?
Solved

off / suspended guests and AV/Patch

Posted on 2012-03-27
12
Medium Priority
?
347 Views
Last Modified: 2012-06-27
Do you deploy any specific procedures around keeping off and suspended guests patched with OS security updates and AV definitions? If not - what is the risk? If yes - why so, why the need? I.e. if you power them on after 6 months they'll obviously be behind (I assume you cant patch and off or suspended guest?) but wouldnt your patch management and AV update tools just kick in and patch them the next time they are on?

I've been going through one of the DoD checklists and they say organisations must have some sort of process to keep off/suspended guests patched.

From vCenter - where could one see a list of currently off and suspended guests, could anyone provide a screenshot? And is there any where that you can see how long they have been "off" or "suspended for"?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 3
12 Comments
 
LVL 30

Expert Comment

by:IanTh
ID: 37770558
I think you need to do that with powercli
0
 
LVL 30

Accepted Solution

by:
IanTh earned 1000 total points
ID: 37770562
see
http://read.virtualizeplanet.com/?p=157

you could see it in vcenter but as it logs everything at the bottom finding a spcific vm off after 6 months
0
 
LVL 30

Expert Comment

by:IanTh
ID: 37770573
0
Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

 
LVL 123

Assisted Solution

by:Andrew Hancock (VMware vExpert / EE MVE^2)
Andrew Hancock (VMware vExpert / EE MVE^2) earned 1000 total points
ID: 37770576
If we Suspend Machines (which we do not really) for any length of time, when a VM is Powered On it will be discovered by AV and Patching software automaitcally and updated to Company Standards.

All Physical and Virtual machines need to be patched and maintained, whether on or off.

in vCenter the Virtual Machine will have a "pause symbol" indificating Suspended in the Inventory.

Suspended Machine
Suspended Machine
The event logs in vCenter would state when the Machine was Suspended.
0
 
LVL 3

Author Comment

by:pma111
ID: 37770730
>All Physical and Virtual machines need to be patched and maintained, whether on or off.

Why so, because if you turn it back on, then surely then the AV/PM solution wll find it, find its out of date and update it? Are you saying you schedule an "on window" where you patch it, then turn it off again, until the next window?

Whats the symbol for an "off" machine as opposed a suspended? Why would you suspend over turning it off, or is it the same issue?
0
 
LVL 3

Author Comment

by:pma111
ID: 37770738
My concern is if you have an unpatched machine thats off, who can attack it?
0
 
LVL 123
ID: 37770760
In the screeshots above, a virtual machine which is OFF, does not have a Green Arrow or Yellow Suspended Pause Button.

It's just Blue. As per vMaster VM.

You would maybe want to Suspend, if you wanted to turn the VM on quicker, but I do not think it's used much in a Production World.

Yes, you need to ensure ALL Computers are patched.

Yes, in our Config, if a computer is attached to our LAN, and discovered by AV and Patching software it's updated.

IF THE MACHINE IS OFF, IT IS NOT AS RISK! IT CANNOT BE ATTACKED!
0
 
LVL 3

Author Comment

by:pma111
ID: 37770780
So you say all machines must be patched, but then say if its off theres no risk. So... why and how do you patch your "off" machines? Do you just turn them back on and let your AV/PM tool patch them, even if theyd been off say 6 months, or do you schedule maintenance windows to patch them in case they were ever back on. I.e. turn the offs on, patch, and turn them off again/

Can you explain why machines would be turned off for prolonged periods of time. And why they'd be off for minimal periods of time?
0
 
LVL 3

Author Comment

by:pma111
ID: 37770786
Im basically getting at do you need any special arrangements for machines you know will be off for some time. I.e. does the fact turning them on with 6 months worth of missing patches/AV cause a window of opportunity...
0
 
LVL 123
ID: 37770904
if our machines are OFF for an extended period the are for decommissioning.

otherwise machines are not turned off.

In the real world, machines would not be off for extended periods if in Production.
0
 
LVL 3

Author Comment

by:pma111
ID: 37770927
Why would they be off at all?
0
 
LVL 123
ID: 37770938
because they are going to be retired. deleted and archived.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If we need to check who deleted a Virtual Machine from our vCenter. Looking this task in logs can be painful and spend lot of time, so the best way to check this is in the vCenter DB. Just connect to vCenter DB(default DB should be VCDB and using…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
This Micro Tutorial steps you through the configuration steps to configure your ESXi host Management Network settings and test the management network, ensure the host is recognized by the DNS Server, configure a new password, and the troubleshooting…
In this video tutorial I show you the main steps to install and configure  a VMware ESXi6.0 server. The video has my comments as text on the screen and you can pause anytime when needed. Hope this will be helpful. Verify that your hardware and BIO…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question