vSphere Security Series – vShield Zones
November 30th, 2009 by bl4ckc4t
vShield Zones is a security virtual appliance that provides visibility and enforcement of network policies within a VMware vSphere deployment. It provides the compliance protection of corporate security policies as well as industry regulations. Previous visibility compliance required diverting traffic from ESX host to an external physical appliance lacking the efficiency of shared computing pool or cloud.
vShield Zones allow the capability to create logical zones that span all the physical resources of the virtual datacenter, so that distinct levels of trust, privacy and confidentiality can be maintained. It also enables the capability to bridge, firewall or isolate virtual machine zones based on logical trust or organizational boundaries.
The main components of the architecture consist of 2 appliances, the vShield Manage and the vShield Appliance. The vShield Manager is the console to gain central view of each zones set through the vShield Appliance. The vShield is the active security component of vShield zones and each instance provides application aware traffic analysis and state full firewall protection by inspecting network traffic and determining access based on a set rules.
A vShield regulates traffic based on zones of trust separating traffic into unprotected and protected zones. The virtual machines protected by a vShield reside in the protected zone and all traffic destined for the protected machines enter from the unprotected zones.
Key features of vShield Zones:
- Central Management of Logical Zone Boundaries and Segmentation
- Leveraging existing virtual infrastructure container, hosts, virtual switches and VLANS as logical trust or organizational zones, also define policies to bridge, firewall, or isolate network traffic between zone boundaries and manage and deploy policies for entire vCenter server deployment.
- Network Enforcement and Flow Monitoring
- Classify traffic by network or application protocol (HTTP, RDP and SNMP); in addition you can filter traffic with state full packet inspection (SPI). vShield zones also allows you to automatically track dynamic port connections for protocol, such as FTP and track network connections across vmotions migration events. It also converts observed network flows into precise network enforcement rules and lets you monitor both allowed and disallowed activities.
- Tight Integration with Existing Deployments
- Self configure vShield Zones virtual appliances in line on existing ESX host and integrate with vCenter server to automatically gather and present existing deployment hierarchy. Also scan and discover existing applications running on virtual machines to identify application protocols.
- Management and Reporting
- Managed via a web base access to report on zones and provides a dashboard overview of current deployment status and real-time activity.
- Comments Off


