Cisco Blogs


Cisco Blog > Data Center and Cloud

UNS Spotlight on VM-ready Security Solutions with VSG

May 19, 2011 at 4:12 pm PST

The Unified Network Services (UNS) portfolio of Layer 4-7 services (such as ACE and WAAS) also includes Cisco’s data center security solutions. A critical part of that security portfolio is our virtualization-aware firewall solution, Virtual Security Gateway (VSG). In a series of upcoming blog posts, I’ll be sharing a few use case scenarios that our customers are implementing with VSG.

For those of you new to VSG, I’ll point out that VSG’s role is to act as a virtual firewall between zones of virtual machines. Isolating traffic between VM zones has been very challenging prior to VSG because: 1) security policies have to be enforced between VMs running on the same server or same virtual switch (where there’s no place to put a firewall), 2) VMs move all around the network and the security policies (as enforced in the firewall) must follow the VM, and 3) the need to maintain segregation of duties for compliance purposes between the security and application server teams, where security is potentially enforced inside the virtual server.

Read More »

Tags: , , , , , , , , , , , ,

Virtual Desktops are Special….

I, just like my colleague Tony Paikeday, am somewhat preoccupied these days with the fast changing world of the desktop and its impact on data center infrastructures. I wanted to pick up on Tony’s desktop virtualization “just another workload” blog back in November because it is a subject of growing discussion, especially with “cloud” being all the buzz. While desktops are an increasingly popular workload to get started with private cloud initiatives, does that mean that data center architects are mixing desktops with more traditional data center workloads?

Talking to our system engineers who are helping plan and design desktop virtualization deployments day in day out…..the more I learn there are very good reasons for treating this workload as special and separate.

The first thing I hear about is sizing of the desktop workload. A “desktop” is not a “desktop”. You can’t just characterize a generic Win 7 desktop for compute, memory, I/O and storage IOPS. You need to be able to customize the infrastructure profile to the specific user type being deployed. Therein lays the danger of mixing these virtual desktops with production workloads, where desktops could end up capturing valuable resources of mission critical services.  For example consolidating a company procurement application on the same compute pool as your desktop workloads could result in a lot of unproductive – or even worse –unhappy employees.

Read More »

Tags: , , , , , , , , ,

Are You Going to EMC World? Some great VXI content awaits…

My $0.02: Skip the buffet, Celine, Cirque, and the slots, but don’t skip learning about Cisco Virtualization Experience Infrastructure (VXI) with EMC. Read More »

Tags: , , , , , , , , , , ,