VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuale Utente Pagina 11

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 30
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 10
VMware, Inc. 11
Chapter 1 Introduction to vShield
Protecting Virtual Machines in a Cluster
InFigure 13,vShieldAppinstancesareinstalledoneachESXhostinacluster.Virtualmachinesareprotected
whenmovedviavMotion™orDRSbetweenESXhostsinthecluster.EachvAppsharesandmaintainsstate
ofalltransmissions.
Figure 1-3. vShield App Instances Installed on Each ESX Host in a Cluster
Common Deployments of vShield Edge
YoucanuseavShieldEdgewiththePortGroupIsolationfeaturetoisolateastubnetwork,usingNATtoallow
trafficinandoutofthenetwork.Ifyoudeployinternalstubnetworks,youcanusevShieldEdgetosecure
communicationbetweennetworksbyusingLANtoLANencryptionvia
VPNtunnels.
vShieldEdgecanbedeployedasaselfserviceapplicationwithinVMwareCloudDirector.
Common Deployments of vShield App
YoucanusevShieldApptocreatesecurityzoneswithinavDC.YoucanimposefirewallpoliciesonvCenter
containersorSecurityGroups,whicharecustomcontainersyoucancreatebyusingthevShieldManageruser
interface.Containerbasedpoliciesenableyoutocreatemixedtrustzonesclusterswithoutrequiring
an
externalphysicalfirewall.
InadeploymentthatdoesnotusevDCs,useavShieldAppwiththeSecurityGroupsfeaturetocreatetrust
zonesandenforceaccesspolicies.
ServiceProviderAdminscanusevShieldApptoimposebroadfirew allpoliciesacrossallguestvirtual
machinesinaninternalnetwork.Forexample,
youcanimposeafirewallpolicyonthesecondvNICofallguest
virtualmachinesthatallowsthevirtualmachinestoconnecttoastorageserver,butblocksthevirtual
machinesfromaddressinganyothervirtualmachines.
Unprotected Cluster
Protected Cluster
Vedere la pagina 10
1 2 ... 6 7 8 9 10 11 12 13 14 15 16 ... 29 30

Commenti su questo manuale

Nessun commento