
VMware, Inc. 21
Chapter 3 Installing the vShield Manager and vShield Zones
3ClickthevShieldtab.
4Acceptthesecuritycertificate.
5ClickInstallforthevShieldZonesservice.
6Enterthefollowinginformation.
7ClickInstallatthetopoftheform.
YoucanfollowthevShieldZonesinstallationstepsfromtheRecentTaskspaneofthevSphereClient
screen.
8Afterinstallationofallcomponentsiscomplete,gotothevShieldZones>ZonesFirewalltabatthe
datacenter,cluster,orportgroupcontainerleveltoconfigurefirewallrules.EachvShieldZonesinstance
inheritsglobalfirewallrulessetinthevShieldManager.Thedefaultfirewallrulesetallowsalltrafficto
pass.Youmustconfigureblockingrulestoexplicitly
denytraffic.ToconfigureZonesFirewallrules,see
thevShieldAdministrationGuide.
Where to Go Next
AftervShieldManagerinstallationiscomplete,youcanconfigurevShieldZonesfirewallsettingsandanalyze
traffic.Formore,seethevShieldAdministrationGuide.
Toenhanceyournetworksecurityposture,youcanobtainlicensesforvShieldApp,vShieldEndpoint,and
vShieldEdge.Formore,seeChapter 4,“InstallingvShieldEdge,vShieldApp,and
vShieldEndpoint,”on
page 23.
Field Action
Datastore SelectthedatastoreonwhichtostorethevShieldZonesvirtualmachine
files.
ManagementPortGroup SelecttheportgrouptohostthevShieldZone’smanagementinterface.This
portgroupmustbeabletoreachthevShieldManager’sportgroup.
IPAddress TypetheIPaddresstoassigntothevShieldZone’s
managementinterface.
Netmask TypetheIPsubnetmaskassociatedwiththeassignedIPaddress.
DefaultGateway TypetheIPaddressofthedefaultnetworkgateway.
NOTEYoucanupgradevShieldZonestovShieldAppbyobtainingavShieldApplicense.vShieldApp
enhancesvShieldZonesprotectionbyofferingFlowMonitoring,customcontainercreation(SecurityGroups),
andcontainer‐basedaccesspolicycreationandenforcement.
YoudonothavetouninstallvShieldZonestoinstallvShieldApp.All
vShieldZonesinstancesbecomevShield
Appinstances,theZonesFirewallbecomesAppFirewall,andtheadditionalvShieldAppfeaturesareenabled.
Commentaires sur ces manuels