
VMware, Inc. 9
1
VMware
®
vShield™isasuiteofnetworkedgeandapplication‐awarefirewallsbuiltforVMwarevCenter™
Serverintegration.vShieldinspectsclient‐servercommunicationsandinter‐virtual‐machinecommunication
toprovidedetailedtrafficanalyticsandapplication‐awarefirewallprotection.vShieldisacriticalsecurity
componentforprotectingvirtualizeddatacentersfromattacksand
misusehelpingyouachieveyour
compliance‐mandatedgoals.
ThisguideassumesyouhaveadministratoraccesstotheentirevShieldsystem.Ifyouareunabletoaccessa
screenorperformaparticulartask,consultyourvShieldadministrator.
Thischapterincludesthefollowingtopics:
“vShieldComponents”onpage 9
“PortsRequiredforvShield”onpage 10
“A n IntroductiontoRESTAPIforvShieldUsers”onpage 10
vShield Components
vShieldincludescomponentsandservicesessentialforprotectingvirtualmachines.vShieldcanbeconfigured
throughaweb‐baseduserinterface,acommandlineinterface(CLI),andRESTAPI.
TorunvShield,youneedonevShieldManagervirtualmachineandatleastonevShieldZones,vShieldApp,
orvShieldEdgevirtualmachine.
vShield Manager
ThevShieldManageristhecentralizedmanagementcomponentofvShieldandisinstalledfromOVAasa
virtualmachinebyusingthevSphereClient.UsingthevShieldManageruserinterfaceorvSphereClient
plug‐in,administratorscaninstall,configure,andmaintainvShieldcomponents.
ThevShieldManagervirtualmachinecanrunon
adifferentESXhostfromyourvShieldAppandvShield
Edgevirtualmachines.
ThevShieldManageruserinterfaceleveragestheVMwareInfrastructureSDKtodisplayacopyofthevSphere
Clientinventorypanel.
FormoreontheusingthevShieldManageruserinterface,seethevShieldAdministrationGuide.
vShield App
AvShieldAppmonitorsalltrafficintoandoutofanESXhost,andbetweenvirtualmachinesonthehost.
vShieldAppprovidesapplication‐awaretrafficanalysisandstatefulfirewallprotection.vShieldApp
regulatestrafficbasedonasetofrules,similartoanaccesscontrollist(ACL).
Overview of VMware vShield
1
Commentaires sur ces manuels