(cas:72) Google Analyticator was unable to authenticate you with Google using the Auth Token you pasted into the input box on the previous step.

This could mean either you pasted the token wrong, or the time/date on your server is wrong, or an SSL issue preventing Google from Authenticating.

Try Deauthorizing & Resetting Google Analyticator.

Tech Info 400:Error fetching OAuth2 access token, message: 'invalid_grant'
Unique
Visitors
Powered By Google Analytics
Comments on: vSphere Security Hardening Policy and SRM 5 http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/ all things Nutanix, VMware, cloud and virtualizing business critical applications Wed, 06 Jun 2012 22:47:09 +0000 hourly 1 https://wordpress.org/?v=6.7.6 By: blocksandbytes http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-1101 Wed, 06 Jun 2012 22:47:09 +0000 http://longwhiteclouds.com/?p=964#comment-1101 I have to agree with Gary. We use DHCP across all our production servers (with reservations) and it has made the integration with SRM 5 and failover of VMs so easy. Best of all the MAC address of the VM doesn't change during failover to a different virtaul center so you can specify IP addresses with reservations in advance for DR too if you wish.

]]>
By: @vcdxnz001 http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-928 Fri, 20 Apr 2012 00:03:33 +0000 http://longwhiteclouds.com/?p=964#comment-928 In reply to FY.

Hi Fo, It's not the vNIC driver that does this, it's SRM doing it via VIX. It's just changing the IP address inside the Guest OS when the VM is recovered and powered on at the recovery site, which is in a different IP subnet. This is not necessary with stretched layer 2, but many companies don't have that available and do need to change IP's. vSwitch Security configuration also needs to be taken into account.

]]>
By: @vcdxnz001 http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-927 Fri, 20 Apr 2012 00:01:29 +0000 http://longwhiteclouds.com/?p=964#comment-927 In reply to FY.

Hi Fo, We do have a safe an reliable IP change service via VIX. Provided the proper security controls around it's use are implemented. It's also possible via vCenter Customization Scripts.

]]>
By: FY http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-925 Thu, 19 Apr 2012 23:56:13 +0000 http://longwhiteclouds.com/?p=964#comment-925 In reply to FY.

I am unsure whether it is good to let the vNIC driver having the capability of changing IP by responding to fail over requirements from SRM.

]]>
By: FY http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-924 Thu, 19 Apr 2012 23:45:57 +0000 http://longwhiteclouds.com/?p=964#comment-924 We need a protocol to provide safe and reliable IP change service.

]]>
By: vSphere 5 Security Hardening Guide – Public Draft « Long White Virtual Clouds http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-919 Wed, 18 Apr 2012 21:39:01 +0000 http://longwhiteclouds.com/?p=964#comment-919 […] may remember that I recently commented about the VIX API impact on SRM in my article – vSphere Security Hardening Policy and SRM 5, and this was also picked up on by Tech Target in VMware SRM 5 encounters potential security […]

]]>
By: @vcdxnz001 http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-910 Tue, 17 Apr 2012 00:51:33 +0000 http://longwhiteclouds.com/?p=964#comment-910 In reply to dconvery.

Hi Dave, I agree. However external auditors and organizations without full knowledge of the impact often make the call as to which recommendations must be applied. Also it is often a requirement to meet certain regulations. In these situations there may be little room to maneuver. Then there is the fact that it's the vSphere Hardening Guide, and doesn't take into account other VMware Products. I will ask VMware to include a note re breaking SRM functionality with this particular recommendation though, given it's now well known.

]]>
By: dconvery http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-909 Tue, 17 Apr 2012 00:44:12 +0000 http://longwhiteclouds.com/?p=964#comment-909 I didn't do the survey, but wanted to voice my opinion. Each item in the guide is a RECOMMENDATION. This is NOT the Gospel According to VMware. It should be added as a recommended item, but should have a note/comment that it will break the functionality of SRM. Some people view this stuff as a requirement and don't consider the constraints each decision places on the next decision. Leave it up to the designer to decide not to comply with the VIX recommendation and provide justification for it.

]]>
By: vSphere Security Hardening Policy and Site Recovery Manager 5 | UP2V http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-911 Mon, 16 Apr 2012 15:49:08 +0000 http://longwhiteclouds.com/?p=964#comment-911 […] more about this at the blogposting of  Michael Webster, a VMware Certified Design Expert and director of IT Solutions 2000 Ltd., a […]

]]>
By: Gary Blake http://longwhiteclouds.com/2012/04/13/vsphere-security-hardening-policy-and-srm-5/comment-page-1/#comment-902 Fri, 13 Apr 2012 19:45:13 +0000 http://longwhiteclouds.com/?p=964#comment-902 In reply to @vcdxnz001.

I have to agree, DHCP is a very effective way to address the IP change. I've just completed a deployment with one of my customers doing just that across a multi-tier SAP implementation. DHCP spoofing is certainly a risk but if a company is that concerned about security they would have a lot of other measures in place to help mitigate that risk. But then that said I'm not a security expert !!

]]>