Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology



Similar documents
Solution Recipe: Remote PC Management Made Simple with Intel vpro Technology and Intel Active Management Technology

PC Solutions That Mean Business

Enhanced Virtualization on Intel Architecturebased

A Superior Hardware Platform for Server Virtualization

Intel Virtualization Technology (VT) in Converged Application Platforms

How To Get A Client Side Virtualization Solution For Your Financial Services Business

Intel Trusted Platforms Overview

Intel Embedded Virtualization Manager

Intel Cloud Builder Guide: Cloud Design and Deployment on Intel Platforms

Proven LANDesk Solutions

Citrix and Intel Deliver Client Virtualization

Intel Cyber-Security Briefing: Trends, Solutions, and Opportunities

Cloud based Holdfast Electronic Sports Game Platform

Developing an Enterprise Client Virtualization Strategy

Intel Cloud Builders Guide: Cloud Design and Deployment on Intel Platforms

Intel Active Management Technology Embedded Host-based Configuration in Intelligent Systems

Virtualization. Dr. Yingwu Zhu

Using Multi-Port Intel Ethernet Server Adapters to Optimize Server Virtualization

Intel Cyber Security Briefing: Trends, Solutions, and Opportunities. Matthew Rosenquist, Cyber Security Strategist, Intel Corp

Overcoming Security Challenges to Virtualize Internet-facing Applications

ORACLE VIRTUAL DESKTOP INFRASTRUCTURE

An Oracle White Paper August Higher Security, Greater Access with Oracle Desktop Virtualization

Citrix XenApp Server Deployment on VMware ESX at a Large Multi-National Insurance Company

Intel Network Builders: Lanner and Intel Building the Best Network Security Platforms

Server Consolidation with SQL Server 2008

IOS110. Virtualization 5/27/2014 1

Intel Remote Configuration Certificate Utility Frequently Asked Questions

ORACLE OPS CENTER: VIRTUALIZATION MANAGEMENT PACK

Comparing Free Virtualization Products

Choosing a Server to Fit your Business

Dell Client. Take Control of Your Environment. Powered by Intel Core 2 processor with vpro technology

Parallels Virtuozzo Containers

Taking Virtualization

Accelerating High-Speed Networking with Intel I/O Acceleration Technology

Intel Ethernet and Configuring Single Root I/O Virtualization (SR-IOV) on Microsoft* Windows* Server 2012 Hyper-V. Technical Brief v1.

Choosing a Server to Fit Your Business. A step-by-step guide to help businesses maximize the benefits of Intel. Xeon -based server solutions.

HP Compaq dc7800p Business PC with Intel vpro Processor Technology and Virtual Appliances

Virtualizing the Client PC: A Proof of Concept. White Paper Intel Information Technology Computer Manufacturing Client Virtualization

SUSE Linux Enterprise 10 SP2: Virtualization Technology Support

Intel Cloud Builder Guide to Cloud Design and Deployment on Intel Xeon Processor-based Platforms

Data Sheet: Archiving Altiris Client Management Suite 7.0 from Symantec Deploy, manage, secure, and troubleshoot

How to Configure Intel Ethernet Converged Network Adapter-Enabled Virtual Functions on VMware* ESXi* 5.1

Top 10 Reasons to Virtualize VMware Zimbra Collaboration Server with VMware vsphere. white PAPER

W H I T E P A P E R. Reducing Server Total Cost of Ownership with VMware Virtualization Software

LANDesk White Paper. LANDesk Management Suite for Lenovo Secure Managed Client

WHITE PAPER Mainstreaming Server Virtualization: The Intel Approach

Intel Identity Protection Technology Enabling improved user-friendly strong authentication in VASCO's latest generation solutions

Reducing the Cost and Complexity of Business Continuity and Disaster Recovery for

Intel Media SDK Library Distribution and Dispatching Process

Getting Started with VMware Fusion

I/O Virtualization Using Mellanox InfiniBand And Channel I/O Virtualization (CIOV) Technology

Data Sheet: Endpoint Management Altiris Client Management Suite 7.0 Deploy, manage, secure, and troubleshoot

Creating Overlay Networks Using Intel Ethernet Converged Network Adapters

Server Virtualization A Game-Changer For SMB Customers

Intel vpro. Technology-based PCs SETUP & CONFIGURATION GUIDE FOR

Virtualizing Exchange

Best Practices for Installing and Configuring the Hyper-V Role on the LSI CTS2600 Storage System for Windows 2008

What is a Managed Service Provider (MSP)? What is the best solution for an MSP?

Q A F 0 3. ger A n A m client dell dell client manager 3.0 FAQ

Leading Virtualization 2.0

Getting Started with VMware Fusion. VMware Fusion for Mac OS X

evm Virtualization Platform for Windows

Simplify IT and Reduce TCO: Oracle s End-to-End, Integrated Infrastructure for SAP Data Centers

Intel Active Management Technology with System Defense Feature Quick Start Guide

System Requirements and Platform Support Guide

Autodesk 3ds Max 2010 Boot Camp FAQ

Vendor Update Intel 49 th IDC HPC User Forum. Mike Lafferty HPC Marketing Intel Americas Corp.

Intel Cyber-Security Briefing: Trends, Solutions, and Opportunities. John Skinner, Director, Secure Enterprise and Cloud, Intel Americas, Inc.

Mitigating Risks and Monitoring Activity for Database Security

Resolving the Top Three Patch Management Challenges

VDI can reduce costs, simplify systems and provide a less frustrating experience for users.

Intel Identity Protection Technology (IPT)

10 easy steps to secure your retail network

APPLICATION OF SERVER VIRTUALIZATION IN PLATFORM TESTING

Memory Sizing for Server Virtualization. White Paper Intel Information Technology Computer Manufacturing Server Virtualization

Enhanced Diagnostics Improve Performance, Configurability, and Usability

Servervirualisierung mit Citrix XenServer

System Planning, Deployment, and Best Practices Guide

Enabling Device-Independent Mobility with Dynamic Virtual Clients

Intel AMT Provides Out-of-Band Remote Manageability for Digital Security Surveillance

International Journal of Advancements in Research & Technology, Volume 1, Issue6, November ISSN

SyAM Software* Server Monitor Local/Central* on a Microsoft* Windows* Operating System

Managing Wireless Clients with the Administrator Tool. Intel PROSet/Wireless Software 10.1

Windows Embedded Security and Surveillance Solutions

Endpoint protection for physical and virtual desktops

Virtual Desktop Infrastructure Planning Overview

Deployment Options for Microsoft Hyper-V Server

Transcription:

Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology 30406_VT_Brochure.indd 1 6/20/06 4:01:14 PM

Preface Intel has developed a series of unique Solution Recipes designed for channel members interested in providing complete solutions to their customers, backed by top-quality technology and support. A solution recipe describes how to combine Intel -based ingredients to create new technology solutions for common business challenges. This recipe illustrates how business productivity and PC security can be improved with Intel Virtualization Technology (Intel VT) a hardware-based technology for enabling virtualization in the PC 1. When you are ready to deploy this recipe, please refer to the related Solution Deployment Guide, which includes step-by-step instructions. You can find the guide by visiting: www.intel.com/go/reseller/vpro or www.intel.com/go/solutions Common Notations and Terms Virtualization: A virtualized computer can run multiple operating systems and applications on the same machine in independent partitions or containers. In other words, virtualization allows one computer to act as if it were several computers working in parallel. Intel Virtualization Technology (Intel VT): This technology permits one hardware platform to function as multiple virtual platforms. It offers improved system manageability, which helps limit downtime and maintain worker productivity. Table of Contents Meeting New Market Opportunities 2 Solution Overview 3 Key Technology 6 Solution Benefits 7 Solution Recipe 9 Solution Support 10 Virtual Machine Monitor (VMM): A layer of software that virtualizes a computer s hardware resources (for example, CPU, memory, network interface) into multiple virtual machine environments. 1 www.intel.com, ftp://download.intel.com/business/bss/products/client/digitaloffice/vt_desktopusage.pdf, May 30, 2006 Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 1 30406_VT_Brochure.indd 2 6/20/06 4:01:17 PM

Addressing New Market Opportunities Meeting New Market Opportunities Today s IT professionals are facing increasingly complex challenges in the areas of PC productivity, manageability, and security. Businesses are demanding more efficient use of their computing systems. End users can become frustrated by perceived workflow interruptions on the network. Extensive use of e-mail and Web browsing exposes PCs to viruses, worms, and other malicious attacks that could put the company s entire network at risk. The good news is that many of these concerns can be addressed with virtualization technology for PCs. Virtualization is a proven technology that allows one computer system to function as multiple virtual systems. It enables multiple operating systems and application stacks to be hosted in distinctly separate areas (known as partitions) on a single computer system at the same time. Until recently, virtualization was used almost exclusively by IT professionals, mostly on the server side. But today, virtualization technology is expanding onto end-user PCs bringing with it remarkable potential to improve basic business operations. Intel VT is a hardware-based technology for enabling virtualization in the PC. Because of this development, leading software developers are already working on more secure, more productive solutions enabled by Intel VT. Intel s latest PC innovation, Intel vpro technology, was created to fully optimize this new, built-in virtualization capability. With the ability to create secure, dedicated partitions, you can configure each customer s network to fit their specific need a clear benefit to your customers, and a promising new source of revenue for you. Bottom line: PCs equipped with Intel vpro technology and Intel VT can help businesses of all sizes improve productivity, manageability, and security and it is available today. 1 Intel Active Management Technology (Intel AMT) requires that the platform have an Intel AMT-enabled chipset, network hardware and software, connection with a power source, and a network connection. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 2 30406_VT_Brochure.indd 3 6/20/06 4:01:22 PM

Solution Overview Traditionally, virtualization has been purely software-based. But now, in PCs equipped with Intel vpro technology and Intel VT, many virtualization capabilities are built directly into the hardware. This simplifies numerous computing processes for the virtualization software, resulting in more reliable and compatible virtualization solutions. Software-only Virtualization In software-only virtualization solutions, the Virtual Machine Monitor (VMM) controls physical server resources so that it can manage the demands of multiple guest operating systems. To provide that level of control, the VMM runs in the space traditionally reserved for the operating system, and guest operating systems run in the space traditionally used for applications. Because the operating systems are not designed to run in this application environment, complex software workarounds are required for them to function reliably. This creates significant issues for IT managers, including: Potential incompatibility with legacy operating systems, which increases testing and validation requirements when consolidating legacy applications onto new servers Increased likelihood of software conflicts due to the complexity of the VMM application Additional performance overhead necessary to handle the complex software workarounds Dependent VMM and operating system development, so the VMM vendor must continually adapt to operating system upgrades and patches (and vice-versa) Synchronized upgrades and patching in IT environments, which adds to complexity, expense, and risk Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 3 30406_VT_Brochure.indd 4 6/21/06 3:23:30 PM

Intel Virtualization Technology (Intel VT) With Intel VT, your customers get hardware-based virtualization that works with compatible virtualization software. Together, they address the challenges faced by software-only solutions. Specifically, Intel VT offers: A new, privileged space for the VMM that reduces the need for VMM intervention and allows guest operating systems to run directly on hardware Handoffs between the VMM and guest operating systems that are supported in hardware, reducing the need for complex, compute-intensive, time-consuming software transitions Hardware-based memory protection, in which processor-state information for the VMM and each guest operating system is retained in dedicated address spaces, accelerating transitions and helping to ensure process integrity Ability to create virtual appliances, which are self-contained operating environments dedicated to a particular function, such as manageability or security On PCs with Intel vpro technology, Intel VT provides the ability to create and control numerous separate virtual machines. Each of these partitions can be isolated and controlled independently of the others, creating work areas for multiple users on one PC. Each of the partitions can also be quickly reconfigured, allowing IT to add, delete, or transfer resources to meet changing business needs. With this technology, IT can strengthen network security, improve manageability, and boost productivity all at the same time. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 4 30406_VT_Brochure.indd 5 6/20/06 4:01:25 PM

Security Businesses can isolate critical applications, such as accounting or Customer Relationship Management (CRM) software, from the rest of the system. If a vulnerable part of the system gets infected, such as the e-mail or Web browsing partition, it can be quarantined to prevent it from infecting other applications. Manageability Virtualization support will allow businesses to maintain full control of a portion of a PC to run security or management services in a dedicated space on the system. By housing the management agents in separate partitions, IT managers can monitor and manage these platforms without interrupting business operations. They can perform functions like hardware inventory management, provisioning, or diagnostics without interrupting the user. Business critical applications can be segregated to separate partitions to reduce risk Productivity Creating different partitions for IT and end users allows for upgrades and patches without interrupting workflow. You can also run multiple operating systems and applications (for example, continue using older proprietary software, but use new office software) and test upgrades to software without interrupting end users. Suggested Uses Desktop PCs with Intel vpro technology and Intel VT are specifically designed to address top IT challenges in security, productivity, and manageability at the hardware level. A typical setup may include virtual machines for key applications such as: Isolation/containment Partition: A separate partition to isolate and contain any virus infections that try to breach the network through a PC. Common sources include Web browsing, e-mail, and file sharing/downloads. Voice Over Internet Protocol (VoIP) Partition: Create a dedicated space to host an always on VoIP (Internet-based phone service). VoIP Software Web Browser E-mail Other Office Applications CRM, ERP, Accounting Applications Operating System Operating System Operating System VMware* (virtual machine manager) Intel vpro technology-based PC Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 5 30406_VT_Brochure.indd 6 6/20/06 4:01:29 PM

Key Technology Intel VT Hardware-based virtualization technology that reduces the workload of virtualization software. This technology is optimized for Intel Core 2 Duo desktop processors and provides more robust virtualization capabilities. Intel Core 2 Duo Desktop Processors Powerful Intel Core 2 Duo desktop processors offer a substantial upgrade in processing capacity at reduced power-consumption levels. VMware* Optimized for use with Intel Core 2 Duo desktop processors, VMware* helps deliver a virtualization experience. Benefits include helping to secure desktop data, enabling easier remote network access and consolidating multiple desktop environments on to one PC or server. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 6 30406_VT_Brochure.indd 7 6/20/06 4:01:29 PM

Solution Benefits Benefits for Intel Channel Partner Program Members By offering desktops with Intel vpro technology and Intel VT, you can solidify your position as a vendor who offers complete solutions, not just products. The best part about offering Intel VT is that almost any company or business function has a legitimate need for it. Online Retail Sales Do any of your customers carry out business online with credit cards? They will certainly want to keep that information secure. Human Resources How about your company s HR records? You don t want everyone in the company to have access to that information, so a separate, secure, virtual partition would be a good solution. Product Development Companies such as software development firms would appreciate the ability to keep different operating system partitions, which would allow for easy testing of their products on different platforms (for example, Microsoft Windows*, Linux*, Apple Macintosh*). Education Schools could take advantage of the ability to run multiple operating systems and applications, broadening their offerings to students. New Revenue Streams With Intel VT, you also open the possibility of creating new revenue streams by extending your service offerings to customers, such as providing remote management of virtual machines using the VMware* remote console. You can gain remote access to a customer s virtual machine, even when remote management capability isn t provided by the particular operating system or application. In addition, because you are able to create a dedicated service partition inside the customer s server, you can run the service activities unnoticed and isolated from your customer s end users. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 7 30406_VT_Brochure.indd 8 6/20/06 4:01:32 PM

Benefits for Your Customers Desktop PCs with Intel vpro Technology and Intel VT provide simple remote management and tamper-resistant security capabilities. This means IT has more control where they need it at the console which delivers a number of key benefits: Improved PC Security Specific applications, such as e-mail or Web browsing, can be assigned to their own partition on PCs. These separate partitions create a way for IT to isolate viruses and other threats so that they don t infect other PCs on the system. This translates to more server uptime and more productivity for end users. End Users Isolated from Security Settings IT functions can be placed on separate partitions from end-user applications. This limits access to key security tools, such as anti-virus and firewall settings, which could be turned off by end users, exposing the PCs on your network to viruses, worms, or other malicious attacks. Fewer Service Interruptions Automatic failover partitions provide an easy, cost-effective way to keep the system running. If an application fails, the system can automatically switch over to a parallel backup application, which limits downtime for end users. Enhanced Manageability Configuration of multiple partitions allow IT to isolate end-user system management agents, which otherwise might be vulnerable to end-user tampering. Separate partitions on a PC can also help improve manageability by providing the flexibility to migrate to newer operating systems while still making use of older operating system environments and applications. Easier Migration to New Software Many companies use custom software for areas such as human resources, logistics, or purchasing. When they migrate to a new operating system or office application, there is no need to immediately update all of the proprietary software. Instead, proprietary software can be assigned its own partition and continue to function as usual. In addition, new operating system platforms and office applications can run concurrently with old software. Then, when end users are proficient with the new software, the old software can be removed from the system, creating more space all of which saves both time and money. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 8 30406_VT_Brochure.indd 9 6/20/06 4:01:47 PM

Solution Recipe Software Architecture VMware* Workstation virtualization software makes the operating system and applications run in a virtual machine environment. This makes these components hardware-independent (that is, hardware platform support is no longer required by these software components). The VMware Workstation virtual machine can be provisioned to any Intel vpro technology-based platform and it can manage multiple operating systems and applications as a single unit by encapsulating them into virtual machines. System Architecture Components Necessary to Build Intel vpro technology-based platform with Intel VT Microsoft Windows XP* Pro SP2 (with Intel PRO/1000 Network driver) VMware Workstation* for Microsoft Windows 5.5.1 Guest operating system (OS) Microsoft Windows NT* 4.0 Server, Red Hat* Linux Desktop 4 update 2, Ubuntu* 5.10 NOTE: The guest operating systems listed above are only a sampling of those that work with Intel Virtualization Technology, not a complete list. The Intel vpro platforms, coupled with VMware Workstation software, are ideal for enabling small- and medium-sized businesses to consolidate multiple client platforms into one high-performance platform at a low cost. It is easy to set up the software, and built-in Intel VT helps it run efficiently on Intel vpro platforms. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 9 30406_VT_Brochure.indd 10 6/20/06 4:01:48 PM

Support Solution Support Intel has tested and verified the components in this virtualization solution for PCs recipe. Please continue to use your existing Intel Support Services (http://www.intel.com/go/channel/support) for information on Intel -based hardware, including Intel Processors, Intel Desktop and Server Boards, and associated drivers. For your convenience, Intel has worked with several independent software vendors, open source vendors, and application vendors to streamline technical support for this solution. For more information on the third-party hardware and software products, please download the Solution Deployment Guide (www.intel.com/go/reseller/vpro or www.intel.com/go/solutions) to obtain the specific list of vendors and contacts. Solution Recipe: Improve PC Security and Reliability with Intel Virtualization Technology Page 10 30406_VT_Brochure.indd 11 6/20/06 4:01:48 PM

Intel, the Intel logo, Intel. Leap ahead. the Intel. Leap ahead. logo, Intel vpro, the vpro logo, Xeon, the Xeon logo, Intel Core and Core Inside are trademarks or registered trademarks of Intel Corporation or its subsidiaries in the United States and other countries. *Other names and brands may be claimed as the property of others. Copyright 2006, Intel Corporation. Intel Literature Center: 1-800-548-4725 Order Number: 313333-001US Printed in USA/06/06/JW/KC/PDF Information in this document is provided in connection with Intel products. No license, express or implied, by estoppel or otherwise, to any intellectual property rights is granted by this document. Except as provided in Intel s terms and conditions of sale for such products, Intel assumes no liability whatsoever, and Intel disclaims any express or implied warranty, relating to sale and/or use of Intel products including liability or warranties relating to fitness for a particular purpose, merchantability, or infringement of any patent, copyright or other intellectual property right. 30406_VT_Brochure.indd 12 6/20/06 4:01:50 PM