VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuale Utente Pagina 28

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 90
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 27
vShield API Programming Guide
28 VMware, Inc.
Managing NAT
ThevShieldEdgeprovidesnetworkaddresstranslation(NAT)servicetoprotecttheIPaddressesofinternal,
privatenetworksfromthepublicnetwork.YoucanconfigureNATrulestoprovideaccesstoservicesrunning
onprivatelyaddressedvirtualmachines.TheNATserviceconfigurationisseparatedintoSNAT(Secure
NetworkAddressTranslation)and
DNAT(DestinationNetworkAddressTranslation)rules.
AllSNATand DNATrulesconfiguredbyusingRESTrequests appearunderthevShieldEdge>NATtabfor
theappropriatevShieldEdgeinthevShieldMana geruserinte rf a c eandvSphereClientplugin.
FortheNATschema,see“NATSchema”onpage 77.
Managing SNAT Rules
ThevShieldEdgeusesSNATtomapinternaladdressestoallocatedpublicaddresses.IfyouusePortGroup
Isolation,youmustconfigureSNATrulestoallowtrafficfromtheinternalnetworktotheexternalnetwork.
Get the SNAT Rule Set
Example 5-13. Get the SNAT rule set on a vShield Edge
Request:
GET <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/snat/rules
Example:
GET /api/1.0/network/network-244/snat/rules HTTP/1.1
Authorization: Basic YWRtaW46ZGVmYXVsdA==
Host: localhost
Post an SNAT Rule Set
YoucanpostanSNATrulesetforavShieldEdgeviaREST.ThevShieldManagerprocessesthepostedXML
fileasacompleterulesetforthespecificvShieldEdge.Thecurrentrulesetisreplacedwiththisnewsetof
rules.
Example 5-14. Post an SNAT Rule Set on a vShield Edge
Request:
POST <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/snat/rules
<VShieldEdgeConfig>
<NATConfig>
<NATRule>
<externalIpAddress>
<ipAddress>IpOrAny</ipAddress>
or
<IpRange>
<rangeStart>ip_address</rangeStart>
<rangeEnd>ip_address</rangeEnd>
</IpRange>
</externalIpAddress>
<internalIpAddress>
<ipAddress>IpOrAny</ipAddress>
or
<IpRange>
<rangeStart>ip_address</rangeStart>
<rangeEnd>ip_address</rangeEnd>
</IpRange>
Vedere la pagina 27
1 2 ... 23 24 25 26 27 28 29 30 31 32 33 ... 89 90

Commenti su questo manuale

Nessun commento