6.7

Table Of Contents
Because Virtual Machine 1 does not share a virtual switch or physical
network adapter with any virtual machines in the host, the other resident
virtual machines cannot transmit packets to or receive packets from the
Virtual Machine 1 network. This restriction prevents sniffing attacks, which
require sending network traffic to the victim. More importantly, an attacker
cannot use the natural vulnerability of FTP to access any of the host’s other
virtual machines.
Internal virtual
machines
Virtual Machines 2 through 5 are reserved for internal use. These virtual
machines process and store company-private data such as medical
records, legal settlements, and fraud investigations. As a result, the system
administrators must ensure the highest level of protection for these virtual
machines.
These virtual machines connect to Internal Network 2 through their own
virtual switch and network adapter. Internal Network 2 is reserved for
internal use by personnel such as claims processors, in-house lawyers, or
adjustors.
Virtual Machines 2 through 5 can communicate with one another through
the virtual switch and with internal virtual machines elsewhere on Internal
Network 2 through the physical network adapter. They cannot communicate
with externally facing machines. As with the FTP server, these virtual
machines cannot send packets to or receive packets from the other virtual
machines’ networks. Similarly, the host’s other virtual machines cannot
send packets to or receive packets from Virtual Machines 2 through 5.
DMZ Virtual Machines 6 through 8 are configured as a DMZ that the marketing
group uses to publish the company’s external Web site.
This group of virtual machines is associated with External Network 2 and
Internal Network 1. The company uses External Network 2 to support the
Web servers that use the marketing and financial department to host the
corporate Web site and other Web facilities that it hosts to outside users.
Internal Network 1 is the conduit that the marketing department uses to
publish content to the corporate Web site, post downloads, and maintain
services like user forums.
Because these networks are separate from External Network 1 and Internal
Network 2, and the virtual machines have no shared points of contact
(switches or adapters), there is no risk of attack to or from the FTP server
or the internal virtual machine group.
By capitalizing on virtual machine isolation, correctly configuring virtual switches, and maintaining network
separation, the system administrator can house all three virtual machine zones in the same ESXi host
and be confident that there will be no data or resource breaches.
vSphere Security
VMware, Inc. 206