Introduction

About Secure Boot

Supported Deployment Platforms

Benefits of Secure Boot Feature

ISA VA Supported Platforms

Abbreviations Used in This Guide

About Secure Boot

The Secure Boot feature offers protection against unauthorized bootloader and kernel images, malware, and rootkits, and ensures compliance with secure-by-design principle while improving boot time security validation.

Supported Deployment Platforms

This Secure Boot feature is supported on:

ISA6000/ISA6500/ISA8000/ISA8500 Hardware Appliances

VMware for ICS release 22.8R2/25.1.0.0

Hyper-V, OpenStack and Azure for ICS release 25.1.1.0

AWS and GCP for ICS release 25.1.3.0

For deploying on VMware. see Deploying Virtual Appliances on VMware.

For deploying on Hyper-V, see Deploying on Hyper-V.

For deploying on Openstack KVM, see Deploying on Openstack.

For deploying on Azure, see Deploying on Azure.

For deploying on AWS, see Deploying on Amazon Web Services

For deploying on GCP, see Deploying on Google Cloud Platform.

Benefits of Secure Boot Feature

Protection from unauthorized bootloader images - Secure Boot prevents booting unauthorized bootloader (GRUB) images via signature verification of the bootloader (GRUB) from UEFI.

Protection from unauthorized kernel images - Secure Boot prevents booting unauthorized kernel images via signature verification of the kernel from GRUB bootloader.

Protection against malware and rootkits - Secure Boot prevents loading malware/rootkits via chain of trust from UEFI to GRUB to Kernel using signatures verification.

Compliance with Security By Design principle for boot protection.

ISA VA Supported Platforms

ISA VA Platforms for 25.1.0.0

ISA VA Platforms for 25.1.1.0

ISA VA Platforms for 25.1.3.0

ISA VA Platforms for 25.1.0.0

Platform

Qualified

Qualified Cloud VM Types /Equivalent ISA-V

VMware ESXi 8.0U3d

Q

(4 vCPUs / ISA4000-v), (8 vCPUs/ ISA6000-v), (12 vCPUs/ ISA8000-v)

ISA VA Platforms for 25.1.1.0

Platform

Qualified

Qualified Cloud VM Types /Equivalent ISA-V

VMware ESXi 8.0U3d

Q

(4 vCPUs / ISA4000-v), (8 vCPUs/ ISA6000-v), (12 vCPUs/ ISA8000-v)

Microsoft Hyper-V Server 2022

Q

(4 vCPUs / ISA4000-v), (8 vCPUs/ ISA6000-v), (12 vCPUs/ ISA8000-v)

Openstack KVM

Q

(4 vCPUs / ISA4000-v), (8 vCPUs/ ISA6000-v), (12 vCPUs/ ISA8000-v)

Azure

Q

ISA4000-V (Standard_D4s_v6)

ISA4000-V (Standard_D4ds_v6)

ISA6000-V (Standard_D8s_v6)

ISA6000-V (Standard_D8ds_v6)

ISA8000-V (Standard_D16ds_v6)

ISA4000-V (Standard_F4as_v6)

ISA6000-V (Standard_F8as_v6)

ISA8000-V (Standard_F16as_v6)

ISA VA Platforms for 25.1.3.0

Platform

Qualified

Qualified Cloud VM Types / Equivalent ISA-V

Disk Space

VMware ESXi 8.0U3d

Q

(4 vCPUs / ISA4500-v / 8 GB RAM), (8 vCPUs / ISA6500-v / 16 GB RAM), (12 vCPUs / ISA8500-v / 32 GB RAM),

80 GB

Microsoft Hyper-V Server 2022 Q (4 vCPUs / ISA4500-v / 8 GB RAM), (8 vCPUs / ISA6500-v / 16 GB RAM), (12 vCPUs / ISA8500-v / 32 GB RAM),

80 GB

(Beta)Openstack KVM

(Beta)Red Hat OpenShift

(Beta)Proxmox

Q

(4 vCPUs / ISA4500-v), (8 vCPUs / ISA6500-v), (12 vCPUs / ISA8500-v)

Note: ICS image for KVM (OpenShift, OpenStack, Proxmox) are available in Beta only. Customers can get these builds only from Support, Sales or Field teams.

80 GB

Azure Q

• 4 vCPUs / ISA4500-V (Standard_D4ds_v6) / 16 GB RAM

• 4 vCPUs / ISA4500-V (Standard_D4s_v6) / 16 GB RAM

• 8 vCPUs / ISA6500-V (Standard_D8ds_v6) / 32 GB RAM

• 8 vCPUs / ISA6500-V (Standard_D8s_v6) / 32 GB RAM

• 16 vCPUs / ISA8500-V (Standard_D16ds_v6) / 64 GB RAM

• 4 vCPUs / ISA4500-V (Standard_F4as_v6) / 16 GB RAM

• 8 vCPUs / ISA6500-V (Standard_F8as_v6) / 32 GB RAM

• 16 vCPUs / ISA8500-V (Standard_F16as_v6) / 64 GB RAM

80 GB

AWS Q

• 4 vCPUs / ISA4500-V (c7i.xlarge) / 8 GB RAM

• 8 vCPUs / ISA6500-V (c7i.2xlarge) / 16 GB RAM

• 16 vCPUs / ISA8500-V (c7i.4xlarge) / 32 GB RAM

• 4 vCPUs / ISA4500-V (m7i.xlarge) / 8 GB RAM

• 8 vCPUs /ISA6500-V(m7i.2xlarge) / 16 GB RAM

• 16 vCPUs / ISA8500-V (m7i.4xlarge) / 32 GB RAM

• 4 vCPUs / ISA4500-V (c7i-flex.xlarge) / 8 GB RAM

• 8 vCPUs / ISA6500-V (c7i-flex.2xlarge) / 16 GB RAM

• 16 vCPUs / ISA8500-V (c7i-flex.4xlarge) / 32 GB RAM

• 4 vCPUs / ISA4500-V (m7i-flex.xlarge) / 8 GB RAM

• 8 vCPUs / ISA6500-V (m7i-flex.2xlarge) / 16 GB RAM

• 16 vCPUs / ISA8500-V (m7i-flex.4xlarge) / 32 GB RAM

80 GB

GCP Q

• 4 vCPUs / ISA4500-V (n4-standard-4) / 16GB RAM

• 8 vCPUs / ISA6500-V (n4-standard-8) / 32GB RAM

• 16 vCPUs / ISA8500-V (n4-standard-16) / 64GB RAM

80 GB

Abbreviations Used in This Guide

Term

Description

BIOS and UEFI

Basic input / output system (BIOS) is a program fixed and embedded on a device's microprocessor that helps to initialize hardware operations.

Unified Extensible Firmware Interface (UEFI) offers users a faster and sleeker experience. It supports secure booting of the bootloader.

BIOS uses 16-bit mode and has a limited user interface, UEFI uses 32-bit or 64-bit mode and offers a more advanced graphical user interface.

MBR and GPT

Master Boot Record (MBR) is the information in the first sector of a hard disk or a removable drive.

GUID Partition Table (GPT) is introduced as part of the Unified Extensible Firmware Interface (UEFI) initiative.

 

GPT provides a more flexible mechanism for partitioning disks than the older Master Boot Record (MBR) partitioning scheme.

GRUB and GRUB2

GRand Unified Bootloader (GRUB or GNU GRUB) is a Multiboot boot loader for Linux and other Unix-based OSes.

GRUB2 bootloader is the bootloader on x86 systems that is used to load the linux kernel or any other OS. GRUB2 is allowed to load by UEFI if its signature matches the signature in the UEFI’s whitelist DB.

ICS

Ivanti Connect Secure (ICS) provides a seamless, cost-effective SSL VPN solution for remote and mobile users from any web-enabled device to corporate resources.

ISA Ivanti Secure Access hardware appliance.