
VMware, Inc. 7
1
ThischapterintroducestheVMware
®
vShield™componentsyouinstall.
Thechapterincludesthefollowingtopics:
“vShieldComponentsataGlance”onpage 7
“DeploymentScenarios”onpage 10
vShield Components at a Glance
VMwarevShieldisasuiteofsecurityvirtualappliancesbuiltforVMwarevCenter™Serverintegration.
vShieldisacriticalsecuritycomponentforprotectingvirtualizeddatacentersfromattacksandmisusehelping
youachieveyourcompliance‐mandatedgoals.
vShieldincludesvirtualappliancesandservicesessentialforprotectingvirtualmachines.vShieldcanbe
configured
throughaweb‐baseduserinterface,avSphereClientplug‐in,acommandlineinterface(CLI),and
RESTAPI.
vCenterServerincludesvShieldManagerandvShieldZones.ThefollowingvShieldpackageseachrequirea
license:
vShieldEdgewithPortGroupIsolation
vShieldApp
vShieldEndpoint
OnevShieldManagermanagesmultiplevShieldZones,vShieldEdge,vShieldApp,andvShieldEndpoint
instances.
vShield Manager
ThevShieldManageristhecentralizednetworkmanagementcomponentofvShield,andisinstalledasa
virtualapplianceonanyESX™hostinyourvCenterServerenvironment.AvShieldManagercanrunona
differentESXhostfromyourvShieldagents.
UsingthevShieldManageruserinterfaceorvSphereClientplug‐
in,administratorsinstall,configure,and
maintainvShieldcomponents.ThevShieldManageruserinterfaceleveragestheVMwareInfrastructureSDK
todisplayacopyofthevSphereClientinventorypanel,andincludestheHosts&ClustersandNetworks
views.
vShield Zones
vShieldZonesprovidesfirewallprotectionfortrafficbetweenvirtualmachines.ForeachZonesFirewallrule,
youcanspecifythesourceIP,destinationIP,sourceport,destinationport,andservice.
Introduction to vShield
1
Commentaires sur ces manuels