VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuale Utente Pagina 75

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 74
VMware, Inc. 75
Chapter 13 App Firewall Management
Create a Layer 2/Layer 3 App Firewall Rule
TheLayer2/Layer3firewallenablesconfigurationofallowordenyrulesforcommonDataLinkLayerand
NetworkLayerrequests,suchasICMPpingsandtraceroutes.YoucanchangethedefaultLayer2/Layer3rules
fromallowtodenybasedonyournetworksecuritypolicy.
Layer2/Layer3firewallrules
allowordenytrafficbasedonthefollowingcriteria:
To create a Layer 2/Layer 3 firewall rule
1InthevSphereClient,gotoInventory>HostsandClusters.
2 Selectadatacenterresourcefromtheresourcetree.
3ClickthevShieldApptab.
4ClickAppFirewall.
5ClickL2/L3Rules.
6ClickAdd.
Anewrowisaddedatthebottomofthe
DataCenterRulessectionofthetable.
7Doubleclickeachcellinthenewrowtotypeorselecttheappropriateinformation.
YoucantypeIPaddressesintheSourceandDestinationfields
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommit.
Creating and Protecting Security Groups
TheSecurityGroupsfeatureenablesyoutocreatecustomcontainerstowhichyoucanassignresources,such
asvirtualmachinesandnetworkadapters,forAppFirewallprotection.Afterasecuritygroupisdefined,you
addthesecuritygrouptoafirewallruleforprotection.
Add a Security Group
InthevSphereClient,youcanaddasecuritygroupatthedatacenterresourcelevel.
To add a security group by using the vSphere Client
1ClickadatacenterresourcefromthevSphereClient.
2ClickthevShieldApptab.
3ClickSecurityGroups.
4ClickAddGroup.
Criteria Description
Source(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)from
whichthecommunicationoriginated
Destination(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)which
thecommunicationistargeting
Protocol Transportprotocolusedforcommunication
NOTELayer2/Layer3firewallrulescanalsobecreatedfromtheFlowMonitoringreport.See“A d d anApp
FirewallRulefromtheFlowMonitoringReport”onpage 67.
Vedere la pagina 74
1 2 ... 70 71 72 73 74 75 76 77 78 79 80 ... 161 162

Commenti su questo manuale

Nessun commento