VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 51

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 90
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 50
VMware, Inc. 51
6
YoucanconfigurevShieldAppfirewallrulesandsyslogservicebyusingRESTAPIcalls.
Thischapterincludesthefollowingtopics:
“ConfiguringFirewallRulesforavCenterContaineronpage 51
“ManagingSecurityGroups”onpage 56
“ConfiguringSyslogServiceforavShieldApp”onpage 59
Configuring Firewall Rules for a vCenter Container
TheprimaryfunctionofavShieldAppistoprovidefirewallprotectiononanESXhostbyinspectingeach
sessionandreturningdetailstothevShieldManager.Trafficdetailsincludesources,destinations,directionof
sessions,applications,andportsbeingused.Trafficdetailscanbeusedtocreatefirewallallowordeny
rules.
InthevShieldManageruserinterfaceorvSphereClientplugin,theAppFirewalltabcontainsthefirewall
rulesenforcedbyvShieldAppinstances.YoucanmanageAppFirewallrulesatthedatacenter,cluster,and
portgrouplevelstoprovideaconsistentsetofrulesacrossmultiplevShieldApp
instancesunderthese
containers.Asmembershipinthesecontainerscanchangedynamically,AppFirewallmaintainsthestateof
existingsessionswithoutrequiringreconfigurationoffirewallrules.Inthisway,AppFirewa lleffectivelyhas
acontinuousfootprintoneachESXhostunderthemanagedcontainers.
WhencreatingAppFirewallrules,youcan
creategeneralrulesbasedon incomingoroutgoingtrafficatthe
containerlev el.Forexample,youcancreatearuletodenyanytrafficfromout si de ofadatacenterthattargetsa
destinationwithinthedatacenter.Youcancreatearuletodenyanyincomingtrafficthatisnottaggedwith
a
VLANID.
Allfirew allrulesconfiguredbyusingRESTrequestsappearundertheAppFirewalltabfortheapprop ria te
containerinthevShieldManageruserinterfaceandvSphereClientplugin.
ForthecompletefirewallXMLschema,see“vShieldAppFirewallSchema”onpage 69.
View All Firewall Rules for a Container
Youcanviewallofthefirewallrulesforaspecificcontainer—datacenter,cluster,orportgroup—andanychild
containersbyidentifyingtheMOREFID(container-moref-id)ofthecontainer.Forexample,ifyourequest
therulesetatthedatacenterlevel,theresponseincludestherulesfortheclustersandport
groupswithinthat
datacenter.
Itisgoodpracticetoviewthecurrentfirewallrulesetbeforepostingneworupdatedrules.
vShield App Management
6
IMPORTANTAllvShieldRESTrequestsrequireauthorization.Youcanusethefollowingbasicauthorization:
Authorization: Basic YWRtaW46ZGVmYXVsdA==
YWRtaW46ZGVmYXVsdA==representstheBase64encodingofthevShieldManagerdefaultlogincredentials
(admin:default).
Vue de la page 50
1 2 ... 46 47 48 49 50 51 52 53 54 55 56 ... 89 90

Commentaires sur ces manuels

Pas de commentaire