Добавил:
Upload Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
vsp_41_esx_server_config.pdf
Скачиваний:
10
Добавлен:
06.02.2016
Размер:
2.67 Mб
Скачать

ESX Configuration Guide

3Select Options > Advanced > General and click Configuration Parameters.

4Click Add Row and type the following values in the Name and Value columns.

Name Value isolation.tools.copy.disable false isolation.tools.paste.disable false

NOTE These options override any settings made in the guest operating system’s VMware Tools control panel.

5Click OK to close the Configuration Parameters dialog box, and click OK again to close the Virtual Machine Properties dialog box.

6Restart the virtual machine.

Removing Unnecessary Hardware Devices

Users and processes without privileges on a virtual machine can connect or disconnect hardware devices, such as network adapters and CD-ROM drives. Therefore, removing unnecessary hardware devices can help prevent attacks.

Attackers can use this capability to breach virtual machine security in several ways. For example, an attacker with access to a virtual machine can connect a disconnected CD-ROM drive and access sensitive information on the media left in the drive, or disconnect a network adapter to isolate the virtual machine from its network, resulting in a denial of service.

As a general security precaution, use commands on the vSphere Client Configuration tab to remove any unneeded or unused hardware devices. Although this measure tightens virtual machine security, it is not a good solution in situations where you might bring an unused device back into service at a later time.

Prevent a Virtual Machine User or Process from Disconnecting Devices

If you do not want to permanently remove a device, you can prevent a virtual machine user or process from connecting or disconnecting the device from within the guest operating system.

Procedure

1 Log in to a vCenter Server system using the vSphere Client. 2 Select the virtual machine in the inventory panel.

3On the Summary tab, click Edit Settings.

4Select Options > General Options and make a record of the path displayed in the Virtual Machine Configuration File text box.

5Log in to the service console and acquire root privileges.

6Change directories to access the virtual machine configuration file whose path you recorded in Step 4.

Virtual machine configuration files are located in the /vmfs/volumes/datastore directory, where datastore is the name of the storage device on which the virtual machine files reside. For example, if the virtual machine configuration file you obtained from the Virtual Machine Properties dialog box is [vol1]vm-finance/vm-finance.vmx, you would change to the following directory.

/vmfs/volumes/vol1/vm-finance/

212

VMware, Inc.

Соседние файлы в предмете [НЕСОРТИРОВАННОЕ]