Dell EMC VxRack System SDDC Security Configuration Manual

Type
Security Configuration Manual

Dell EMC VxRack System SDDC is a turnkey software-defined data center (SDDC) appliance that combines VMware Cloud Foundation with Dell EMC PowerEdge servers to deliver a fully integrated and pre-tested SDDC environment. VxRack System SDDC is designed to simplify the deployment and management of VMware Cloud Foundation, providing customers with a turnkey solution for building and operating a private cloud.

With VxRack System SDDC, customers can:

  • Rapidly deploy a fully integrated and pre-tested SDDC environment
  • Simplify the management of their VMware Cloud Foundation environment
  • Benefit from Dell EMC's expertise in designing and deploying SDDC solutions

Dell EMC VxRack System SDDC is a turnkey software-defined data center (SDDC) appliance that combines VMware Cloud Foundation with Dell EMC PowerEdge servers to deliver a fully integrated and pre-tested SDDC environment. VxRack System SDDC is designed to simplify the deployment and management of VMware Cloud Foundation, providing customers with a turnkey solution for building and operating a private cloud.

With VxRack System SDDC, customers can:

  • Rapidly deploy a fully integrated and pre-tested SDDC environment
  • Simplify the management of their VMware Cloud Foundation environment
  • Benefit from Dell EMC's expertise in designing and deploying SDDC solutions
Dell EMC VxRack System SDDC
Version 5.1.3
Security Configuration Guide
REV 01
Copyright
©
2018 Dell Inc. or its subsidiaries. All rights reserved.
Published August 2018
Dell believes the information in this publication is accurate as of its publication date. The information is subject to change without notice.
THE INFORMATION IN THIS PUBLICATION IS PROVIDED “AS-IS.“ DELL MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND
WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. USE, COPYING, AND DISTRIBUTION OF ANY DELL SOFTWARE DESCRIBED
IN THIS PUBLICATION REQUIRES AN APPLICABLE SOFTWARE LICENSE.
Dell, EMC, and other trademarks are trademarks of Dell Inc. or its subsidiaries. Other trademarks may be the property of their respective owners.
Published in the USA.
Dell EMC
Hopkinton, Massachusetts 01748-9103
1-508-435-1000 In North America 1-866-464-7381
www.DellEMC.com
2 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
Introduction 5
About this guide........................................................................................... 6
Revision history............................................................................................ 6
Support........................................................................................................ 6
Registering for online support......................................................... 6
Where to go for support resources.................................................. 7
Reporting vulnerabilities............................................................................... 7
Security quick reference 9
Deployment models.....................................................................................10
Product and Subsystem Security 11
Authentication.............................................................................................12
iDRAC security............................................................................................12
Network security.........................................................................................12
Chapter 1
Chapter 2
Chapter 3
CONTENTS
Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide 3
CONTENTS
4 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
CHAPTER 1
Introduction
l
About this guide................................................................................................... 6
l
Revision history....................................................................................................6
l
Support................................................................................................................6
l
Reporting vulnerabilities....................................................................................... 7
Introduction 5
About this guide
This guide provides an overview of security configuration settings for the Dell EMC
VxRack SDDC system, and best practices for using those settings to ensure secure
operation of the product.
This guide provides information for system administrators and other users responsible
for configuring and maintaining the security for a VxRack SDDC cluster. This
document is designed for people familiar with:
l
Dell EMC systems and software
l
VMware virtualization products
l
Data center appliances and infrastructure
Revision history
The following table lists revision history for the VxRack SDDC Security Configuration
Guide.
Table 1 Revision History
Revision number Date Description
01 August 27, 2018 Initial release.
Support
Create an Online Support account to get access to support and product resources for
your VxRack SDDC system.
If you already have an account, register your VxRack SDDC system to access the
available resources.
For convenience, you can link your Online Support account with VxRack SDDC and
access support resources without having to log in separately.
Note
If you plan to set up ESRS, your Online Support account must be linked to VxRack
SDDC under the same party ID or the deployment will fail. Your system must also be in
an installed state in the Install Base.
Registering for online support
Create an Online Support account to access support resources.
After you register, you can:
l
Register your system
l
Obtain product license files and software updates
l
Download product documentation
l
Browse the community and support information
l
Link your support account for access to resources from within VxManager
Introduction
6 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
Procedure
1. Point your Web browser to support.emc.com.
2. Click Register here.
3. Fill in the required information.
Support will send you a confirmation email, typically within 48 hours.
Where to go for support resources
Access support resources for your VxRack SDDC system by doing any of the
following:
l
In VMware SDDC Manager, click Support.
l
Point your Web browser to support.emc.com.
Note
You must provide the iDRAC root passwords and the Administrator password for the
Support VM for all Dell EMC support engagements.
Reporting vulnerabilities
Dell EMC takes reports of potential vulnerabilities in our products very seriously. For
the latest on how to report a security issue to Dell EMC, please see the Product
Security Response Center on EMC.com.
Introduction
Where to go for support resources 7
Introduction
8 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
CHAPTER 2
Security quick reference
l
Deployment models............................................................................................ 10
Security quick reference 9
Deployment models
The VxRack SDDC system comes in multiple configurations with different capacities
and components.
Before deployment
When building the VxRack SDDC system, the factory performs the following actions:
l
Install all components in the chassis.
l
Install the system in the rack.
l
Complete basic configuration to provide a platform for final deployment at the
customer site.
During deployment
The VxRack SDDC system is installed by trained Dell EMC or partner personnel. When
deploying the appliance, technicians perform the following actions:
l
Connect power.
l
Connect the system to the customer network environment.
l
Complete VMware Cloud Foundation Bring-up process.
l
Register the system with the ESRS system.
The VxRack SDDC deployment process makes no security-related assumptions about
the customer environment. Customers are expected to provide suitable power and
data connections, as well as physical security to protect the system components.
The VxRack SDDC interface does not provide security-specific configuration options
or support additional configurations. All system components are deployed using the
best practices that are defined in the security configuration guides for each
component. The interface enforces an optimal environment for correct operation of
the appliance components.
After deployment
The VxRack SDDC system contains externally accessible interfaces for use by data
protection and management clients. Customers should take care to apply appropriate
access restrictions to prevent unauthorized use. All forms of access should be
regularly monitored and audited, as dictated by customer security requirements.
Security quick reference
10 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
CHAPTER 3
Product and Subsystem Security
l
Authentication.................................................................................................... 12
l
iDRAC security................................................................................................... 12
l
Network security................................................................................................ 12
Product and Subsystem Security 11
Authentication
This section describes default settings and configuration options for how users or
processes authenticate to the VxRack SDDC system.
"Mystic" account password
The VxManager sets the VxRack SDDC "mystic" account password by default.
Dell EMC strongly recommends that you change this password and maintain it
securely.
Support VM administrator password
Dell EMC recommends that you change the administrator password for the Support
VM.
The
Dell EMC VxRack System SDDC (version 5.1.3 or later) Administration Guide
provides
instructions for changing these passwords.
iDRAC security
This section describes best practices for the iDRAC interfaces used by the VxRack
SDDC system.
VxRack SDDC iDRAC ports are configured during manufacturing and installation. The
default iDRAC user name and password are provided on the system information tag.
We highly recommend that you change the iDRAC root password once the system is
deployed.
The
Dell EMC VxRack System SDDC (version 5.1.3 or later) Administration Guide
provides
instructions for changing this password.
Network security
This section describes best practices for the network interfaces used by the VxRack
SDDC system.
VxRack SDDC networking is configured during installation and the first-run process.
Consult with your sales representative or partner to prepare your switches and
network before installation.
Product and Subsystem Security
12 Dell EMC VxRack System SDDC 5.1.3 Security Configuration Guide
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12

Dell EMC VxRack System SDDC Security Configuration Manual

Type
Security Configuration Manual

Dell EMC VxRack System SDDC is a turnkey software-defined data center (SDDC) appliance that combines VMware Cloud Foundation with Dell EMC PowerEdge servers to deliver a fully integrated and pre-tested SDDC environment. VxRack System SDDC is designed to simplify the deployment and management of VMware Cloud Foundation, providing customers with a turnkey solution for building and operating a private cloud.

With VxRack System SDDC, customers can:

  • Rapidly deploy a fully integrated and pre-tested SDDC environment
  • Simplify the management of their VMware Cloud Foundation environment
  • Benefit from Dell EMC's expertise in designing and deploying SDDC solutions

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI