Must-Read Post on Virtualized Switches

While visiting Hoff's blog I saw his post VMware to Open Development of ESX Virtual Switches to Third Parties...Any Guess Who's First?. You must read this. The question I have, as with all new "features," is this: is visibility built in? Will I have access to a "virtual tap"? Can I trust it? We'll see.

Comments

ethan said…
This comment has been removed by a blog administrator.
I think it's time to start planning "TCP/IP Virtual Weapons School" for Blackhat 2008.
Chris Buechler said…
You can already get a virtual tap on ESX, to a VM at least.
http://www.vmware.com/community/message.jspa?messageID=371562

AFAIK you can't currently turn a physical NIC on the host box into a vswitch tap, maybe that'll be part of it. I suspect the primary driver for this will be the "usual" stuff on managed switches that you can't get on a vswitch. Things like some L3 functionality, 802.1X maybe, and other means of allowing better control over ports on vswitches.

I'm definitely looking forward to hearing details about Cisco's plans. Should be interesting.

Popular posts from this blog

Zeek in Action Videos

New Book! The Best of TaoSecurity Blog, Volume 4

MITRE ATT&CK Tactics Are Not Tactics