Communication Protection
vGate puts all communication throughout the virtual environment under control.
Outside the perimeter
vGate proxies all communications between administrators and the virtual infrastructure, ensuring that:
- All administrator and user activities are authorized.
- All management traffic is locked within the secured subnet.
- Network traffic between authorized personnel and infrastructure elements is signed, eliminating the possibility of “man-in-the-middle” attacks.
Inside the perimeter
vGate controls all network interfaces and communications between:
- ESX servers and other infrastructure elements (management tools, backup servers, etc.)
- ESX servers and storage servers (powered by iSCSI and FiberChannel technologies) that host virtual machines’ files. Access rules can be configured granularly on a particular LUN level according to the company’s restricted data types.
- Alternative VM-to-VM communication channels that allow virtual machines on the same host communicate one with another without using the network layer.
The product also ensures that ESX replication network runs in encrypted mode.