VMware Workstation 7 Manuale Utente Pagina 402

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 401
Workstation User’s Manual
402 VMware, Inc.
Setting Network Access Policies
Thenetworkaccessfeatureusesapacketfilteringfirewalltoenableyoutospecify
whichmachinesorsubnetsanACEinstanceoritshostsystemmayaccess.Thismeans
thatyoucan,forexample,configuretheinstancesothatitisallowedtoconnectonlyto
yourVPNserver,whichthencontrolsaccesstoot
herresources.
Youcanalsocustomizethenetworkaccesssettingstofilteronthebasisofnetwork
addresses,trafficdirection,protocol,andports.Youcansetthefollowingtypesof
networkaccessrestrictiondefinitions:
Networkzones
NetworkaccessforanACEinstance’shostmachine(alsoknownas“hostnetwork
access”)
NetworkaccessforanACEinstance’sguestoperatingsystem(alsoknownas
“guestnetworkaccess”)
NetworkaccesspoliciescanbedynamiciftheACEinstanceisassociatedwithanACE
ManagementServer.ThismeansthatafteryoupublishapolicyupdatetoACE
ManagementServer,ACEinstancesgetthenewpolicythenextti
metheycheckfor
policyupdates.YoucanquicklylockACEinstancesoutofallorpartofyournetwork
tohelpcombatthespreadofawormorviruswithoutdeployingupdatepackages.See
theVMware ACEManagementServerAdministrator’sGuide.
Before You Begin Setting Host Policies
Usethefollowingguidelinesasyouplannetworkaccesspolicies:
AhostmachineforACEinstancescanhaveonlyonehostpolicyfile.Ifyoutryto
installanACEpackagewithahostpolicyfileonamachinethatalreadyhasa
differenthostpolicyfile,installationofthenewpackagefails.
AhostpolicyisineffectevenwhennoACEinstancesarerunning.Thepolicystarts
immediatelyafterinstallationandstartsworkingeverytimethehostsystemboots.
Anyrestrictionsonthehost’snetworkaccessalsorestrictnetworkaccessforan
ACEinstancethatusesNATnetworking,becausetheNATconnectionisaffected
byallthepoliciesyouapplytothehost.Ifyousetuprestrictedhostaccessbyusing
theACEruleseteditorandruleseditorratherthantheNetw
orkAccesswizard,
configuretheACEenabledvirtualmachine’svirtualNICstousebridged
networking.
IfyouaresettingupamanagedACEenabledvirtualmachine,youmustallowthe
hosttoaccessACEManagementServer,communicatingthroughTCPoverthe
appropriateportthatyouconfigure.
Vedere la pagina 401
1 2 ... 397 398 399 400 401 402 403 404 405 406 407 ... 511 512

Commenti su questo manuale

Nessun commento