
VMware, Inc. 27
4
vShieldZonesprovidesfirewallprotectionaccesspolicyenforcement.Trafficdetailsincludesources,
destinations,directionofsessions,applications,andportsbeingused.Trafficdetailscanbeusedtocreate
firewallallowordenyrules.
Thischapterincludesthefollowingtopics:
“UsingZonesFirewall”onpage 27
“CreateaZonesFirewallRule”onpage 29
“CreateaLayer2/Layer3ZonesFirewallRule”onpage 30
“ValidatingActiveSessionsagainsttheCurrentZonesFirewallRules”onpage 31
“ReverttoaPreviousZonesFirewallConfiguration”onpage 31
“DeleteaZonesFirewallRule”onpage 32
Using Zones Firewall
ZonesFirewallisacentralized,hierarchicalfirewallforESXhosts.ZonesFirewallenablesyoutocreaterules
thatallowordenyaccesstoandfromyourvirtualmachines.EachinstalledvShieldZonesenforcestheApp
Zonesrules.
YoucanmanageZonesFirew allrulesatthedatacenter,cluster,andportgrouplevels
toprovideaconsistent
setofrulesacrossmultiplevShieldZonesinstancesunderthesecontainers.Asmembershipinthesecontainers
canchangedynamically,ZonesFirewallmaintainsthestateofexistingsessionswithoutrequiring
reconfigurationoffirewallrules.Inthisway,ZonesFirewalleffectivelyhasacontinuousfootprintoneachESX
host
underthemanagedcontainers.
WhencreatingZonesFirewallrules,youcreate5‐tuplefirewallrulesbasedonspecificsourceanddestinationIP
addresses.
Zones Firewall Management
4
NOTEYoucanupgradevShieldZonestovShieldAppbyobtainingavShieldApplicense.vShieldApp
enhancesvShieldZonesprotectionbyofferingFlowMonitoring,customcontainercreation(SecurityGroups),
andcontainer‐basedaccesspolicycreationandenforcement.
YoudonothavetouninstallvShieldZonestoinstallvShieldApp.All
vShieldZonesinstancesbecomevShield
Appinstances,theZonesFirewallbecomesAppFirewall,andtheadditionalvShieldAppfeaturesareenabled.
Commentaires sur ces manuels