IDS in a Virtualized Environment (vmware)

Can anyone elaborate on an IDS solution for a virtualized environment?
I have blade servers running ESX/ESXi - heavily virtualized environment. Im using blade switches as chassis I/O - no pass throughs.
The requirement is to run an IDS service such that VM-to-VM traffic is monitored. The traffic flow can be between two VMs on the same blade, 2 VMs on two separate blades in the same chassis, or two VMs on two separate chasses...
In that case, I see 3 traffic flows off the bat...
same blade: vm-to-vm traffic is switched by a hypervisor switch (1000v or vmware vDS).
different blades in same chassis: vm-to-vm traffic will leave blade and be switched by chassis hardware switch (chassis I/O blade).
different chassis: vm-to-vm traffic will have to go to ToR (maybe even end-of-row).
NOTE: if VMs are on different VLANs, traffic will always go to end-of-row/agg switches (the L3/L2 boundary).
So given all those possible flows, what is the best way to go about deploying an IDS service? Placement? Virtual or physical? etc....
Thanks!

This topic was disccussed in this thread from last week:
(too bad we can't merge threads)
https://supportforums.cisco.com/thread/2092838?tstart=30
- Bob

Similar Messages

  • Can CUCM 8.5 version be installed on a DL 380 G5 server in Virtual environment (Vmware Esxi 4.0 or 4.1)? Or does it have to be only installed in UCS boxes for VMware?

    Can CUCM 8.5 version be installed on a DL 380 G5 server in Virtual environment (Vmware Esxi 4.0 or 4.1)? Or does it have to be only installed in UCS boxes for VMware?
    1. If the installation is possible for the Vmware instance on a DL 380 G5/G6 server , will that be supported by Cisco ?
    Similary is the case with CUIC 8.5. Has anybody worked on these do suggest ideas.

    Virtualized UC applications from Cisco are only supported on the UC on UCS platform using ESXi 4.0, 4.0 Update 1, or 4.1 - hypervisor support may vary based on application.
    Hailey
    Please rate helpful posts!
    Sent from Cisco Technical Support iPhone App

  • IDS in a Virtualized Environment

    Can anyone elaborate on an IDS solution for a virtualized environment?
    I  have blade servers running ESX/ESXi - heavily virtualized environment.  Im using blade switches as chassis I/O - no pass throughs.
    The  requirement is to run an IDS service such that VM-to-VM traffic is  monitored. The traffic flow can be between two VMs on the same blade, 2  VMs on two separate blades in the same chassis, or two VMs on two  separate chasses...
    In that case, I see 3 traffic flows off the bat...
    same blade: vm-to-vm traffic is switched by a hypervisor switch (1000v or vmware vDS).
    different blades in same chassis: vm-to-vm traffic will leave blade and be switched by chassis hardware switch (chassis I/O blade).
    different chassis: vm-to-vm traffic will have to go to ToR (maybe even end-of-row).
    NOTE: if VMs are on different VLANs, traffic will always go to end-of-row/agg switches (the L3/L2 boundary).
    So  given all those possible flows, what is the best way to go about  deploying an IDS service? Placement? Virtual or physical? etc....
    Thanks!

    Since you're asking this question in a Cisco forum, I assume you are looking for a Cisco type answer.
    Cisco does not have any VM based sensors (unlike Sourcefire, and maybe some other vendors).
    It appears that you can not configure a virtual switch to span traffic externally. However you CAN set up a VMware host to promiscuously receive a copy of all traffic on the vswitch.
    I read about this solution that might help, but I've never tired it:
    “The Solera V2P Tap is a VMware™ virtual appliance that passively  captures network traffic flowing through an ESX Server virtual switch.  The Solera V2P Tap then regenerates that traffic to any physical port,  and then onto the physical wire, for complete visibility into the  traffic and analysis by any existing security or management tool for  in-depth monitoring or analysis.”
    http://www.soleranetworks.com/products/datasheets/datasheetV2Ptap_web.pdf
    - Bob

  • Virtual environment support: microsoft or vmware

    Guys, is any virtual environment officially supported for UCM? have any of you tried it?
    Thanks

    You have run into the same situation we have.
    We had lots of customers on VMWare, and back in the day Stellent told us go ahead, it would be fine. However, now the official response from Oracle support is you will receive a best effort of support. I'm not trying to bash Oracle support here. So far, the best efforts we've received has been pretty good, but we also have a pretty good relationship with some of the support people. Ultimately, they can cut you off though, especially if they can tie the issue to virtualization in any form. Plus, don't forget about the license issue. If you run UCM in a VMWare machine that you've allocated 2 processors to, but the physical box has 12 processors, you have to license all 12 processors. The licensing is based on the physical box, no the hardware allocated to your virtual instance.
    We could go on forever about why that is that way, and we have had a slew of calls with Oracle on this matter and it is not changing. We are still on the fence ourselves, but we have recently been recommending people either go with Oracle VM (which is not a terrible choice) or go standalone physical box. Most of our customers hate Oracle VM option because they already have VMWare. Catch 22.

  • Oracle product not supported on Vmware virtual environment

    Members,
    Oracle certification says Oracle products running on Vmware virtual environment are not supported.
    One of my development Identity manager setup is running on Vmware virtual environment.
    As of now application is running fine and I am getting support from Oracle on product issues.
    Can anyone suggest what could be the impact of this in future and what types of issues I can expect in future.
    Thanks,
    S M

    Could you verify this behaviour outside a VMware virtual machine?
    If yes, then please open an SR on Metalink to let support diagnose.
    Provide an RDA, AWR snapshot if you have licensed the Diagnistic Pack - if not than provide STATSPACK snapshots.
    Sorry - but this is a database upgrade forum :-)
    Regards
    Mike

  • Running MII on a Wintel virtual environment + hybrid architecture questions

    Hi, I have two MII Technical Architecture questions (MII 12.0.4).
    Question1:  Does anyone know of MII limitations around running production MII in a Wintel virtualized environment (under VMware)?
    Question 2: We're currently running MII centrally on Wintel but considering to move it to Solaris.  Our current plan is to run centrally but in the future we may want to install local instances local instances of MII in some of our plants which require more horsepower.  While we have a preference for Solaris UNIX based technologies in our main data center where our central MII instance will run, in our plants the preference seems to be for Wintel technologies.  Does anybody know of any caveats, watch outs or else around running MII in a hybrid architecture with a Solarix Unix based head of the hybrid architecture and the legs being run on Wintel?
    Thanks for your help
    Michel

    This is a great source for the ins/outs of SAP Virtualization:  https://www.sdn.sap.com/irj/sdn/virtualization

  • 11g in virtual environment

    Good day to all,
    I have certain questions regarding Oracle 11g working under virtual environment, and any information in this regard is most welcome.
    We are planning to migrate multiple existing databases(say 9i, 8i, 10g) on one bigger server with sufficient RAM, CPU and other resources.
    We are planning to migrate all the above databases on 11g and use some virtual environment software to install multiple 11g databases on that server.
    I think the migration should not be a big issue as we will use simple export and import.
    My questions and doubts in this regard are as follows
    (1) Is it practical to run production databases in virtual environment
    (2) Is 11g is mature enough to be used in such environment(or 10g r2 will be better option)
    (3) If one runs multiple databases or instances in virtual environment, how the Kernel setting of one database will effect the other one as I have heard that these virtual software’s( for example VMware) shares some common files for system resource.
    (4) Which OS will be a better option in such scenario(HP UX, SUN Solaris, Windows....)
    (5) If any one is working in such scenario can suggest his or her own experience.
    (6) Any other suggestion will be appreciated.
    Regards
    Ans

    (1) Is it practical to run production databases in virtual environment Yes
    (2) Is 11g is mature enough to be used in such environment(or 10g r2 will be better option) Yes. Infact, there are some really good features of 11g that you may want to consider. Deciding 10g or 11g, depends on the type of databases are in hand. It would be better if you'd do some testing on both environments to come to a better conclusion.
    (3) If one runs multiple databases or instances in virtual environment, how the Kernel setting of one database will effect the other one as I have heard that these virtual software’s( for example VMware) shares some common files for system resource.
    http://download.oracle.com/docs/cd/E11081_01/doc/doc.21/e10901/resources.htm#CJADCIHE
    http://download.oracle.com/docs/cd/E11081_01/doc/doc.21/e10898/ha.htm#insertedID1
    (4) Which OS will be a better option in such scenario(HP UX, SUN Solaris, Windows....) Depends on lot of things. If you use Oracle 11g, you may want to conseder Oracle VM with Oracle Unbreakable Linux/Oracle Enterprise Linux
    Hope it helps.
    Regards,
    Z.K.

  • "virtual environment software"

    Hello!
    I'm researching about "grid computing" in Oracle. I'm just start, little_knownledge about it. If you have document or nkown about it, please help me.
    Thanks for your help!

    (1) Is it practical to run production databases in virtual environment Yes
    (2) Is 11g is mature enough to be used in such environment(or 10g r2 will be better option) Yes. Infact, there are some really good features of 11g that you may want to consider. Deciding 10g or 11g, depends on the type of databases are in hand. It would be better if you'd do some testing on both environments to come to a better conclusion.
    (3) If one runs multiple databases or instances in virtual environment, how the Kernel setting of one database will effect the other one as I have heard that these virtual software’s( for example VMware) shares some common files for system resource.
    http://download.oracle.com/docs/cd/E11081_01/doc/doc.21/e10901/resources.htm#CJADCIHE
    http://download.oracle.com/docs/cd/E11081_01/doc/doc.21/e10898/ha.htm#insertedID1
    (4) Which OS will be a better option in such scenario(HP UX, SUN Solaris, Windows....) Depends on lot of things. If you use Oracle 11g, you may want to conseder Oracle VM with Oracle Unbreakable Linux/Oracle Enterprise Linux
    Hope it helps.
    Regards,
    Z.K.

  • Setting up OSX server in a virtual environment

    I am looking into setting up OSX server in a virtual environment where the hardware will not be an Apple product. Can this be acccomplished

    With the release of OS X 10.10, are there any plans to update the license agreement so that Apple's new version of the OS X Server software can be run on non-Apple-branded hardware? It seems that Apple is willing to change the license agreement between 10.4 and 10.5, so why not change it between 10.9 and 10.10, especially since the OS X client software 10.10 is available as a free download through the App Store, and the OS X Server software is available for $20 through the App Store? It also makes sense to open the software sales market to non-Apple-branded hardware users, unless Apple really is feeling skittish about the professional marketable quality of its newer model computers like the 2014 Mac Pro towards server hosting provider companies. They are using comparable Intel Xeon E5 processors, but not making any effort to market that computer to web hosting providers, and they are certainly not getting their foot in the door by withholding the potential of their OS X Server software by allowing it only to be run on Apple-branded hardware. If Apple gets their foot in the door with server software, they will be in a market for selling their OS X Server software AND their Mac Pro line of server-similar hardware FIVE-FOLD by directly competing with Microsoft's IIS, Linux software developers, AMD hardware developers, and other server hardware and software developers. Intel should be PRODDING Apple to get into the server market, and offering OS X Server for a measly $20 to non-Apple-branded hardware users would essentially STEAL their customers away from them, vastly growing the Apple domain.
    If Apple does not want us to be making OS X Server applications, however, then by all means, they should simply discontinue the OS X Server software, because with the current license restriction of only being able to use the OS X Server software on Apple-branded hardware, in tandem with Apple's complete ignorance of the server market with their hardware which is using server-quality Intel Xeon E5 processors, Apple sitting in the water like an immobile swan among the Internet Server market is just plain dumb. I mean, Apple wants to make money, don't they? Or are they just fooling around with the consumer market, pretending like OS X Server running on a Mac Mini is something that Web Hosting Providers would take a second look at? MARKET YOUR MAC PRO LINE TO WEB HOSTING PROVIDERS AND LET OS X SERVER SOFTWARE RUN ON NON-APPLE-BRANDED HARDWARE ALREADY! STOP FOOLING AROUND HERE. APPLE SHOULD BE PARTNERING UP WITH VMWARE IN THIS ENDEAVOR; THEY HAVE MADE IT DIRT....SIMPLE.... TO ENTER THE SERVER MARKET THROUGH VMWARE ESXI.
    my gosh, even a caveman can do it
    why isn't Apple doing it

  • Implementations of Oracle EBS on virtualized environment

    dear experts
    our company wants to implement Oracle EBS R12 on virtualized environment .
    is any one of you ever did such implementation or worked in such environment ??

    Some virtualization technologies are certified with EBS - pl see these MOS Docs
    Certified Oracle Solaris and SPARC Virtualization and Partitioning Technologies for Oracle E-Business Suite [ID 1234632.1]
    Using Oracle VM with Oracle E-Business Suite Release 11i or Release 12 [ID 465915.1]
    Support Position for Oracle Products Running on VMWare Virtualized Environments [ID 249212.1]
    HTH
    Srini

  • Oracle Application Server 10g on a virtual environment

    Hi,
    Can anyone provide us the Step by Step approch to install Oracle Application Server 10g on a virtual environment on solaris cluster?

    HI,
    Oracle is provided two documents for OAS install in Solaris (32bit and 64bit).
    Here I am providing both documents.
    http://docs.oracle.com/cd/B31017_01/solx86.1013/install.pdf --- Oracle app server install 32bit
    http://docs.oracle.com/cd/B31017_01/sol.1013/install.pdf -- orcle app server install 64bit
    Award points it is useful.
    Thanks,
    satya

  • XI/PI 7.0 Installation on Windows Machine (Virtualized Environment)

    Hi All
    We are planning to install XI/PI 7.0 on virtualized environment (Windows as OS) for Development and Test Environment
    Does anyone has experince installing this on Windows environment (virtualized environment) and also prons and cons, in installing it on Windows
    Please let me know your feedback as we have to finalise the OS for XI/PI 7.0 Installation
    Thanks in Advance
    Thanks with regards
    Deelip

    hai check the below links
    https://www.sdn.sap.com/irj/sdn/articles-lastyear?startindex=121
    https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/a04e59be-f51f-2a10-829b-dd3e5a359aa4
    note:award points if found helpfull
    regards
    chandrakanth.k

  • Project Server jobs going to "Waiting to be processed" state after resolving Error:1053 in virtual environment.

    Hi all,
    I am using project server 2007 in virtual environment. Before some time, my project server queue service was not starting & it gave Error: 1053. Then server team made some small changes in registry & resolved the problem. After that queue service
    was in running condition. But when any job goes into queue, it processed the job first, then after some processing, it goes into "waiting to be processed", and after some time it again starts processing. So, the project server queue is working very
    very slow. I restarted queue, event, sql, timer services, but no benefit.
    In log it is showing "Queue unable to interact with SQL.".
    Please Help....
    Thanks.
    Thanks & Regards Pradeep Gangwar

    Hi Hrishi,
    ULS log is as below:
    ===========================================================
    02/12/2013 10:19:20.99 OWSTIMER.EXE (0x0460)                  
    0x089C
    Windows SharePoint Services   Timer                        
    5uuf Monitorable
    The previous instance of the timer job 'Shared Services Provider Synchronizing Job', id '{AD482C7A-A6D5-4313-A4B6-3F5A78730F61}' for service '{54B6D7E9-6F24-459E-92AC-E11FB157B119}' is still running, so the current instance will be skipped.  Consider
    increasing the interval between jobs.
    02/12/2013 10:20:10.58 w3wp.exe (0x04C0)                      
    0x13FC
    Windows SharePoint Services   General                      
    8m90 Medium  
    105 heaps created, above warning threshold of 32. Check for excessive SPWeb or SPSite usage.
    02/12/2013 10:20:29.99 OWSTIMER.EXE (0x0460)                  
    0x089C
    Windows SharePoint Services   Timer                        
    5uuf Monitorable
    The previous instance of the timer job 'Config Refresh', id '{5BA90EA2-D960-4F00-BF99-2C9C96056FB1}' for service '{46CB2006-65AC-40C6-9B5D-E2924F18B8CD}' is still running, so the current instance will be skipped.  Consider increasing the interval
    between jobs.
    ==========================================================
    And in Event Viewer, it is showing:
    ==========================================================
    Log Name:      Application
    Source:        Office SharePoint Server
    Date:          12-02-2013 10:14:02
    Event ID:      7761
    Task Category: Project Server Queue
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      xyz
    Description:
    Standard Information:PSI Entry Point: 
    Project User: domain\epmadmin
    Correlation Id: a5e020df-ee43-417f-b47c-a1f1142fe2cf
    PWA Site URL: http://xyz/PWA
    SSP Name: SharedServices1
    PSError: Success (0)
    An unxpected exception occurred in the Project Server Queue. Queue type (Project Queue/Timesheet Queue): ProjectQ. Exception details: CompleteGroup failed.
    ===========================================================================================================================================================
    Log Name:      Application
    Source:        Office SharePoint Server
    Date:          12-02-2013 10:14:02
    Event ID:      7758
    Task Category: Project Server Queue
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      xyz
    Description:
    Standard Information:PSI Entry Point: 
    Project User: domain\epmadmin
    Correlation Id: a5e020df-ee43-417f-b47c-a1f1142fe2cf
    PWA Site URL: http://xyz/PWA
    SSP Name: SharedServices1
    PSError: Success (0)
    Queue SQL call failed. Error: System.Data.SqlClient.SqlException: Violation of PRIMARY KEY constraint 'PK_MSP_QUEUE_PROJECT_GROUP_ARCHIVE'. 
    Cannot insert duplicate key in object 'dbo.MSP_QUEUE_PROJECT_GROUP_ARCHIVE'.
    ===========================================================================================================================================================
    Log Name:      Application
    Source:        Office SharePoint Server
    Date:          12-02-2013 10:14:02
    Event ID:      7754
    Task Category: Project Server Queue
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      xyz
    Description:
    Standard Information:PSI Entry Point: 
    Project User: domain\epmadmin
    Correlation Id: a5e020df-ee43-417f-b47c-a1f1142fe2cf
    PWA Site URL: http://xyz/PWA
    SSP Name: SharedServices1
    PSError: Success (0)
    Queue unable to interact with SQL. Queue type (Project Queue, Timesheet Queue etc): 
    ProjectQ Exception: Microsoft.Office.Project.Server.BusinessLayer.Queue.QueueSqlException: CompleteGroup failed ---> 
    System.Data.SqlClient.SqlException: Violation of PRIMARY KEY constraint 'PK_MSP_QUEUE_PROJECT_GROUP_ARCHIVE'. 
    Cannot insert duplicate key in object 'dbo.MSP_QUEUE_PROJECT_GROUP_ARCHIVE'.
    ==========================================================
    Thanks & Regards Pradeep Gangwar

  • Oracle file handling in Virtual Environment

    Hi Gurus,
    We have a 9i environment, where file handling is being done till now.
    The client now got migrated to 10g, on a virtual environment.
    We are using external tables, and doing file operations (populating CSV files etc..) till now on 9i.
    I heard that the concept of files (directory paths) does not exist on the VDC(Virtual Data Center) environment.
    Can anyone clarify on this, why this can't happen, and if so what is the workaround for such cases.
    Thanks & Regards
    RK Veluvali

    I've never had such problems, but I've sure heard about them (or problems like them) a fair amount over the years.
    If you can report specific problems to Adobe here (1 problem per report), there is a chance it will do some good:
    Recently active topics in Photoshop Family about Photoshop Lightroom
    Note: one thing I realized way back is that I did not want to leave anything up to Lightroom (or chance), file-handling-wise, and so always assure my naming convention does not result in duplicate files. I NEVER want a -2 added to any of my files (ok, sometimes when testing, but otherwise: not). So anyway, to make a long story short, I recommend conventions and workflow which avoids the drama as much as possible.. - good luck (sorry I've not been more help..).
    Rob

  • Third party hosting in virtual environment

    Hi
    We have just won our first web tools implementation.
    The customer is considering using third party hosting. The third party company has asked if web tools can be hosted in a virtual environment e.g. Microsoft Virtual Server.
    Is it okay to use a virtual environment and if so are there any issues/concerns etc. with doing this?
    Any feedback greatly appreciated particularly if someone has already done this.
    Thanks
    Regards
    Lynne

    Hi Lynne,
    We typically recommend using virtual machines only for test environments.
    We have seen some issues that appear to be related to running Webtools from a virtual machine.  Specifically,  the session cache appears to be recycled very frequently and is sometimes "lost", resulting in a number of errors to the enduser.
    This may be an issue that can be addressed by throwing hardware at the problem, but, since SAP does not run QA in virtual machines, this is nothing I could vouch for.

Maybe you are looking for

  • No media in file?

    Yesterday day I've started getting a no media in file in a few points of two of my sequences. The video was brought into FCP with the Log and Transfer, it was originally shot on a Sony EX3 XDCAM unit. I've tried renaming the capture folder so that FC

  • Create dynamic internal table with deep structure;cell coloring dynamic ALV

    Hi, My requirement is to do cell colouring for a dynamic ALV. So I am creating a dynamic internal table using the following method.   CALL METHOD cl_alv_table_create=>create_dynamic_table     EXPORTING       it_fieldcatalog = i_fieldcatalog[]     IMP

  • Query Oracle database using JCheckBox getLabel()

    Hey guys. I'm not sure if this is the right place, so if it's not I greatly apologise! I just figured if it include Java code then it's appropriate. Anyway, just a query... I've got a Java application hooked up to an Oracle database. I was just wonde

  • Creating TR automatically - mutliple TRs for the same St.Bin.

    Hi Experts, Please let me know if this is possible? I'm able to create auto TR without any problem for my WM-PP interface for the pick parts. I've one issue on this.  Please help me if you can on this. My requirement is to create one TR for the same

  • Upgraded FCP to latest release & now can't output to WMV to play on PC

    Just recently upgraded my Final cut Pro to the latest release and since that upgrade when I export my project to Window's Media files they no long will play on a PC. What has changed? What settings do I have to set to make this work again. I have con