欢迎来到天天文库
浏览记录
ID:37815993
大小:596.46 KB
页数:20页
时间:2019-05-31
《VMware view best practice》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、SecurityServer部署最佳实践廖天云GCHDesktopTeam©2011VMwareInc.Allrightsreserved议程1.LAN中View的部署2.为何要将SecurityServer部署在DMZ区3.SecurityServer防火墙策略设定4.SecurityServer安装与配置5.SecurityServer部署常见的问题6.讨论10-2©2011VMwareInc.Allrightsreserved常见无SecurityServer部署场景VMwarevCenter™ViewServersystemsAdministrato
2、rthinclientvirtualdesktopswithViewAgentsViewClientwithViewVMware®LocalModeConnectionESX™/ESXihostsServer安装PCoIP组件ADdomaincontrollersViewClient10-3©2011VMwareInc.Allrightsreserved为什么不直接将ViewConnectionServer放置在DMZ安全的因素:ViewConnectionServer直接被暴露在外网ViewConnectionServer必须是域中的成员服务器.一旦
3、受到攻击是必影响AD中的用户、组、以及其它数据的安全ViewManagerConsole暴露在外网中Standard和replicaViewConnection只能支持一块活动网卡10-4©2011VMwareInc.AllrightsreservedSecurityServer的价值可以与ViewConnectionServer网络分开,并且担负着ViewConnectionServer连接的功能.同时支持两外网络连接:•对企业内网连接•对外网络连接Viewsecurityserver可以不用加入域.多台securityservers可以同时指向
4、同一台connectionserver.ViewsecurityViewConnectionserverServer10-5©2011VMwareInc.AllrightsreservedDMZ网络配置DMZInternalvCenterServersystemsViewsecurityserversViewConnectionServersvirtualdesktopsLoadwithViewbalancerAgentsESX/ESXihostsADdomaincontrollers10-6©2011VMwareInc.Allrightsreserved端
5、口通讯DMZInternalvCenterServerTCP4001TCP80systemsTCP8009TCP443TCP/UDP4172TCP443TCP4172TCP3389UDP4172ViewConnectionvirtualdesktopsViewsecurityServerwithViewserverAgentsTCP4001ESX/ESXihostsTCP389ADdomaincontrollers10-7©2011VMwareInc.Allrightsreserved详细的通讯JMSfirewallfirewallViewClientVie
6、wConnectionServer4001ADAMADLDP389SecurityserverViewbroker&adminServerAD8009389ViewClient443Viewmessaging-JMSRDPViewsecure4001ESXihostGWserver&PCoIPViewRDPViewsecureGWViewsecureManager4001clientClient4172GWserverLDAPPCoIP&PCoIPsecureGWViewAgent3389-RDP4172-PCoIPPorts:389=LDAPTerms:4
7、43=HTTPSAJP–ApacheJServeProtocol3389=RDPJMS–JavaMessageService4001=JMSLDAP–LightweightDirectoryAccessProtocol4172=PCoIPRDP–RemoteDesktopProtocol8009=AJP13HTTPS–HypertextTransferProtocoloverSSL10-8©2011VMwareInc.Allrightsreserved防火墙规则对外,前端防火墙策略SourceProtocolPortDestinationNotesAnyTC
8、P443(or80)Securityserver44
此文档下载收益归作者所有