Sign-up to receive a free Intro to Virtualization training course.
VMware vSphere Security Design Training
Industry Recognized Training: 2010, 2009 Editor's Best and Community Choice Award from Windows IT Pro

VMware vSphere Security Design Training

This course will teach you the skills needed to properly secure a vSphere environment, beyond basic implementation, configuration and administration. This course covers Section 7 – Secure a vSphere Environment of the VCAP – DCA exam.

This Course Includes All of the Following:

  • Instant Online Access to Your TrainingInstant Online Access Begin Streaming Your Training Immediately
  • Physical Media Shipped Directly to Your DoorstepPhysical Media Shipped Directly to Your Doorstep For Free, Worldwide

Certified Instruction:

  • Certified Instructor Jason Nash Jason NashVCP4, CISSP, RHCE, CCNP, VCDX #49
  • Certified Instructor Lane Leverett Lane LeverettVCDX 3 and 4 (VCDX #53), VCAP4-DCD, VCA4-DT , VCP4-DT, VCP3 and 4, MCSE NT4/2000/2003, CCNA, DCUCD, DCUCI
  • Certified Instructor David Davis David Davis VCP4, VCAP-DCA, vExpert, CCIE #9369
  • $397
  • Paying with Purchase Order?
  • View Outline
  • TrainSignal Exclusive 90 Day Total Experience Guarantee

    Our Total Experience Guarantee is Very Simple

    If you are not satisfied with our training, our service, or our support FOR ANY REASON, return your course within 90 days for a FULL REFUND (up to $397). You have my word.

    Scott Skinger Founder & President of TrainSignal, Inc.

Overview

  • Train Anywhere You Want Mobile On-Demand Training Train Where You Want, When You Want
  • Additional Training Formats Additional Training Formats High Resolution Video, MP3 Audio and PDF of Instructor Notes
  • Watch a Demo

This course will teach you the skills needed to properly secure a vSphere environment including

  • Information security and risk management concepts
  • How virtualization affects security
  • Guidelines and best practices for securing a virtual environment
  • Securing the virtual machines
  • Configuration and change management
  • Top VMware and third-party tools for securing vSphere – Top Security Tools

Professional Training

  • Nearly 12 Hours (11 Hours, 39 Minutes, 46 Seconds) of VMware vSphere Security Design Training Videos Jam Packed on 2 DVDs!
  • Multiple File Formats Make it convenient for you to learn anywhere you go! iPod Video, Mp3 Audio, .WMV & high quality .AVI video
  • PDF of Instructor Notes allow you to follow along with the videos and take more organized notes
  • Instant Access Online to the entire training course

Course Outline

Section 1: Course Introduction

Lesson 1 - Getting Started with VMware vSphere Security Design Training

In this lesson learn what makes vSphere security such an important topic for you and your company. You’ll find out what the course will cover as well as the basics of building a vSphere lab that you could use to practice the configurations you’ll learn in the course.

  • Why vSphere Security is Critical Knowledge
  • What You Will Learn in This Course
  • Lab Setup
Lesson 2 - About Your Instructors

Find out who Jason Nash and Lane Leverett are, their qualifications, and why they make such excellent vSphere security instructors.

  • About Jason Nash
  • About Lane Leverett
Lesson 3 - Introduction to Information Security Concepts

This lesson provides a fundamental base of understanding for system and information security, specifically as it relates to virtualization security.

  • The Many Layers of Security in a Virtual Environment
  • The Fundamentals: A Security Primer
  • AAA: Authentication, Authorization, and Accounting
  • Standard Terminology
  • CIA: Confidentiality, Integrity, and Availability
  • The Different Shapes and Sizes of Potential Attackers
  • The Steps of an Attempted Attack
  • The Process for Developing and Maintaining Good Security
  • Security Tools

Section 2: Information Security Concepts

Lesson 4 - Security Priorities in a Virtual Environment

Explore how security is different a virtual environment, dispel common virtualization security concerns, find out the impact of security in a virtual infrastructure, and learn what VMware is doing about security.

  • Is Virtualization Secure?
  • Is The Hypervisor a Security Weakness?
  • Encapsulation
  • Common Worries About virtualization Security
  • Types of Security Threats
  • Impact of Virtualization of Security
  • What is VMware Doing About Security?
  • Regular Tasks a Good Admin Should Perform
Lesson 5 - Security Technologies

In this lesson you will learn technologies, features, and options for securing your vSphere environment. You will also learn how to control who has access to your virtual infrastructure as well as how to keep maintain that level of security for the long term.

  • What do I Need to Protect What?
  • Pairing Assets to Security Technology
  • vSphere Authentication
  • Who Has Access to Your Environment?
  • Creating Local VSphere Users
  • VSphere Host Authentication
  • Integration with active Directory
  • The VI Firewall
  • Integrating Security in with the Hypervisor by Using VMsafe
  • Using vShield to Secure Application and Guests
  • Keeping Hosts and Guests Updated with Update Manager

Section 3: Security in Virtual Networks

Lesson 6 - vNetwork Security Architecture

This lesson will give you an overview of how security impacts the selection, deployment, and management of the vNetwork. Instructor Jason Nash also details recommendations and common mistakes seen in production environments.

  • Deployment Types for Different Trust Zones
  • Partially Collapsed with Separate Physical Trust Zones
  • Partially Collapsed with Separate Virtual Trust Zones
  • Fully Collapsed Trust Zones
  • Top 10 Common Mistakes and Recommendations
  • Security Considerations with the Standard vSphere vSwitch
  • Security Considerations with the vSphere vdSwitch
  • Layering Additional Functionally with the Cisco Nexus 1000v
  • Protecting Your Management Communications
  • Isolating Management
Lesson 7 - Securing vNetwork Configuration

Learn about implementing vNetwork security with features like VLANs, PVLANs, and trust zones. Also, you will get an introduction to using the Cisco Nexus 1000v Distributed Switch.

  • Security Considerations in Your vNetwork Design
  • Configuring the vNetwork for Different Trust Zones
  • Implementing VLANs and Network Separation
  • Using and Configuring Private VLANs (PVLANS)
  • vSwitch Security Configuration
  • Using and Configuring the vSphere dvSwitch
  • Overview of the Cisco Nexus 1000v Distributed Switch
  • Deployment and Configuration of the Cisco Nexus 1000v Distributed Switch
  • Configure Physical and VM Port-Groups

Section 4: Protecting vCenter

Lesson 8 - Working with SSL Certificates

This lesson discusses how to use SSL Certificates, whether from a certificate authority or self signed, to secure vCenter communications.

  • An Overview on How SSL Works and Why We Use It
  • How VMware Uses SSL
  • Example of an SSL Negotiation
  • Let’s Talk About Digital Certificates
  • Getting Reid of That Annoying SSL Warning when I Log in to vCenter!
  • Using Internal Versus Generating “Real” Certificates
  • Protect Your Certificates!
  • Installing Your Own Certificates
  • About the Digital Certificate Files
  • How to Replace Existing SSL Certificates
Lesson 9 - Hardening the vCenter Server System

Appling security’s triple A (Authentication, Authorization, and Accounting) to harden the underlying operating system, vCenter, and the vSphere Client. Finally, find out how to monitor vCenter logs to know that the infrastructure is secure.

  • Authentication, Authorization, and Accounting with vCenter
  • Best Practices for Deploying and Protecting vCenter
  • Hardening the Underlying Operating System
  • Don’t forget the vSphere Client!
  • Monitoring the vCenter Logs

Section 5: Protecting ESX/ESXi Host Systems

Lesson 10 - ESX and ESXi Security Architecture

In this lesson you will learn the difference between ESX Classic and ESXi Server when it comes to security. You will also learn about security at each layer of ESX/ESXi as well as how to secure the ESX service console.

  • Why is ESXi More Secure Than ESX Classic – or is It?
  • The Virtualization Layer, Virtual Network Layer, and Virtual Machine Layer
  • What is the Service Console/Management Interface and Why Does It Need to Be Secured?
Lesson 12 - Hardening ESX and ESXi Host Systems

Based on the vSphere security hardening guide, this lesson shows you, step by step, how to take a base ESX/ESXi installation and give it heavy-duty security.

  • ESX Hardening – User and Group Configuration
  • Sudo
  • Customize SSH
  • Secure ESX Web Proxy
  • Configuring Password Policies
  • Configure the ESX Firewall
  • ESXi Hardening – Enabling ESXi Lockdown Mode
  • Tech Support and Remote Tech Support Configuration
  • Common Hardening – Isolate the ESX/ESXi and vCenter Management Networks
  • Enabling Certificate Checking in vCenter
  • Configuring CA Signed Certificates
  • Configure SSL Timeouts
Lesson 11 - Controlling Access to Storage

This lesson discusses what security controls are available for each of the storage protocols.

  • Common Security for All Protocols
  • Fiber Channel: Zoning and LUN Masking
  • iSCSI: CHAP and LUN Masking
  • NFS (Network File System)

Section 6: Hardening Virtual Machines

Lesson 13 - Virtual Machine Security Architecture

Find out the enhancements to security that virtualization brings, the challenges that virtualization introduces, and the common OS hardening needed for virtual machines.

  • Virtual Machine Isolation
  • Virtualization Security Enablers
  • Virtualization Security Challenges
  • Operating System Security Best Practices
Lesson 14 - Hardening Virtual Machines - Best Practices

Learn how to apply real-world proven virtual machine security practices in your infrastructure, step by step!

  • Use a Firewall or Access Control Lists
  • Use an Antivirus Solution
  • Use VMware Update Manager
  • Limit Who Has Console Access
  • Do Not Use the VMCI if Possible
  • Isolate VMotion and/or FT Networks
  • Use vCenter Roles
  • Use Virtual Machine Log Rotation
  • Turn off or Disable Unneeded Services
  • Turn on Auditing and/or Logging

Section 7: Standardizing ESX/ESXi Host Configurations

Lesson 15 - Using Host Profiles to Standardize ESX/ESXi Configuration

In this lesson you will learn how to use vSphere’s host profiles as a template to insure that new and existing ESX/ESXi hosts comply with security policies and best practices.

  • How Host Profiles Help Secure ESX/ESXi
  • What is Supported with Host Profiles
  • What is Not Supported with Host Profiles
  • Create, Apply, and Check Compliance with a Host Profile
Lesson 16 - Keeping Hosts and VMs Secure with Update Manager

VMware’s Update Manager (VUM) is a powerful vSphere security enabler that you can use to keep both hosts and virtual machines up to date with security patches. Find out how to do it, step by step.

  • Using VMware Update Manager (VUM) to Help Secure ESX/ESXi and VMs
  • Deployment Options for Update Manager

Section 8: vSphere Logging and Event Monitoring

Lesson 17 - Understanding and Managing vSphere Logs

A critical piece of any security monitoring is the proper monitoring and alerting of security events. Find out how to monitor vSphere security logs, how to retain those logs, and how to use vCenter alarms to make sure you know when security events occur.

  • Monitoring Log Files for Security
  • Where vSphere Stores Local Log Files
  • Using Syslog for Logging Repository
  • How to Monitor and Retain Log Files for Auditing Purposes
  • Using vCenter Alarms for Security Monitoring

Section 9: Getting Started with Top vSphere Security Tools

Lesson 18 - vShield: Zones, App, and Edge

VMware’s vShield is a suite of virtualization security products designed to keep your virtual datacenters secure, ESXi hosts secure, the edge of the network secure, and even your VM apps secure. Find out how it works, what it can do for you, and how to implement vShield zones in your vSphere infrastructure.

  • An Overview of the vShield Suite
  • Centralized Management of the vShield Suite Using vShield Manager
  • Protecting Virtual Machines with vShield Zones
  • How vShield Zones Does Traffic Analysis
  • Configuring vShield Zones Firewall Policies
  • Enhancements Provided by vShield App
  • Deploy the vShield Manager
  • Deploy Agent VMs
  • Moving VMs Between Protected and Unprotected Hosts
  • Using vShield Edge to Provide Multi-tenancy Security
  • Putting All of the Pieces Together, Deploying the vShield Suite for Maximum Benefit
Lesson 19 - vShield: Endpoint and Trend Micro Deep Security

vShield endpoint provides third-party companies the ability to perform revolutionary virtual network security. You will learn how vShield endpoint works and how you would use Trend Micro’s Deep Security for vSphere to ensure your virtual infrastructure is virus-free without installing any anti-virus agents on your virtual machines.

  • What is vShield Endpoint?
  • An Overview of Trend Micro’s Deep Security
  • Pros and Cons
  • Deployment Steps
  • Deploy Endpoint
  • Install Deep Security Manager
  • Prepare the vSphere Host and Deploy an Agent VM
  • Install Drivers on the Guest and Activate the Guest to Be Managed
  • Configure Anti-malware and Intrusion Prevention Functionality
  • Where/When Would I Use Deep Security?
Lesson 20 - Hytrust Appliance

One of the most popular and useful third-party virtual infrastructure security solutions is the Hytrust appliance. Learn how it can help you and how it works in this lesson.

  • An Overview of Hytrust
  • Pros and Cons
  • Hytrust Installation Demo
  • Where/When Would I Use Hytrust
Lesson 21 - Compliance and vCenter Configuration Manager

VMware’s vCenter compliance and configuration manager ensures that the virtual infrastructure is never misconfigured or insecure by automatically detecting and comparing changes to policies. Learn how it works and how you would use it to maintain configuration security and compliance. Additionally, find out how to use VMware’s free compliance checker.

  • What is Compliance?
  • How Do We Do Compliance?
  • Why is Compliance Important?
  • Tools for Managing Compliance
  • About VMware Configuration Manager
  • VMware’s Compliance Checker for vSphere and PCI Compliance Checker
  • Installing and Running Free Compliance Checking Tools

Section 10: Course Conclusion

Lesson 22 - Next Steps

  • What is Your Next Step?
  • We Value Your Opinion

Certified Instruction

Certified Instructor Jason Nash

Jason Nash (VCP4, CISSP, RHCE, CCNP, VCDX #49)

Jason Nash has over 15 years of industry experience and is currently the Data Center Solutions Principal at Varrow, a leader in virtualization, storage, and DR located in the southeast. Before Varrow, Jason was a Platform Architect at a large investment bank where he helped to develop the organization’s IT strategy. He has published several books on networking, Windows, and Linux. Jason was designated a vExpert by VMware and holds a BS in Networking Technology and a MS in Information Security.

Certified Instructor Lane Leverett

Lane Leverett (VCDX 3 and 4 (VCDX #53), VCAP4-DCD, VCA4-DT , VCP4-DT, VCP3 and 4, MCSE NT4/2000/2003, CCNA, DCUCD, DCUCI)

Lane has worked in the IT industry for over 13 years. He has worked as a Server, Network, and Virtualization engineer in both private and public sector organizations. Lane has spent the last 6 years in a consulting role for 3 different Systems Integrators implementing, designing, and architecting VMware Infrastructure, Cisco and HP networking, and EMC, NetApp, HP, and IBM storage solutions for customers. He currently works for ENS Inc. out of Sacramento, CA as a Senior Systems Engineer where he works primarily with VMware Virtualization, EMC, Cisco, and Microsoft solutions for customers.

Lane has focused on server virtualization, specifically VMware server virtualization, over the past 6 years seeing the amazing benefits of cost savings and new opportunities, flexability, and mobility that virtualization offers companies.

In 2010 Lane was awarded the tile of VCDX 3 #53, one of the few people in the world to hold this title. In 2011 he also attained the upgrade of this certification to VCDX 4, as well as some of the newer Virtual Desktop related certifications: VCA4-DT and VCP4-DT. Lane has a passion for engaging with his customers and extoling and evangelizing the benefits of virtualization. He loves any chance he has to share and impart information with his customers.

Courses Instructed by Lane Leverett

Certified Instructor David Davis

David Davis (VCP4, VCAP-DCA, vExpert, CCIE #9369)

David has been in the IT industry for over 18+ years. He has served as a server/network admin, IT manager, and independent contractor. Today, David is a full-time instructor for TrainSignal.com where he has created over 10 different IT training courses.

Additionally, he has written hundreds of IT articles on the Internet, written for Virtualization Review magazine, served as a judge at VMware product competitions, and spoke on virtualization at conferences in the USA, Canada, and Europe. David's "real-world" experience combined with his diversity of skills (Virtualization, Windows Server, & Cisco Networking) gives you a powerful learning resource that can't be matched.

"Loved your ESX Server training videos!"

Thanks to you, I secured a position with a huge insurance firm looking after their VI of 60+ hosts and 100s of guests.

Michael Reilly United Kingdom
"We recently setup a 2nd server and needed a refresh on the partitioning and install procedure – the training course helped us review this by walking through the process..."

I purchased this to refresh skills taken from a hands on course and to see if there were other things I could learn about the product. I did not purchase the product to complete a certification. I purchased it to offer a visual review of items we at times need to refresh on.

We recently setup a 2nd server and needed a refresh on the partitioning and install procedure – the training course helped us review this by walking through the process.

We have used it several times for this need and it has been of value and helped with what we expected it to.

The course has helped me with exactly what I had hoped, I have been able to review items that needed review and refresh my skills. I need to take more time and complete the entire course to compare the hands on course to the CD based course.

Thanks,

Quinn Fowers Manager, Information Technologies, FMC Technologies
"Because time was a factor I needed to learn the material in a short period and TrainSignal was able to do that..."

AMHC is looking at consolidating and configuring our environment utilizing a virtualization approach. TrainSignal is an excellent resource to learn the material the fastest.

Because time was a factor I needed to learn the material in a short period and TrainSignal was able to do that. The material is organized in a way that is easy to learn.

I also like the fact that the instructor provides you with additional websites to obtain information about the product. Having the notes is also helpful because I am able to print each chapter and document the important areas that the instructor highlights.

The instructor is right to the point and I like how the examples are real-world scenarios. Other trainings will elaborate on discussions and will sometimes include material that is not related to the training.

Jason Cyr
"I knew I could rely on TrainSignal to provide usable information as I’ve used your other CBT’s to assist with Windows server projects such as File Server and Active Directory..."

I purchased the VMware ESX server course to improve hands on skills in installing the system. After doing demo work with the ESX system I was left with questions and wanted to see how your TrainSignal instructors set it up and what tips I could gather through your videos.

I knew I could rely on TrainSignal to provide usable information as I’ve used your other CBT’s to assist with Windows server projects such as File Server and Active Directory.

I wanted information on 3 areas; ESX installation; Virtual Center; and Consolidated Backup. I studied primarily the Consolidated Backup module, I learned that it is not a GUI program as I had envisioned but rather an agent.

With your CBT I am learning to understand the concept of the agent and how to install it properly. I have been able to work on my servers and watch your video simultaneously to step thru the installation process.

I love having the ability to go back to the videos and find the chapter I’m looking for and review the procedures. Your CBT’s are replacing my reference manuals!

Michael Virnig IS Director, Mille Lacs County

Looking For Volume User Licensing For VMware vSphere Security Design Training?

24/7 Instant Access to Individual Courses from TrainSignal

24/7 Access to Training

Online access to all training through My Online Training, with an option for physical media.

Volume Discounts on Individual Courses from TrainSignal

Volume Discounts

Discounts start at quantities as low as 2 licenses per training course.

Scalable Licensing Model from TrainSignal

Scalable Licensing Model

License your team for specific courses that meet their needs to build a custom package of TrainSignal Training.

Call 1.888.229.5055 or Email sales@trainsignal.com

Contact us for a free volume license quote or tell us how many licenses you need and we'll show you the volume license discount immediately in your cart.

Volume Discount Pricing For VMware vSphere Security Design Training

# of Users% DiscountCost Per User
10%$397.00
220%$317.60
3-425%$297.75
5-930%$277.90
10-1935%$258.05
20-4940%$238.20
50+Call 1.888.229.5055