img
Home > Mechanisms > Virtual Firewall

Virtual Firewall

Virtual Firewall

A virtual firewall is a virtual appliance (virtual software) running as a virtual server that controls and filters communication to virtual servers, from virtual servers, and between virtual servers. Virtual servers need to be protected via physical and virtual firewalls. The data, virtual servers, LUNs and networks of different cloud consumers need to be isolated so that they cannot access each other's services.

Virtual servers are similar to physical servers in that they also require protection and security, although they have additional requirements:

  • Encryption mechanisms need to be used to protect the virtual servers' disk content. This prevents someone who has gained access to the virtual disk file from being able to access the actual data stored inside the virtual disk file.
  • Unnecessary services need to be disabled.
  • Virtual servers can be deployed from a hardened virtual server image.

In Figure 1, a virtual firewall and three virtual servers are hosted on the same hypervisor. Traffic is received and inspected by the virtual firewall before being forwarded to and from the virtual servers.

Figure 1 - A virtual firewall example.

Related Patterns:

CloudSchool.com Cloud Certified Professional (CCP) Module 7: Fundamental Cloud Security
CloudSchool.com Cloud Certified Professional (CCP) Module 8: Advanced Cloud Security

This mechanism is covered in CCP Module 7: Fundamental Cloud Security and
in Module 8: Advanced Cloud Security.

For more information regarding the Cloud Certified Professional (CCP) curriculum, visit www.arcitura.com/ccp.

Cloud Computing Design Patterns

The architectural model upon which this design pattern is based is further covered in:

Cloud Computing Design Patterns by Thomas Erl, Robert Cope, Amin Naserpour

(ISBN: 9780133858563, Hardcover, ~ 528 pages)

For more information about this book, visit www.arcitura.com/books.