<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS in a Virtualized Environment (vmware) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705787#M64864</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can anyone elaborate on an IDS solution for a virtualized environment? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I have blade servers running ESX/ESXi - heavily virtualized environment. Im using blade switches as chassis I/O - no pass throughs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;The requirement is to run an IDS service such that VM-to-VM traffic is monitored. The traffic flow can be between two VMs on the same blade, 2 VMs on two separate blades in the same chassis, or two VMs on two separate chasses...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;In that case, I see 3 traffic flows off the bat...&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;same blade:&lt;/STRONG&gt; vm-to-vm traffic is switched by a hypervisor switch (1000v or vmware vDS).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;different blades in same chassis:&lt;/STRONG&gt; vm-to-vm traffic will leave blade and be switched by chassis hardware switch (chassis I/O blade).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;different chassis:&lt;/STRONG&gt; vm-to-vm traffic will have to go to ToR (maybe even end-of-row).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;NOTE: if VMs are on different VLANs, traffic will always go to end-of-row/agg switches (the L3/L2 boundary). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;So given all those possible flows, what is the best way to go about deploying an IDS service? Placement? Virtual or physical? etc....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:24:05 GMT</pubDate>
    <dc:creator>lamav</dc:creator>
    <dc:date>2019-03-10T12:24:05Z</dc:date>
    <item>
      <title>IDS in a Virtualized Environment (vmware)</title>
      <link>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705787#M64864</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Can anyone elaborate on an IDS solution for a virtualized environment? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;I have blade servers running ESX/ESXi - heavily virtualized environment. Im using blade switches as chassis I/O - no pass throughs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;The requirement is to run an IDS service such that VM-to-VM traffic is monitored. The traffic flow can be between two VMs on the same blade, 2 VMs on two separate blades in the same chassis, or two VMs on two separate chasses...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;In that case, I see 3 traffic flows off the bat...&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;same blade:&lt;/STRONG&gt; vm-to-vm traffic is switched by a hypervisor switch (1000v or vmware vDS).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;different blades in same chassis:&lt;/STRONG&gt; vm-to-vm traffic will leave blade and be switched by chassis hardware switch (chassis I/O blade).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;different chassis:&lt;/STRONG&gt; vm-to-vm traffic will have to go to ToR (maybe even end-of-row).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;NOTE: if VMs are on different VLANs, traffic will always go to end-of-row/agg switches (the L3/L2 boundary). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;So given all those possible flows, what is the best way to go about deploying an IDS service? Placement? Virtual or physical? etc....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705787#M64864</guid>
      <dc:creator>lamav</dc:creator>
      <dc:date>2019-03-10T12:24:05Z</dc:date>
    </item>
    <item>
      <title>IDS in a Virtualized Environment (vmware)</title>
      <link>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705788#M64865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving it to Security community for them to have a look&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pulkit Nagpal &lt;/P&gt;&lt;P&gt;Technical Support Community Manager - Routing and Switching&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 07:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705788#M64865</guid>
      <dc:creator>Pulkit Nagpal</dc:creator>
      <dc:date>2011-07-19T07:06:17Z</dc:date>
    </item>
    <item>
      <title>IDS in a Virtualized Environment (vmware)</title>
      <link>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705789#M64868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This topic was disccussed in this thread from last week:&lt;/P&gt;&lt;P&gt;(too bad we can't merge threads)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2092838"&gt;https://supportforums.cisco.com/thread/2092838?tstart=30&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 15:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-in-a-virtualized-environment-vmware/m-p/1705789#M64868</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-07-19T15:45:00Z</dc:date>
    </item>
  </channel>
</rss>

