Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
VMware View Security Essentials
VMware View Security Essentials

VMware View Security Essentials: The vital elements of securing your View environment are the subject of this user-friendly guide. From a theoretical overview to practical instructions, it's the ideal tutorial for beginners and an essential reference source for the more experienced.

eBook
$23.39 $25.99
Paperback
$43.99
Subscription
Free Trial
Renews at $19.99p/m

What do you get with Print?

Product feature icon Instant access to your digital copy whilst your Print order is Shipped
Product feature icon Paperback book shipped to your preferred address
Product feature icon Redeem a companion digital copy on all Print orders
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
Modal Close icon
Payment Processing...
tick Completed

Shipping Address

Billing Address

Shipping Methods
Table of content icon View table of contents Preview book icon Preview Book

VMware View Security Essentials

Chapter 2. Securing Your Base

In this chapter we will take a good look at the base installation of View, its configuration settings, and how to secure the base of your virtual desktop deployment. We will start with a look at the base structure that View builds on—vShpere.

vSphere considerations


Before we start with the View considerations, let's step back a second and understand what basic security concepts have to be implemented on the vSphere level in order to secure the whole virtualization stack that VMware View depends on.

Using View means that you are using vSphere. Desktop virtualization centralizes the desktop infrastructure onto the core virtualization stack. Therefore if the core virtualization (vSphere) is not available, View will not be available; meaning anybody that uses a virtualized desktop will not be able to work. The cost implications are clear.

When we are talking about vSphere security, we have to understand that this encompasses a multitude of topics. As this book is focusing mainly on View, I will only touch this topic briefly.

The vSphere stack is built from a minimum of one VM/appliance, but in most cases we are talking about two to three VMs. Best practices for scaling and security dictate that vSphere uses a dedicated database server...

Capacity planning


Capacity planning is one of the most ignored topics. When businesses start virtualization, especially desktop virtualization, people believe that VMs do not cost any money or are freely available. This can lead to immense problems very quickly. As I said before, security is not only about intrusion but also about availability. If your vSphere environment is out of resources, such as CPU, memory, storage, or even network bandwidth, it poses a risk to the whole environment. Businesses that use free resources of their production environment to host virtual desktops will realize huge savings, as free capacity is used and so they save on buying full-desktop computers or dedicated hardware for virtual desktops. However, it also poses the following risk. If not configured correctly, the capacity drain of all the virtual desktops can impact the production servers. Another aspect is to realize how fast virtual desktop environments can grow. It happens quite a lot that Proof-of-Concept...

Basic View hardening


We now will talk about the steps to harden the View environment.

vSphere hardening

Hardening your vSphere installation is a rather important point; however, it is going beyond the focus of this book. Please have a look at the following official VMware vSphere 5.1 Hardening Guide:

http://communities.vmware.com/docs/DOC-22981

Operating system (OS) hardening

I will just quickly mention that one cannot harden View properly without first hardening the Windows operating system that View resides on. As we want to focus on View hardening, I will just point out the typical OS hardening points as follows:

  • Windows Updates

  • Password policies

  • Antivirus

We will discuss, in the next chapter, Windows Firewall settings. However, Windows hardening that is already in place is mostly sufficient for View.

User accounts

To install and operate View you could use just one user account, the domain-Admin account. However, this would enable an attacker to gain control of the whole system or an unintentional...

Logging


Logging works in the following way.

The Event Database

The Event Database (DB) stores all events that occur with a View Connection Server in a SQL DB. This sounds rather weak but actually can be extremely useful. The events stored in the DB can be read out with a business analyzing software such as Crystal Reports, IBM Cognos, and others, which enable the correlation between View and business events. This automatically provides a tool to find out what business event has the View desktop and user triggered. The power this gives for investigation should be clear. Also, it lets you understand who logged on when and where.

We now will configure the Event DB:

  1. Create a new Microsoft SQL or Oracle database (refer to VMware View Installation Guide for more details).

  2. Log in to the View Administration Console.

  3. Navigate to View Configuration | Event Configuration. The following screenshot shows VMware View Administrator:

  4. Click on Edit.

  5. In the following menu you now can attach a SQL Database or Oracle...

SSL certificates


All vSphere components and for that matter all View components communicate via a secure connection using SSL certificates. The following diagram shows all the API (HTTPS SSL secured) connections between the different layers:

All VMware products automatically create certificates during installation. However, when using certificates that have been issued from a Certificate Authority (CA), you make sure that no man-in-the-middle attack can occur. For this, we have to exchange the VMware self-signed SSL certificates that VMware uses by default with CA signed certificates.

Certificates improve not only the security for inter-server communication, but especially the client-server connectivity.

In this section we will see how we can import SSL certificates. If you don't have any trusted certificate, I will quickly show you how you get an Active Directory (AD) CA signed certificate.

Creating a Certificate Authority (CA) and obtaining a certificate

If you do not have a valid signed certificate...

Creating a redundant View Connection Server


We already discussed the challenge of a Virtual desktop environment, one of which is that the every desktop user is now utilizing the View Connection Server. In order to load balance, and more importantly, provide failover capability, we now will install a second copy of the View Connection Server. This chapter assumes that you already have an existing installation of a View Connection Server (Standard).

Usage of a replica server

There are several ways that a replica View Connection Server can be used. The first and the most straightforward method is to use it to serve specialized desktop pools. The replica and the standard View Connection Server have different IPs, but will share the same ADAM base as well as the same basic configuration. Publishing two different IPs to two different kinds of personnel will automatically lead to "hardcoded" load balancing; meaning that one specific group of people will only ever use one View Connection Server to...

Summary


You should now understand more about the base services of View as we have looked at the vSphere aspects of clustering and talked about logs and SSL certificates. We have also discussed creating View replica servers and load balancing them to create a stable and redundant setup.

In the next chapter, we look at connections between the base and the client. We will discuss the desktop connections with the different View desktop protocols we can use, as well as taking a look at the View Security Server and the View Transfer Server.

Left arrow icon Right arrow icon

Key benefits

  • Discover how to correctly implement View connection, security, and transfer servers
  • Understand all the firewall rules and the basics of multi-layered security
  • Secure all your connections between client and desktop

Description

Most people associate security with network security and focus on firewalls and network monitoring. However, there is more to security than that. Security starts with the establishment of a stable environment, protecting this environment not only from intrusion, but also from malicious intent. It is about tracking the issue and recovering from it. These elements of security are what this book aims to address. VMware View Security Essentials addresses the topic of security in the corporate environment in a new way. It starts with the underlying virtual infrastructure and then delves into securing your base, your connection, and your client. This is not only a “how-to” book, but is also a book that explains the background and the insights of View security for the experienced professional's desktop virtualization. This book takes you through the four major View security areas. Each area deals with all the aspects of security and explains the background as well as laying out simple-to-follow recipes to implement a higher security standard. We start at the Virtualization base and work our way through the various View server types. We will then dive into the problems and issues of securing a connection before we address the security of the desktop itself. We conclude with a look into the backing up of our View installation and preparing for disaster recovery.

Who is this book for?

This book is a “how-to” for the novice, a “reference guide” for the advanced user, and a “go to" for the experienced user in all the aspects of VMware View desktop virtualization security.

What you will learn

  • Create, use, and install SSL certificates
  • Acquire a new skill set in troubleshooting security issues
  • Learn about secure tunnelling your desktop connection with RDP and PCoIP
  • Understand the concepts of pairing View security and transfer severs with View connection servers
  • Understand the key aspects of blocking undesirable USB devices
Estimated delivery fee Deliver to United States

Economy delivery 10 - 13 business days

Free $6.95

Premium delivery 6 - 9 business days

$21.95
(Includes tracking information)

Product Details

Country selected
Publication date, Length, Edition, Language, ISBN-13
Publication date : Jul 26, 2013
Length: 130 pages
Edition : 1st
Language : English
ISBN-13 : 9781782170082
Vendor :
VMware
Category :

What do you get with Print?

Product feature icon Instant access to your digital copy whilst your Print order is Shipped
Product feature icon Paperback book shipped to your preferred address
Product feature icon Redeem a companion digital copy on all Print orders
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
Modal Close icon
Payment Processing...
tick Completed

Shipping Address

Billing Address

Shipping Methods
Estimated delivery fee Deliver to United States

Economy delivery 10 - 13 business days

Free $6.95

Premium delivery 6 - 9 business days

$21.95
(Includes tracking information)

Product Details

Publication date : Jul 26, 2013
Length: 130 pages
Edition : 1st
Language : English
ISBN-13 : 9781782170082
Vendor :
VMware
Category :

Packt Subscriptions

See our plans and pricing
Modal Close icon
$19.99 billed monthly
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Simple pricing, no contract
$199.99 billed annually
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just $5 each
Feature tick icon Exclusive print discounts
$279.99 billed in 18 months
Feature tick icon Unlimited access to Packt's library of 7,000+ practical books and videos
Feature tick icon Constantly refreshed with 50+ new titles a month
Feature tick icon Exclusive Early access to books as they're written
Feature tick icon Solve problems while you work with advanced search and reference features
Feature tick icon Offline reading on the mobile app
Feature tick icon Choose a DRM-free eBook or Video every month to keep
Feature tick icon PLUS own as many other DRM-free eBooks or Videos as you like for just $5 each
Feature tick icon Exclusive print discounts

Frequently bought together


Stars icon
Total $ 159.97
vSphere High Performance Cookbook
$60.99
VMware View Security Essentials
$43.99
Implementing VMware Horizon View 5.2
$54.99
Total $ 159.97 Stars icon

Table of Contents

5 Chapters
Introduction to View Chevron down icon Chevron up icon
Securing Your Base Chevron down icon Chevron up icon
Securing the Connection Chevron down icon Chevron up icon
Securing the Client Chevron down icon Chevron up icon
Backup and Recovery Chevron down icon Chevron up icon

Customer reviews

Rating distribution
Full star icon Full star icon Full star icon Full star icon Half star icon 4.5
(2 Ratings)
5 star 50%
4 star 50%
3 star 0%
2 star 0%
1 star 0%
They call me... "The Hamster". Dec 14, 2013
Full star icon Full star icon Full star icon Full star icon Full star icon 5
The author does an excellent job of explaining and guiding the reader through an end to end secure implementation of a Virtual Desktop Infrastructure with VMware View in this book. Not only are all aspects of the underlying infrastructure requirements and considerations discussed, but the detail in how to implement the solution adhering to best practices and addressing security concerns is extremely valuable while simultaneously easy to comprehend.This is a thorough discussion of the areas of concern one needs to take into consideration prior to the implementation of VDI leveraging VMware View, while not seeming as if it is a task to read in order to absorb the material and concepts. Additionally it is a wonderful resource for not only those that are new to VDI, but also those who have been working with these solutions for some time to use as a reference when working with View to ensure that they are adhering to best practices.
Amazon Verified review Amazon
Jeff Jones Jan 04, 2014
Full star icon Full star icon Full star icon Full star icon Empty star icon 4
I volunteered to review this book as I was intrigued by the potential of one based on View and the security options of a VDI infrastructure. I have been working with View and the Horizon Suite from VMware for the last eight months or so and am familiar with the various security options. What I hoped to find interesting was the real world implementation of View security beyond the basic Best Practices that are readily available.Who would benefit from this book?Anyone considering View for their VDI project or anyone in charge of designing the environment may benefit from reading this start to finish. If you have no experience, it’s a pretty good manual for setup and network connections between the View objects. Obviously, the basic security setups are covered also. I have built four environments (three labs and one production) using View 5.2 and 5.3 and I got some good tips, but it’s not a cover-cover read for anyone with some experience. It’s not a bad reference tool though.What’s in the book?This is a good round-up of most of the documentation you would end up reading in bits if you were just starting out. It covers basic design, setup and security. There are screenshots to complement the test instructions which are helpful if you’re new to the product. If you’re looking for something more comprehensive, like total environment design and security, this isn’t it. The book doesn’t lie though; it’s explicit on what it’s going to tell you, and gives you some web links on reading about what it isn’t.There is a basic design based on a mid-size office included but it’s limited to Connection and Security server connections and a couple desktop pool options.This will help if you’re considering a DMZ or multiple DMZ’s for your Security servers. The book does explain why the DMZ is important and how to harden the connection between the LAN and DMZ. More aggressive security concepts are explored, like a DMZ between the LAN and your View network. These parts of the book were standout. There is also a good section on the load balancing variations that can be built using vCNS, vShield and third party hardware.The security continues to get better near the end when he covers ADM templates. However, like the rest of the book, the options are covered in great detail, but no reasons on why or why not to implement some of them. I was looking for more of an experience based security design book and “from the trenches” anecdotes on what security options work better in certain situations.Backup options are also covered, but this is basic stuff. VMware has never claimed to be backup software, and third party tools are absolutely imperative in backing up View and vSphere. Still, what needs to be backed up and why is covered and that’s always a good reminder.Recommendation: This is a good complement to your VMware book collection as a reference for View environments if you’re an experienced architect or administrator. It’s worth more attention if you need to prepare for your first View build. Keep in mind that this book is based on View 5.2 even though it isn’t mentioned in the title
Amazon Verified review Amazon
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

What is the digital copy I get with my Print order? Chevron down icon Chevron up icon

When you buy any Print edition of our Books, you can redeem (for free) the eBook edition of the Print Book you’ve purchased. This gives you instant access to your book when you make an order via PDF, EPUB or our online Reader experience.

What is the delivery time and cost of print book? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela
What is custom duty/charge? Chevron down icon Chevron up icon

Customs duty are charges levied on goods when they cross international borders. It is a tax that is imposed on imported goods. These duties are charged by special authorities and bodies created by local governments and are meant to protect local industries, economies, and businesses.

Do I have to pay customs charges for the print book order? Chevron down icon Chevron up icon

The orders shipped to the countries that are listed under EU27 will not bear custom charges. They are paid by Packt as part of the order.

List of EU27 countries: www.gov.uk/eu-eea:

A custom duty or localized taxes may be applicable on the shipment and would be charged by the recipient country outside of the EU27 which should be paid by the customer and these duties are not included in the shipping charges been charged on the order.

How do I know my custom duty charges? Chevron down icon Chevron up icon

The amount of duty payable varies greatly depending on the imported goods, the country of origin and several other factors like the total invoice amount or dimensions like weight, and other such criteria applicable in your country.

For example:

  • If you live in Mexico, and the declared value of your ordered items is over $ 50, for you to receive a package, you will have to pay additional import tax of 19% which will be $ 9.50 to the courier service.
  • Whereas if you live in Turkey, and the declared value of your ordered items is over € 22, for you to receive a package, you will have to pay additional import tax of 18% which will be € 3.96 to the courier service.
How can I cancel my order? Chevron down icon Chevron up icon

Cancellation Policy for Published Printed Books:

You can cancel any order within 1 hour of placing the order. Simply contact customercare@packt.com with your order details or payment transaction id. If your order has already started the shipment process, we will do our best to stop it. However, if it is already on the way to you then when you receive it, you can contact us at customercare@packt.com using the returns and refund process.

Please understand that Packt Publishing cannot provide refunds or cancel any order except for the cases described in our Return Policy (i.e. Packt Publishing agrees to replace your printed book because it arrives damaged or material defect in book), Packt Publishing will not accept returns.

What is your returns and refunds policy? Chevron down icon Chevron up icon

Return Policy:

We want you to be happy with your purchase from Packtpub.com. We will not hassle you with returning print books to us. If the print book you receive from us is incorrect, damaged, doesn't work or is unacceptably late, please contact Customer Relations Team on customercare@packt.com with the order number and issue details as explained below:

  1. If you ordered (eBook, Video or Print Book) incorrectly or accidentally, please contact Customer Relations Team on customercare@packt.com within one hour of placing the order and we will replace/refund you the item cost.
  2. Sadly, if your eBook or Video file is faulty or a fault occurs during the eBook or Video being made available to you, i.e. during download then you should contact Customer Relations Team within 14 days of purchase on customercare@packt.com who will be able to resolve this issue for you.
  3. You will have a choice of replacement or refund of the problem items.(damaged, defective or incorrect)
  4. Once Customer Care Team confirms that you will be refunded, you should receive the refund within 10 to 12 working days.
  5. If you are only requesting a refund of one book from a multiple order, then we will refund you the appropriate single item.
  6. Where the items were shipped under a free shipping offer, there will be no shipping costs to refund.

On the off chance your printed book arrives damaged, with book material defect, contact our Customer Relation Team on customercare@packt.com within 14 days of receipt of the book with appropriate evidence of damage and we will work with you to secure a replacement copy, if necessary. Please note that each printed book you order from us is individually made by Packt's professional book-printing partner which is on a print-on-demand basis.

What tax is charged? Chevron down icon Chevron up icon

Currently, no tax is charged on the purchase of any print book (subject to change based on the laws and regulations). A localized VAT fee is charged only to our European and UK customers on eBooks, Video and subscriptions that they buy. GST is charged to Indian customers for eBooks and video purchases.

What payment methods can I use? Chevron down icon Chevron up icon

You can pay with the following card types:

  1. Visa Debit
  2. Visa Credit
  3. MasterCard
  4. PayPal
What is the delivery time and cost of print books? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela
Modal Close icon
Modal Close icon