Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Options seen lacking in firewall virtual server protection

Gartner report says partitioning virtual servers is needed and requires guarantees
By Tim Greene , Network World , 01/08/2008
  • Share/Email
  • Comment
  • Print

Options are scarce for protecting applications when they are deployed on virtual servers within the same physical machine, according to a recent Gartner report.

Network firewalls located external to physical servers that support multiple virtual servers cannot filter traffic between virtual servers, according to the report “Limited Choices Are Available for Network Firewalls in Virtualized Servers.” This means  applications on the virtual servers can communicate undetected with other virtual servers, perhaps in violation of security policies.

This is because virtual machines can talk to each other directly within the same hardware platform, giving external firewalls and intrusion-prevention systems (IPS) no chance to inspect or even monitor the traffic.

It is possible for communications among virtual servers to be routed out of the physical box to an external firewall, but that is inefficient, Gartner says. Firewalls that can separate these virtual servers are clearly needed, "however, few vendors offer full-featured solutions," the resport says.

Some firewalls from vendors including Astaro, Blue Lane, Catbird, Enterasys and Reflex Security address some of these problems, while others including Stonesoft and StillSecure have plans to address them, Gartner says.

Two of the major firewall vendors, Cisco and Juniper, have shifted their products to hardware-based firewalls and therefore  lack the software firewalls that might fit into virtual environments, says Greg Young, a Gartner analyst who helped write the report.

With physical servers, businesses had set up Web applications in isolated network segments -- demilitarized zones -- separated by firewalls from databases. In a virtual environment, that separation can become blurred, Young says.

It is possible to place firewalls on each virtual machine, but that saps processing power that virtual machines are designed to conserve, the report says.

The solution is setting up firewalls on virtual machines within physical servers so these firewalls can monitor and filter traffic among the other virtual machines, Young says. Vendors need to certify that these software-based firewalls work in virtual environments so customers can install them with some confidence that they will be reliable, he says.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.