
VMware, Inc. 9
Chapter 1 Introduction to vShield
vShield App
vShieldAppisaninterior,vNIC‐levelfirewallthatallowsyoutocreateaccesscontrolpoliciesregardlessof
networktopology.AvShieldAppmonitorsalltrafficinandoutofanESXhost,includingbetweenvirtual
machinesinthesameportgroup.vShieldAppincludestrafficanalysisandcontainer‐basedpolicy
creation.
vShieldAppinstallsasahypervisormoduleandfirewallservicevirtualappliance.vShieldAppintegrates
withESXhoststhroughVMsafeAPIsandworkswithVMwarevSphereplatformfeaturessuchasDRS,
vMotion,DPM,andmaintenancemode.
vShieldAppprovidesfirewallingbetweenvirtualmachinesbyplacingafirewallfilteronevery
virtual
networkadapter.Thefirewallfilteroperatestransparentlyanddoesnotrequirenetw orkchangesor
modificationofIPaddressestocreatesecurityzones.YoucanwriteaccessrulesbyusingvCentercontainers,
likedatacenters,cluster,resourcepoolsandvApps,ornetworkobjects,likePortGroupsandVLANs,to
reducethenumber
offirewallrulesandmaketheruleseasiertotrack.
YoushouldinstallvShieldAppinstancesonallESXhostswithinaclustersothatVMwarevMotion™
operationsworkandvirtualmachinesremainprotectedastheymigratebetweenESXhosts.Bydefault,a
vShieldAppvirtualappliancecannotbemovedby
usingvMotion.
TheFlowMonitoringfeaturedisplaysallowedandblockednetworkflowsattheapplicationprotocollevel.
Youcanusethisinformationtoauditnetworktrafficandtroubleshootoperational.
vShield Endpoint
vShieldEndpointdeliversanintrospection‐basedantivirussolution.vShieldEndpointusesthehypervisorto
scanguestvirtualmachinesfromtheoutsidewithoutabulkyagent.vShieldEndpointisefficientinavoiding
resourcebottleneckswhileoptimizingmemoryuse.
vShieldEndpointinstallsasahypervisormoduleandsecurityvirtualappliancefromathird‐
partyantivirus
vendor(VMwarepartners)onanESXhost.
Figure 1-2. vShield Endpoint Installed on an ESX Host
Commentaires sur ces manuels