I was reading this thread, and got to thinking about this a bit:
http://hardforum.com/showthread.php?t=1554608
Does anyone have any links regarding a true ESX/Hyper-V remote exploits? I've seen the occasional ESX bug over the years, including the ones that allow cross VM attacks, but these all required access to a VM on the host irself. I don't think I've ever come across a true honest to god remote exploit that didn't involve some idiot exposing the management interface to the web or something similar.
I can't say I would normally put an edge device and internal servers on the same host, but after thinking about it for the past day, I really can't see a problem with it. I understand and have always preferred the completely separate hardware, but I honestly can't come up with a solid reason not to virtualise on the same host. Sure, I can think of all sorts of hypothetical and mythical attacks that don't exist, but when it comes down to it, the edge device is a million times more likely to be hacked, and it doesn't really matter after that what your setup is. As long as you keep external/internal links partitioned by seperate NICs/vSwitches, it seems OK to me. Damnit, it seems so wrong, but I just can't come up with a good reason!
Then I realised that BackOffice/SBS Premium is pretty much this exact scenario, a single server with external/internal facing NICs, and all of us IT guys have happily installed thousands and thousands of these setups over the past 10+ years. Yeah, they might be installed behind a cheap, basic router with some port forwarding, but I've also seen hundreds plugged directly into the internet with no ill effects.
Also, thought this would be a decent setup for a colo situation. Instead of just coloing your 1U linux web server, why not colo an esxi server, with a small Untangle VM sitting in front of your linux VM? More piece of mind for the same rackspace cost.
Thoughts? As far as I can tell, neither MS or VMware have a stance on this, though that's not surprising.
Edit: Note, I'm really thinking towards the home/small business type of setup with just a single server. If you've got the 50k plus to put towards some nice multi server/SAN/HA type setup, you can afford something like an ASA or similar to us as your edge device.
http://hardforum.com/showthread.php?t=1554608
Does anyone have any links regarding a true ESX/Hyper-V remote exploits? I've seen the occasional ESX bug over the years, including the ones that allow cross VM attacks, but these all required access to a VM on the host irself. I don't think I've ever come across a true honest to god remote exploit that didn't involve some idiot exposing the management interface to the web or something similar.
I can't say I would normally put an edge device and internal servers on the same host, but after thinking about it for the past day, I really can't see a problem with it. I understand and have always preferred the completely separate hardware, but I honestly can't come up with a solid reason not to virtualise on the same host. Sure, I can think of all sorts of hypothetical and mythical attacks that don't exist, but when it comes down to it, the edge device is a million times more likely to be hacked, and it doesn't really matter after that what your setup is. As long as you keep external/internal links partitioned by seperate NICs/vSwitches, it seems OK to me. Damnit, it seems so wrong, but I just can't come up with a good reason!
Then I realised that BackOffice/SBS Premium is pretty much this exact scenario, a single server with external/internal facing NICs, and all of us IT guys have happily installed thousands and thousands of these setups over the past 10+ years. Yeah, they might be installed behind a cheap, basic router with some port forwarding, but I've also seen hundreds plugged directly into the internet with no ill effects.
Also, thought this would be a decent setup for a colo situation. Instead of just coloing your 1U linux web server, why not colo an esxi server, with a small Untangle VM sitting in front of your linux VM? More piece of mind for the same rackspace cost.
Thoughts? As far as I can tell, neither MS or VMware have a stance on this, though that's not surprising.
Edit: Note, I'm really thinking towards the home/small business type of setup with just a single server. If you've got the 50k plus to put towards some nice multi server/SAN/HA type setup, you can afford something like an ASA or similar to us as your edge device.
Last edited: