VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 25

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 30
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 24
VMware, Inc. 25
Chapter 4 Installing vShield Edge, vShield App, and vShield Endpoint
7 SelectthevShieldEdgePortGroupIsolationHostPreparationcheckbox.
8 SelecttheDatastoreonwhichtostorethePortGroupIsolationservicefiles.
9 SelectthevShieldEndpointcheckbox.
10 ClickInstallatthetopoftheform.
YoucanfollowthevShieldAppinstallationstepsfromtheRecentTaskspaneofthevSphereClientscreen.
11 Afterinstallationofallcomponentsiscomplete,dothefollowing:
vShieldApp:Atthispoint,vShieldAppinstallationiscomplete.GotothevShieldApp>App
Firewalltabatthedatacenter,cluster,orportgroupcontainerleveltoconfigurefirewallrules.Each
vShieldAppinheritsglobalfirewallrulessetinthevShieldManager.Thedefaultfirewallruleset
allows
alltraffictopass.Youmustconfigureblockingrulestoexplicitlyblocktraffic.Toconfigure
AppFirewallrules,seethevShieldAdministrationGuide.
PortGroupIsolation:YoumustenablethePortGroupIsolationfeatureoneachvDS.After
enablementiscomplete,installavShieldEdgeoneachvDSportgroup.See“PrepareavNetworkfor
PortGroupIsolation”onpage 25.
vShieldEndpoint:Tocompleteinstallation,see“InstallingvShieldEndpoint”onpage 27.
Prepare a vNetwork for Port Group Isolation
PortGroupIsolationcreatesabarrierbetweenthevirtualmachinesprotectedbyavShieldEdgeandthe
externalnetwork.WhenyouenablePortGroupIsolationandinstallavShieldEdgeonavDSportgroup,you
isolateeachsecuredvDSportgroupfromtheexternalnetwork.WhenPortGroupIsolationis
enabled,traffic
isnotallowedaccesstothevirtualmachinesinthesecuredportgroupunlessNATrulesorVLANtagsare
configured.
To utilize Port Group Isolation
1InstallPortGroupIsolationoneachESXhost.
2EnablePortGroupIsolationoneachvDS.
3InstallavShieldEdgeoneachvDSportgroupyouplantosecure.
4Move
virtualmachinestosecuredvDSportgroups.
EnablingPortGroupIsolationoneachvDSwhereyouwillinstallavShieldEdgeallowsthePortGroup
IsolationservicetobeusedonanyportgroupinavDS.
To enable Port Group Isolation on a vDS
1LogintothevSphereClient.
2GotoView>Inventory>Networking.
3Right
clickavDS.
4 SelectvShield>EnableIsolation.
AbrowserwindowopenstoconfirmthatPortGroupIsolationhasbeenenabled.
AfterPortGroupIsolationinstallationiscomplete,installavShieldEdgeinstanceoneachvDSportgroup.
N
OTEPortGroupIsolationisanoptionalfeaturethatisnotrequiredforvShieldEdgeoperation.PortGroup
IsolationisavailableforvDSbasedvShieldEdgeinstallationsonly.
Vue de la page 24
1 2 ... 20 21 22 23 24 25 26 27 28 29 30

Commentaires sur ces manuels

Pas de commentaire