Outline: Securing The Cloud with VMWARE vsphere Code: ACBE GEN-VMSECURE_ONLINE. Days: 5. Course Description:

Similar documents
VI3 to vsphere 4.0 Upgrade and New Technology Ultimate Bootcamp

VMware vsphere 6.5/6.0 Ultimate Bootcamp

Administering VMware vsphere and vcenter 5

VMware vsphere 6.0 / 6.5 Infrastructure Deployment Boot Camp

VMware vsphere with ESX 6 and vcenter 6

VMware vsphere 6.0 / 6.5 Advanced Infrastructure Deployment (AID)

VMware vsphere 5 Ultimate Bootcamp

VMware vsphere 4.1 Ultimate Bootcamp. Course Overview. Course Outline

ATA Infotech Ventures Pvt. Ltd.

By the end of the class, attendees will have learned the skills, and best practices of virtualization. Attendees

VMware vsphere Customized Corporate Agenda

Introduction to Virtualization

VMware vsphere 4.0 Ultimate Bootcamp

VMware vsphere with ESX 4.1 and vcenter 4.1

New Features in VMware vsphere (ESX 4)

VMware vsphere 6.5 Boot Camp

VMware vsphere 5.5 Professional Bootcamp

Overview. Prerequisites. VMware vsphere 6.5 Optimize, Upgrade, Troubleshoot

"Charting the Course... VMware vsphere 6.7 Boot Camp. Course Summary

VMware vsphere with ESX 4 and vcenter

VMware Ultimate Bootcamp v 3.5

Potpuna virtualizacija od servera do desktopa. Saša Hederić Senior Systems Engineer VMware Inc.

VMware vsphere Administration Training. Course Content

VMware: Advanced Security Training

VMware vsphere 5.5 Ultimate Bootcamp. Course Overview

VCP410 VMware vsphere Cue Cards

VMware vsphere 6.5 Administration Basics Ultimate Bootcamp

VMware vsphere 4. Architecture VMware Inc. All rights reserved

Foundation for Cloud Computing with VMware vsphere 4

VMware vsphere Beginner s Guide

VMware vsphere: Install, Configure, Manage plus Optimize and Scale- V 6.5. VMware vsphere 6.5 VMware vcenter 6.5 VMware ESXi 6.

VMware vsphere 6.5: Install, Configure, Manage (5 Days)

VMware vsphere: Install, Configure, Manage (vsphere ICM 6.7)

[VMICMV6.5]: VMware vsphere: Install, Configure, Manage [V6.5]

"Charting the Course... VMware vsphere 6.5 Optimize, Upgrade, Troubleshoot. Course Summary

Advanced Vmware Security The Lastest Threats and Tools

VMware - VMware vsphere: Install, Configure, Manage [V6.7]

VMware vsphere 4.x/5.x to vsphere 5.5 Upgrade and New Technology Ultimate Bootcamp Course 01 - Course Introduction and Methodology

vshield Administration Guide

Professional on vsphere

vshield Quick Start Guide

The Future of Virtualization. Jeff Jennings Global Vice President Products & Solutions VMware

role at the the host. The the Administrator r can perform a user with Note Directory. Caution If you do

vsphere 4.1 Ultimate Bootcamp Course 01 Course Introduction and Methodology

VMware vsphere 5.5 Advanced Administration

The Future of Virtualization Desktop to the Datacentre. Raghu Raghuram Vice President Product and Solutions VMware

VMware vsphere: Taking Virtualization to the Next Level

Detail the learning environment, remote access labs and course timings

The vsphere 6.0 Advantages Over Hyper- V

VMware vsphere on NetApp (VVNA)

Real Security for Server Virtualization

Virtualization Security & Audit. John Tannahill, CA, CISM, CGEIT, CRISC

Virtualization with VMware ESX and VirtualCenter SMB to Enterprise

Logical Operations Certified Virtualization Professional (CVP) VMware vsphere 6.0 Level 1 Exam CVP1-110

vsphere Security Modified on 21 JUN 2018 VMware vsphere 6.7 VMware ESXi 6.7 vcenter Server 6.7

Deploying the Cisco ASA 1000V

Exam Name: VMware Certified Associate Network Virtualization

vsphere Security Update 2 Modified 04 OCT 2017 VMware vsphere 6.0 VMware ESXi 6.0 vcenter Server 6.0

Connect array to Cisco UCS and VMware vsphere

VMware vsphere: Fast Track [V6.7] (VWVSFT)

Logical Operations Certified Virtualization Professional (CVP) VMware vsphere 6.0 Level 2 Exam CVP2-110

E V A L U A T O R ' S G U I D E. VMware vsphere 4 Evaluator s Guide

Exam Name: VMware Certified Professional on vsphere 5 (Private Beta)

vsphere Security Update 2 Modified on 22 JUN 2018 VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5

VMware Join the Virtual Revolution! Brian McNeil VMware National Partner Business Manager

VMware vsphere 4.1 Security Hardening Guide. Rev C: June 2011

Securing the Data Center against

vsphere Networking Update 2 VMware vsphere 5.5 VMware ESXi 5.5 vcenter Server 5.5 EN

VMware Exam VCI550 VMware Certified Instructor on vsphere 5 Version: 7.2 [ Total Questions: 270 ]

vnetwork Future Direction Howie Xu, VMware R&D November 4, 2008

vsphere Networking Update 1 ESXi 5.1 vcenter Server 5.1 vsphere 5.1 EN

Vmware VCP-310. VMware Certified Professional on VI3.

What s New in VMware vsphere 4:

VMware vsphere 4 Competitive Reviewer s Guide W H I T E P A P E R

Vendor: EMC. Exam Code: E Exam Name: Cloud Infrastructure and Services Exam. Version: Demo

vsphere 5/6: Install, Configure, Manage Review Questions

Virtualization with VMware ESX and VirtualCenter SMB to Enterprise

vsphere Security Update 1 Modified 03 NOV 2017 VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5

Cisco ACI Simulator VM Installation Guide

o Restrict administrative privileges

Cloud and Datacenter Networking

vsphere Security VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5 EN

Vmware VCP-511. VMware Certified Professional on vsphere 5 (Private Beta) Download Full Version :

vsphere Design and Deploy Fast Track v6 Additional Slides

Configuration Maximums

VMWARE VSPHERE: FAST TRACK V6.7 (EDU-VSFT67)

vsphere Datacenter Administration Guide

vsphere Basic System Administration

Configure RSPAN with VMware

Installing VMware vsphere 5.1 Components

Virtual Security Gateway Overview

Vmware VCP410. VMware Certified Professional on vsphere 4. Download Full Version :

Course overview. CompTIA Security+ Certification (Exam SY0-501) Study Guide (G635eng v107)

Vendor: VMware. Exam Code: VCP550PSE. Exam Name: VMware Certified Professional - Data Center Virtualization (PSE) Version: Demo

VersaStack for Data Center Design & Implementation (VDCDI) 1.0

EMC Performance Optimization for VMware Enabled by EMC PowerPath/VE

Security in a Virtualized Environment with TrendMicro

Cisco HyperFlex Systems

What s New in VMware vsphere 4: Virtual Networking W H I T E P A P E R

iscsi Target Usage Guide December 15, 2017

Transcription:

VMTRAINING Securing The Cloud with VMWARE vsphere Code: ACBE GEN-VMSECURE_ONLINE Days: 5 Course Description: This course is going to provide a solid understanding of the various components that make up the vsphere environment. From the virtual CPU to the storage devices attached to your host and everything in and around that network, we will study and understand the interconnectivity and design of all those components. You will walk away with a solid understanding of how the adversary infiltrates the virtual environment and most importantly how you can secure that environment. We will study the virtual components that VMware has developed in the vsphere product line, including the vcpu, vmemory, vnetwork, vstorage, ESX/I host, virtual center, update manager and many other plug-ins, appliances and third-party mitigation tools. We will also prepare you for the Certified Virtualization Security Expert certification. This is a unique and one-of-a-kind certification intended to prove you have the knowledge necessary to secure a virtual environment, cloud environment that is running on VMware vsphere. When you finish this course you will be able to assess the security posture of your vsphere 4.x architecture, and by extension, the services offered thru and by that architecture, and reducing the identified risks. The course will study the following VMware products: ESX 3.5, ESX 4.x, ESXi 4.x, vcenter 4.x Outline: 1. Course Introduction and Methodology 2. Penetration Testing 101 What is a Penetration Test? What does a Hack Cost You? Penetration Testing Methodologies Information Gathering (HOL) Scanning (HOL) Enumeration (HOL) Tools of the Trade (HOL) Website Review How to stay up to date! Hashing, Encryption and Certi_cates. Di_erent Types of Exploits! (HOL) Where do we start with vsphere? 3. Primer and Rea_rming our Knowledge What is Virtualization? Hypervisor Types ESX vs ESXi vsphere 4.1 Product Features

Management Interfaces (HOL) DRAC/iLO Web Interface SSH via Putty vsphere Client, ESX/i and vcenter vma, vcli, Powershell, PowerGUI Communication Ports General Administrative Features (HOL) vcenter Views Tasks and Alarms VM Administration Advanced Administrative Features (HOL) DRS HA Fault Tolerance 4. Security Architecture, vcpu, vmemory Linux Kernel Architecture Linux Files System ESX/i File Structure Log Files (HOL) ESX/i and vcenter Security Architecture Virtual Machine Monitor Security Roles and Permissions (HOL) VMsafe Security at its _nest vcpu (HOL) Bu_er Over_ow Protection vcpu Availability vmemory Transparent Page File Sharing Balloon Driver Swap File Compression Hyperspacing 5. Routing and the vnetwork Networking Components vswitch vnic Port Groups Uplinks Physical Switch Con_guration (HOL) NIC Teaming (HOL) Load Balancing Failover Security Features VLAN s (HOL) vds Private VLAN Network I/O Control Cisco Nexus 1000v Network Routing (HOL)

6. vstorage Architecture and Security Implementations Virtualized Storage (HOL) Pluggable Storage Architecture Storage Control vsphere API for Array Integration Fiber Channel LUN Masking SAN Zoning Fiber Channel Attacks Securing Fiber Channel iscsi (HOL) Software vs Hardware Initiators iscsi Security Features 1. CHAP IPSec Securing iscsi 7. Hardening the Virtual Machines Harden the Server Unnecessary Functions Using Templates (HOL) VM Isolation (HOL) VM Advanced Settings (HOL) SetInfo Hazard VMCI (HOL) Isolation Tools (HOL) VMsafe Settings 8. Hardening the Host Service Console Security (HOL) Password Integrity sudo Wheel Group File System Integrity Encrypted Communication DCUI Direct Console User Interface CIM Common Information Model Tech Support Mode (HOL) Proxy.xml ESXi Lockdown Mode 9. Hardening Virtual Center Limiting Administrative Access (HOL) Limiting Network Connectivity Server Certi_cate Replacement (HOL) Controlling Log Files (HOL) Custom Rules Update Manager VMware Converter Managing the vcenter Clients (HOL)

vshield (HOL) 10. Virtualizing your DMZ DMZ Virtualization with the VMware Infrastructure Virtualized DMZ Networks Three Typical Virtualized DMZ Con_gurations Partially Collapsed DMZ with Separate Physical Trust Zones Partially Collapsed DMZ with Virtual Separation of Trust Zones Fully Collapsed Best Practices for Achieving a Secure Virtualized DMZ Deployment (HOL) Harden and Isolate the Service Console Clearly Label Networks for each Zone Set Layer 2 Security Options on Virtual Switches Separation of Duties Use ESX Resource Management Capabilities Regularly Audit Virtualized DMZ Con_guration Common Attack Vectors (HOL) SSLv3/TLS Renegotiation Web Access Vulnerabilities 11. Party Mitigation Tools Altor Networks Catbird s vcompliance (HOL) HyTrust Re_ex Systems VMC CheckPoint Virtual Appliances Trend Micro (HOL) TripWire Con_guration Management 12. Putting it all Together Looking back at the key security issues for all topics covered Design thoughts Final Hands On Lab Can you secure your environment? Follow a Westcon Training Online : Joining a Westcon online training is easy from either a Mac, PC, ipad, iphone or Android device. Once subscribed to the training, attendees simply click the meeting link Westcon Academy provides by email. While joining, attendees choose whether to conference in via phone or their computers' microphone and speakers.

For the practical lab exercises, we work together by sharing keyboard and mouse control between instructor and student. For the presentation, the Westcon instructors Interact on the screen using the pen, highlighter, arrow and spotlight tools.