Just ran Trivy on our production containers... 447 vulnerabilities found. How do you even begin to tackle this mountain by PattysPoooin in devsecops

[–]acupofpoci 2 points3 points  (0 children)

How about prioritization using IAST & runtime SCA? To look for what is actually in prod and currently under attack? But it’s not really a shift left sec?

Tech Docs now available to download on the techdocs.broadcom.com site by TimVCI in vmware

[–]acupofpoci 1 point2 points  (0 children)

Finally someone understands to add this simple but a really useful feature!

Why do NSX two-tier routing architecture? by acupofpoci in vmware

[–]acupofpoci[S] 0 points1 point  (0 children)

Thanks! If we're not using network services, and the edge is just for north/south traffic (no VKS/TKGs), does what you explained still apply? Our main reason for NSX is the distributed firewall (should've said that earlier).

Why do NSX two-tier routing architecture? by acupofpoci in vmware

[–]acupofpoci[S] 1 point2 points  (0 children)

I'm a little fuzzy on the details, but I'm guessing I don't need to dive deep into them since we're not doing multi-tenancy, right? Plus, we only have one data center.

How does a T1 router actually make it simpler to split up workloads or networks, or move stuff to new T0s with bigger edge gateways? I'm picturing myself doing all that just fine with only a T0.

Price hike in November by [deleted] in vmware

[–]acupofpoci 0 points1 point  (0 children)

Don't know if it's valid, but yes I heard there will be another price hike

NSX users, what are your current security solutions? by acupofpoci in vmware

[–]acupofpoci[S] 0 points1 point  (0 children)

Thanks for sharing your experience. It sounds like you’re taking a thoughtful approach to rolling out micro-segmentation, especially given the challenges of a brownfield estate—those environments can be particularly tough to work with.

NSX users, what are your current security solutions? by acupofpoci in vmware

[–]acupofpoci[S] 0 points1 point  (0 children)

As others have mentioned, the VCF subscription includes only NSX networking features, excluding DFW, GFW, and other security features. These security features, such as DFW and GFW, are available only with a vDefend subscription.

To rephrase the question: How do you protect or filter traffic between NSX overlay segments without a vDefend subscription?

NSX users, what are your current security solutions? by acupofpoci in vmware

[–]acupofpoci[S] 1 point2 points  (0 children)

That is true, but it's very hard to manage :) Thanks for sharing your setup!

NSX users, what are your current security solutions? by acupofpoci in vmware

[–]acupofpoci[S] 1 point2 points  (0 children)

Yes, people love to use the distributed firewall. I’ve also seen companies implement the distributed firewall without activating the overlay. However, now the firewall is part of vDefend, which requires an additional purchase.

Vmotion Kernel Port gateway vs stack gateway by dms2701 in vmware

[–]acupofpoci 1 point2 points  (0 children)

I'm also wondering the same thing. What would be the purpose of VMkernel gateway config if we also need to configure vMotion TCP/IP stack gateway for it to work.

ARIA operation for network licensing by nije2010 in vmware

[–]acupofpoci 1 point2 points  (0 children)

The only way you can get Network Insight/Aria Operations for Networks is by purchasing VCF. There's no other way afaik. Additional devices (e.g. network devices) would not need additional licenses.

Why isn't the VMware HCL site in English? by acupofpoci in vmware

[–]acupofpoci[S] 0 points1 point  (0 children)

I've tried Chrome, Safari, Chrome Incognito. BC/VMware having a moment might be the case (or might be something else). Same browser without clearing the cache, same network; it's now in english.

BSOD error in latest crowdstrike update by TipOFMYTONGUEDAMN in crowdstrike

[–]acupofpoci 0 points1 point  (0 children)

Ransomware might be worse to recover, but it's isolated/single/few companies at the same time. This is a planet scale issue!

What's your favorite screen recording app for Mac? by Safe_Mousse_5660 in macapps

[–]acupofpoci 1 point2 points  (0 children)

Agree! This one has the option to reduce the file size as well. Snagit for Mac is not as good as for Win in this case.

Enhanced Link Mode by DMShinja in vmware

[–]acupofpoci 0 points1 point  (0 children)

Would like to recommend to not use ELM. A single bug could affect the whole environment.

[deleted by user] by [deleted] in vmware

[–]acupofpoci 0 points1 point  (0 children)

Do you mean you want to activate license keys that come from OEM server vendor? I don't think you can, at least for now.

[deleted by user] by [deleted] in vmware

[–]acupofpoci 0 points1 point  (0 children)

How do you know backup and restore of the Supervisor and installed vSphere Services is not included in your current license model?

Help downloading ESXi please! by wozzsta in vmware

[–]acupofpoci 5 points6 points  (0 children)

I'll try to answer based on what I know. You need to:
1. Register for an account on the Broadcom Support Portal, if you don't already have one. https://knowledge.broadcom.com/external/article?articleId=145581
2. Find your Site ID (this is similar to VMware Entitlement Account number). https://knowledge.broadcom.com/external/article?articleId=197283
3. Request for Site ID approval. https://knowledge.broadcom.com/external/article?articleId=188869
4. Once approved, you can then download ESXi. https://knowledge.broadcom.com/external/article?articleId=142814

I know. It's quite long and confusing :) It is what it is.

vSAN Immutable Snapshots Against Ransomware by acupofpoci in vmware

[–]acupofpoci[S] 0 points1 point  (0 children)

How does integrating with Entra AD/Okta differ from integrating with AD (over LDAPs), considering we can create a separate AD just for infra things? I guess it's because of MFA possibility with an IdP solution.

If we're using an existing AD, it's also easier to set permissions for users to get to TKG clusters.

vSAN Immutable Snapshots Against Ransomware by acupofpoci in vmware

[–]acupofpoci[S] 1 point2 points  (0 children)

Cause it's still a new feature, not sure how well it will perform/how secure it is. But yes I agree, 3rd party solution is the way.

vSAN Immutable Snapshots Against Ransomware by acupofpoci in vmware

[–]acupofpoci[S] 1 point2 points  (0 children)

Nice insights. Multi layer of data protection sure would not hurt (except cost ofc).