-
Overview
-
Practical sheets
-
-
-
-
-
-
-
- Backup : Agent-Level B&R via NSS for IAAS offer
- Backup : Create VCOD Backup
- Backup : Netbackup Agent Installation for Linux
- Backup : Netbackup Agent Installation for Windows
- Backup : Overall Design for VCOD Offer
- Backup : User's Guide for VCOD Offer
- NSX-T : Configuring a Distributed Firewall [FR]
- NSX-T : Create a VPN Ipsec
- NSX-T : Creation of T1
- NSX-T : DNAT configuration
- NSX-T : How to configure a Gateway Firewall
- NSX-T : SNAT configuration
- NSX-T: Create and Configure a Geneve Overlay Segment [FR]
- NSX-T: How to configure an IPSEC solution
- vCenter : Clone a VM [FR]
- VCenter : Create a new VM
- VCenter : Create a snapshot of a VM
- VCenter : Reset cloudadmin password
- VCenter : Storage Vmotion on a VM
- VCenter : Upgrade Vmware tools on a VM
- Show all articles (5) Collapse Articles
-
-
Q & A
-
Services
- Backup
- Bare metal server
- Block Storage [FR]
- BVPN access
- Certifications [FR]
- Cross Connect [FR]
- Dedicated Cluster
- DRaaS with VCDA
- Dual Site [FR]
- HA Dual-Room
- Internet access
- Kubernetes [FR]
- Licenses
- LoadBalancer As A Service
- Network
- Network Storage
- Object storage
- QoS Appliance
- Security
- Support and Coaching
- Tools [FR]
- VCenter On Demand
- VM Replication [FR]
- Show all articles (8) Collapse Articles
Security
Overview
The security features available on Cloud Avenue are integrated at several levels:
- platform “output” level, via the embedded services into the internet and BVPN connectivity
- vCD “Organization / Tenant” level, through vmware NSX-T and AVI products.
Internet
Internet access is provided by Orange Business, and includes the following protection services:
- redundant access
- blackhole DDOS protection, on demand (removal of traffic to a public IP address)
In option, the Customer can subscribe to an additional offer which includes the Cleanpipe service that will redirect the trafic to a cleaning center.
https://www.orange-business.com/en/products/ddos-protection
BVPN
The Orange Business MPLS network is EAL2+ certified.
Portals protection
All portals exposed on the internet are protected by a WAF.
To reinforce security a little more, a Customer can request the deactivation of the internet exposure of the access url to its VCD portal. He will then have to access the VCD portal (and the APIs) via his BVPN access.
NSX-T
Perimeter firewall
The T1 gateway embeds a perimeter firewall, allowing North-South flows to be filtered, exactly as a physical firewall does. It manages the address translation rules (NAT) and thus makes it possible to protect the VMs of the organization networks carried by the T1.
Distributed firewall
NSX-T also makes it possible to deploy a distributed firewall, which can manage security in the scope of :
- one vDC
- several vDC, if they are grouped into a Datacenter Group.
This implementation, carried out at the ESXi level, makes it possible to manage east-west flows between the VMs. The rules can be based on tags placed on the VMs, in order to facilitate the propagation of the rules. For example, VMs tagged DEV will not have access to the internet, while VMs tagged PROD will have access.
VPN
NSX-T allows to create tunnels on the internet of 2 types:
- L2VPN
- L3VPN (IPSEC),
For the 2 types of tunnel, transmission security is entrusted to an AES GCM 128 encryption algorithm, and Diffie-Hellman group 14 for the key exchange algorithm.
Orange templates
The VM templates available in the vCD catalogs (Orange and Linux) have “hardened” OS (ports and services disabled), and include a Sophos antivirus agent (Windows template only). The Sophos agent is regularly updated via a centralized console, not visible to the Customer.
Billing
The security services integrated into Cloud Avenue are not subject to any specific billing.
For more information, see the Cloud Avenue White Paper.