Data Loss Prevention

 View Only
  • 1.  ESXi server for DLP

    Posted Apr 10, 2013 07:46 AM

    Hi All,

    As we are planning for DLP implementation, I need some idea from all.

    As we can do this on ESXi server with 4 physical ports or Windows server 2008. Also let me know the better feasibility to implement this.



  • 2.  RE: ESXi server for DLP

    Posted Apr 11, 2013 11:49 AM

    Hi Rajat, I really don't think you're going to find help in the community until you provide us with more information. We need to know-

    • Number of Users
    • Desktop OS
    • Site Config (including network info)
    • DLP Features Desired
    • DLP Version
    • More info on Hardware.

    Anyone responding without that info would be taking a shot in the dark.

     

    Tim



  • 3.  RE: ESXi server for DLP
    Best Answer

    Posted Apr 12, 2013 12:36 AM

    hi Rajat,

    Refer below

    V10.0

    (Enforce & Discover/Protect + Prevent only) 
    Note: does not include Oracle DB

    The only VMware product Symantec DLP officially supports installation on is ESX Server 3.X (not VMware Workstation, GSX Server, ESXi Server, etc).  Configurations involving physical-to-virtual conversions ("P2V") using VMware Converter have not been tested by Symantec and are not certified.  Please also note that this only applies to VMware virtualization software.  Symantec DLP does not support any other virtualization platform, including ones from Microsoft or Citrix/Xen.  If you have questions about what may be supported in the future and when, please contact your Symantec DLP representative.

    V11

    Enforce
    Network Discover
    Network Protect
    Network Prevent for Email
    Network Prevent for Web
    Endpoint agents only (not Endpoint server)

    Citrix XenApp (Presentation Server) 4.5 and Citrix XenDesktop 3.0 are supported.
    VMware ESXi in general and VMware ESX 3.5 for Endpoint server are explicitly unsupported.
    ESX 4.0 is supported as well.

    VMWare Note:
    1. All –supported- DLP vms would have to meet the minimum requirements as outlined in Symantec_DLP_11.1_System_Requirements_Guide.
    2. The VMWare host machine would need to meet the SUM of those DLP vms PLUS additional resources to run the VMWare
    3. No specific performance guarantees or sizing recommendations for the virtual container specifications will be made.  Customer will need to validate proper sizing and performance impact on their own by testing their current virtualization design and expected performance needs.
    4. There will be no support for VMWare configuration and troubleshooting. Supporting DLP on VMWare is targeted for customers who have this technology deployed elsewhere in their current environment, have established internal standards on what should be virtualized, and a methodology to size and test the different products.



  • 4.  RE: ESXi server for DLP

    Posted Apr 13, 2013 02:08 PM

    Hi rajat,

    I think above things are enough to answer your question as virtualization supports to all components of DLP exclusing DLP endpoint server and oracle if I am not wrong.



  • 5.  RE: ESXi server for DLP

    Posted Apr 13, 2013 02:35 PM
    You can virtualize everything but oracle db and network monitor


  • 6.  RE: ESXi server for DLP

    Posted Apr 15, 2013 06:07 AM

    Hi Rajat,

    Did u got your answer or need anything more.



  • 7.  RE: ESXi server for DLP

    Posted Apr 16, 2013 01:55 PM

    Hi Rajat,

    Using ESXi server for DLP is to just reduce the resource cost and physical space and management. As virtulization not only reduces cost but also the space and maintence cost.This is good choise to efficietly use this solution for multipurpose as stumno mentioned only Oracle DB and Network monitor can only be on Physical servers as they does not support this.



  • 8.  RE: ESXi server for DLP

    Posted Apr 16, 2013 01:58 PM

    santosh

    these are good points, the disk spaces from the LUN as a whole not indivual spindles.

    Alot of the vmware disks a faster 10k or 15k spindles. this helps with the performance of the sytem overall performace, in the aspect of reporting and navigating the enfroce platform