Welcome | Sign In
ECommerceTimes.com
Virtualization

Securing Your Network, One Zone at a Time

Print Version
E-Mail Article
Reprints
Securing Your Network, One Zone at a Time

Virtualization and other measures can complicate enterprise security, so Apani Networks has launched EpiForce VM, software that works across platforms to isolate servers and other endpoints into logical security zones.


Success is just a matter of knowing the right "secrets." Download the free eBook, "The Edge of Success: 9 Building Blocks to Double Your Sales." You will discover the fastest, most effective ways to grow your business and still have time to live your life.

As corporations implement compliance with various regulations such as Sarbanes-Oxley, they find that they end up with different zones within their network that can't talk to each other.

This makes it difficult to implement an enterprise security solution. Adding virtualization to the mix complicates things further.

Apani Networks has come up with a solution to this: EpiForce VM.

EpiForce VM

Launched at the RSA Security Conference held last week at San Francisco's Moscone Center, EpiForce VM is a software-based solution that lets enterprises isolate both virtual and physical servers and endpoints as well as business-critical data into logical security zones regardless of what platform they run on or where they are physically on the network.

"We don't care if you're running on legacy systems or Windows or Solaris or a virtual platform, you should be able to isolate your servers and PCs into zones of like-minded computers," Ryan Malone, Apani's vice president of marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales, told TechNewsWorld.

"We control communications between zones and within the zones themselves," he added, saying that this is "an alternative to traditional network segments and virtual local area networks."

How It Works

EpiForce VM came out of research done at the National Security Agency. It is IPSec-based and is deployed at the network layer so "it is transparent to your existing network, to your applications and to your users," Malone said. IPSec, or Internet protocol security, is a suite of protocols for securing IP communications by authenticating or encrypting each IP packet in a data stream, or doing both.

So, all communications between zones is controlled by authentication of all machine-to-machine traffic and encryption based on policies set by the user and accessed on demand.

All machines in the same logical zone, whether they run the same operating system, or are physical or virtual, will remain connected regardless of their physical location. "You can take a physical machine and convert it to a virtual machine, or physically relocate a machine, and it will still be connected to others in the same logical zone," Malone said.

That's because EpiForce VM uses IPSec agents. "Instead of having links between IP addresses (a server's or desktop's location on the Internet), we have IPSec agent to IPSec agent, so we can have persistent connectivity," Malone explained.

Managing EpiForce VM

The application comes with its own centralized console and 30 canned reports.

Alternatively, it can be integrated into existing network management applications. "If you have, say, HP (NYSE: HPQ) OpenView and you want to use Syslog to read your reports, EpiForce will write the reports to Syslog," Malone said.

Syslog is a standard for forwarding log messages in an IP network.

EpiForce VM will be available in the second quarter of this year, and will initially support VMWare ESX Server.

VMWare ESX Server users will be able to migrate virtual machines protected by EpiForce VM between physical hosts without disrupting existing security policies.


Print Version E-Mail Article Reprints More by Richard Adhikari


More by Richard Adhikari

Nvidia Optimus Gives Laptops a Graphical Gearshift
February 09, 2010
For gamers or anyone else using a computer for heavy graphics work, a discreet graphics card is a must-have. For laptop users, though, discreet graphics can be a real drain on battery power. Nvidia's new Optimus technology is able to discern which types of applications need the heavy-duty hardware and which can be handled by the integrated graphics processor, then smoothly transitions between the two, saving power.
Cisco Guns for Burgeoning Government Security Market
February 09, 2010
Former White House cybersecurity advisor Melissa Hathaway has been appointed as a consultant for Cisco to facilitate cooperation between the company and the federal government. With Hathaway's appointment, Cisco is taking what appears to be a stronger, lobbyist-style approach to getting government business, said Rob Enderle, principal analyst at the Enderle Group.
IBM Taps Green Power With New Chips, Servers
February 08, 2010
IBM's new Power7 processors provide the foundation for several new Unix server offerings from the company. Each Power7 processor has up to eight cores and four threads per core. Power7 also features "TurboCore" mode and has "intelligent threads," meaning the number of threads varies depending on the workload.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network