of VISA resources.

    We have verified that the port is good with another program (a Modbus Simulator) and installed the last TIME VISA v4.41 separately without result.

    Any suggestions for more troubleshooting would be extremely useful.

    Joe T.

    My main of the application still does not work, but now the little test ones are.

    Here's what I did:

    1. update my LabView 8.5 with the last VISA - 4.4 runtime.  This update the installer as well.

    2. added the install MAX for the build.

    3. adding the Support of Configuration of NI-VISA for construction

    4. uninstalled the app and reinstalled with the new volume of the system.

    When I run MAX, COM3 appears.  He also appears in the application of test resources.  The simple test Modbus to write the program works, too.  I have a sneaky feeling that COM1 can be hardcoded somewhere in the parent application; our next task is to find where communication breaks down in our code.  The bottom line seems to be a lack of experience with the demand of our manufacturer.

    Thanks to all who participated!

    Joe T.

  • When a character appeared reading serial port

    How to wait for some specific characters occurred in the serial port (e.g. port COM1 RS232 on PC) and then they recover at the port?

    I want to communicate back with a motor controller that uses ASCII strings such as commands and responses. It formulates a response to any command sent, and the response contains exactly a termination character (that I can specify during installation) at the end of the response string. Sometimes also, it sends a message when there is no order issued, for example a disc error message. There is no simple way and reliable when the controller is going to speak, when he won't, and the message will be exactly how many time, but we do know that each message will have this stop only at the end character. I would like to interpret the entire message in my code, that is to say, I would like to retrieve the string of all the characters from the previous endpoint character up to and including the most recent stop character. I think it means that I would have a VI that returns the message string and does not stream until the stop character appeared and was added to the response string. Or, Alternatively, a loop that adds entire messages to a queue of strings.

    All the screw example I found seems to rely on a certain number of milliseconds to wait or to know how many bytes to read, in order to use VISA Read.

    So far, I use a loop which seeks bytes in the buffer, retrieves everything to add to a string of shift register and test if there is a character of the string endpoint, all extract up to and including the stop character, if so. This feels very awkward and expensive for what should be a common task. Is this general law approach, or did I miss something in a simpler way?

    I read on the communication by Message and characters of endpoint, approach that sounds functionally similar to this, but it seems around standards of SCPI and my motor controller does not support this. In any case example Finder does not get a single hit on 'Message '.

    Thank you!!

    It really looks like you are doing things a lot more difficult it must be. Look at the VISA configure Serial Port. It has a character of endpoints allow and end characters entries. If you wire a real (or leave that he unwired) entry activate, read VISA will end automatically when you specify the stop character is detected. As long as the number of bytes to read is larger that the largest string that you expect to read, there is nothing else you need to do. That's how examples of shipment are put in place and discussions about the characters of the termination. Should there be nothing related to sustainable intensification of CROPS. If you do not get a message in your specified time-out, you get a time-out error.

  • Bluetooth Serial Port (SPP) on the XOOM profile

    Does anyone has experiences using devices to profile serial port with the XOOM?

    We try to get our through SPP Bluetooth barcode scanner and we had a few problems with the matching.

    We are able to pair our device with the XOOM did very well (using Bluetooth 2.1 Secure Simple pairing (SPP)), however, when we try to open a serial port (RFComm channel), the XOOM is trying to make an increased level of security and enforce Bluetooth man in the middle (MITM) protection.  The problem is that our device does not have ANY screen or buttons that would allow a user to enter the PIN code!

    Anyone tried the "non - ui" SPP BT 2.1 devices with the XOOM?  Such as barcode scanners or GPS units?

    We "got around" this by having our 'claim' device, the pin code has been entered correctly, but this is really just a hack.

    Thanks for any comments.

    Len

    We have solved this problem by using a new call API 2.3 and higher to specifically ask for a link "unauthenticated."

    Socket CHS Series software now fully supports Android 2.3 and features honeycomb (3.x).

    Kind regards

    Len Ott

    Socket Mobile

  • Smartphones blackBerry how to connect the serial port (SSP) to a PC?

    I try to connect my BB (8310) to my pc using the port profile series bluetooth with my old phone (sony ericsson w300i) would just pair the phone with the pc and then the pc would discover services on my phone and I woluld double clicking the port icon series, but when I explore the services BB I only have handsfree and dial-up networking , I know the phone supports the serial port because I checked in the bluetooth options, and it supports the connection to the serial port.

    Thank you.

    http://www.BlackBerry.com/BTSC/search.do?cmd=displayKC&docType=kc&externalId=KB04132&sliceId=1&docTy...

    proceed as if you want to sync via bluetooth

    If you just want to transfer files, stop after completing step 5

Maybe you are looking for

  • How to decompress emails?

    I inadvertently clicked on 'archive mail' and now I am unable to see in my box in. What should do?

  • Cannot find a driver for multimedia audio controller

    Windows XP home operating computer pavilion a1200e Fomated disc and reloaded xp and downloaded all the drivers for the hardware but it still shows under other in the Device Manager and have no sound.

  • W LAN Satellite A10

    Hellobought a Wlan mini-PCI for the A10, but may not know where to attach the wires on the map.The A10 has a black and a white wire.The mini-PCI is equipped with connectors for 'MAJOR' and ' to THE '. What wire color is intended to THE MAIN or. I can

  • After access freezes Office safe mode after pressing on on Windows XP

    I get the blue screen advising to go in safe mode to fix.  I'm in safe mode after you restart stopping computer, I press f8 alnd when I get xp a lot of filenames scroll down then the comp freezes there. I can only try to reboot by turning off my comp

  • How to change the folder opens when windows Explorer opens

    In XP Service Pack 3, when Win Explorer is open, files that open has changed on its own (or I don't know what I did to cause this change). Records of Documents are all posted, but the C: drive is closed, where it will display all folders to open at t