VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 151

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 150
VMware, Inc. 151
Appendix C Troubleshooting
Firewall Block Rule Not Blocking Matching Traffic
Problem
IconfiguredanAppFirewallruletoblockspecifictraffic.IusedFlowMonitoringtoviewtraffic,andthetraffic
Iwantedtoblockisbeingallowed.
Solution
Checktheorderingandscopeoftherule.Thisincludesthecontainerlevelatwhichtheruleisbeingenforced.
IssuesmightoccurwhenanIPaddressbasedruleisconfiguredunderthewrongcontainer.
Checkwheretheaffectedvirtualmachineresides.IsthevirtualmachinebehindavShieldApp?If
not,then
thereisnoagenttoenforcetherule.Selectthevirtualmachineintheresourcetree.TheAppFirewalltabfor
thisvirtualmachinedisplaysalloftherulesthataffectthisvirtualmachine.
PlaceanyunprotectedvirtualmachinesontoavShieldprotectedswitchorprotectthevSwitchthat
thevirtual
machineisonbyinstallingavShield.
EnableloggingfortheAppFirewallruleinquestion.ThismightslownetworktrafficthroughthevShieldApp.
VerifyvShieldAppconnectivity.CheckforthevShieldAppbeingoutofsyncontheSystemStatuspage.Ifout
ofsync,clickForceSync
.Ifitisstillnotinsync,gototheSystemEventlogtodeterminethecause.
No Flow Data Displaying in Flow Monitoring
Problem
IhaveinstalledthevShieldManagerandavShieldApp.WhenIopenedtheFlowMonitoringtab,Ididnot
seeanydata.
Solution
Thismightbetheresultofoneormoreofthefollowingconditions.
YoudidnotallowenoughtimeforthevShieldApptomonitortrafficsessions.Allowafewminutesafter
vShieldAppinstallationtocollecttrafficdata.YoucanrequestdatacollectionbyclickingGetLateston
theFlowMonitoringtab.
TrafficisdestinedtovirtualmachinesthatarenotprotectedbyavShieldApp.Makesureyourvirtual
machinesareprotectedbyavShieldApp.Virtualmachinesmustbeinthesameportgroupasthe
vShield Appprotected(p0)port.
ThereisnotraffictothevirtualmachinesprotectedbyavShieldApp.
CheckthesystemstatusofeachvShieldAppforoutofsyncissues.
Troubleshooting Port Group Isolation Issues
Validate Installation of Port Group Isolation
To validate installation of Port Group Isolation
1MakesurethatthesameportgroupandvirtualmachinesarenotalsoconfiguredforvCloudService
DirectornetworkisolationorLabManagercrosshostfencing.Doubleencapsulationmodeisnot
supportedcurrently.
2VerifythatthePortGroupIsolationbundleisinstalled:esxupdate query
3Verifythatvshdisrunning.
ESXi:ps | grep vsh.Theresultsmightcontainmorethanoneinstance,whichisok.
ESXClassic:ps –eaf | grep vshd
Vue de la page 150
1 2 ... 146 147 148 149 150 151 152 153 154 155 156 ... 161 162

Commentaires sur ces manuels

Pas de commentaire