vGate

Virtual Machine Micro-Segmentation and Lifecycle Protection Tool

vGate

All-in-one cloud security platform

vGate creates a single virtualization protection loop for VMware, Microsoft Hyper-V and Skala-R environments. This unifies security and reporting policies in a heterogeneous environment.

Protection of all components for environment virtualization

Administrator's workplace, management server, and hypervisor host control provide comprehensive protection of applications against attacks coming from the virtual infrastructure.

Transparency and audit

Correlation of vGate events and the virtualization environment detects unauthorized activity and allows the detection incidents before they cause disastrous consequences.

Prompt execution of requirements

Built-in security presets ensure the level of IT infrastructure security required by regulators with minimal effort by maintenance personnel.

Virtual network micro-segmentation

Can be superimposed over the available network topology

Managed via API

Virtual machine life-cycle control

"Golden" template integrity control

Trusted load

Protection against the access of the environment administrator access to repositories and consoles

Reliable removal

Fault tolerance and scalability

VMware vCenter SRM support

VCenter Server Appliance High Availabiliy (vCSA HA) support

VCenter Linked Mode support

VMware Auto Deploy Support

Customization templates

Template for FSTEC order’s requirements

Template for GOST 57580.1-2017 and PCI DSS requirements for financial organizations

In compliance with VMware Hardening guide and CIS Benchmarks safety guidelines

vGate is used in

Structural part of the protected cloud 152-FZ

Softine cloud

vGate 4.7

Hardware

  • Requirements for a configuration of computer on which vGate components are installed are the same as requirements for the operating system installed on it.
  • The computer designated for the authorization server must have at least one Ethernet interface when using a network configuration with a separate router and at least two Ethernet interfaces if the traffic is routed by the authorization server.
  • It is not recommended to use the DHCP protocol for Ethernet interfaces connected to protected perimeter and perimeter of the administration network.

Software


Authentication server Windows Server 2012 R2, version 6.3.9600 x64
Windows Server 2016, version 1607 x64 + Update KB4103720
Windows Server 2019, version 1809, 2109 x64
Windows Server 2022
Hard drive — 10 ГБ
Ethernet network adapter
The minimum required channel bandwidth for the redundancy network is 10 Mbps
JaCarta drivers
Rutoken drivers
Backup authorization server

Ethernet network adapter
Windows Server 2012 R2, version 6.3.9600 x64
Windows Server 2016, version 1607 x64 + Update KB4103720
Windows Server 2019, version 1809, 2109 x64
Windows Server 2022 (21H2)
Hard drive — 10 ГБ
Ethernet network adapter
The minimum required channel bandwidth for the redundancy network is 10 Mbps
vGate client Microsoft Windows 10, version 1809, 2109 x64
Microsoft Windows 11 (21H2)
Windows Server 2012 R2, version 6.3.9600 x64
Windows Server 2016, version 1607 x64 + Update KB4103720
Windows Server 2019, version 1809, 2109 x64
Windows Server 2022 (21H2)
Hard drive — 200 МБ
Optional (when using a personal ID):
JaCarta drivers
Rutoken drivers
Web console Microsoft Edge version 91.0.864.48 (64-bit)
Google Chrome version 91.0.4472.101 (64-bit) and 91.0.4472.106 (32-bit)
Firefox version 89.0 (64-bit)
Safari version 12.1.2
Management Console and Report Viewer Microsoft Windows 10 version 1809, 2109 x64
Microsoft Windows 11 (21H2)
Windows Server 2012 R2, version 6.3.9600 x64
Windows Server 2016, version 1607 x64 + Update KB4103720
Windows Server 2019, version 1809, 2109 x64
Windows Server 2022 (21H2)
Hard drive — 200 МБ
Ethernet network adapter
vGate agent for ESXi VMware vSphere 6.5 (VMware ESXi Server 6.5)
VMware vSphere 6.7 (VMware ESXi Server 6.7)
VMware vSphere 7.0 (VMware ESXi Server 7.0)
The traffic filtering component for VMware ESXi 7.0 Update 3i is not supported

vGate software is not guaranteed to work with free editions of ESXi, as well as on custom vSphere images (from server manufacturers HP, IBM, etc.)
vGate Agent for vCenter (vCSA) Windows Server 2012 R2 + Update KB2999226
Windows Server 2016 version 1607 x64 + Update KB4103720
Windows Server 2019, version 1809 x64
Photon OS
VMware vSphere 6.5 (VMware vCenter Server 6.5)
VMware vSphere 6.7 (VMware vCenter Server 6.7)
VMware vCenter Server Appliance 6.5
VMware vCenter Server Appliance 6.7 VMware
vCenter Server Appliance 7.0
Hard drive – 200 МБ
Operation of vGate software on custom vSphere images (from server manufacturers HP, IBM, etc.) is not guaranteed
Agent for PSC Platform Services Controller 6.7
Platform Services Controller Appliance 6.7
vGate agent for KVM Ubuntu 18.04.6 LTS
Ubuntu 20.04.3 LTS
Additionally, the Glibc package must be installed on the KVM server
vGate software is supported to work with the following
KVM virtualization management tools:
Proxmox 7.2
OpenNebula 5.10.5, Proxmox 7.0
Monitoring server VVMware vSphere 6.5
VMware vSphere 6.7
VMware vSphere 7.0

A virtual machine that meets the minimum requirements:
CPU — 2 core
RAM — 4 ГБ
storage — 20 ГБ
Analysis server A virtual machine that meets the minimum requirements:
CPU — 2 cores per network interface for traffic analysis
RAM — 4 ГБ
storage — 20 ГБ

vGate Documentation

Information contained in these documents may be changed by the developer without special notice; such changes do not violate the developer’s obligations to the user.



Function vGate Enterprise vGate Enterprise+

Separation of rights for virtual infrastructure management and security management

Yes Yes

Authentication of virtual infrastructure, information security and computer administrators

Yes Yes

Authorized control over access to confidential resources

Yes Yes

Security policies for virtual infrastructure management tools and protected perimeter facilities

Yes Yes

VM configuration integrity control, trusted boot

Yes Yes

Recording of information security events

Yes Yes

Centralized management and security events audit

Yes Yes

Notifications on audit events via SMTP and Syslog protocols

Yes Yes

Automated deployment of vGate agents

Yes Yes

Back up of configuration and Vgate event log

Yes Yes

Simultaneous management of multiple vGate authorization servers

Yes Yes

Synchronization of authorization server settings

Yes Yes

VGate authorization server hot standby for increased fault-tolerance

Yes Yes

VCenter Linked Mode support

Yes Yes

VMware Auto Deploy support

Yes Yes

VCenter High Availability support

Yes Yes

Vmware vSAN Operations Control

Yes Yes

Information security status and events reporting

No Yes

Virtual infrastructure monitoring

No Yes

Network segmentation

No Yes

Integrity control of Hypervisor Configuration Files

No Yes

IS compliance scanner

No Yes