VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 51

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 50
VMware, Inc. 51
Chapter 10 vShield Edge Management
5ClickAdd.
Anewrowappearsinthetable.
6Doubleclickeachcellintherowtoenterorselecttheappropriateinformation.
YoumusttypeIPaddressesintheSourceandDestinationfields.
7 (Optional)ClickLogtosendlogeventstoaspecifiedsyslogserverwhenthefirewallruleisviolated.
8 (Optional)SelectthenewrowandclickMoveUptomovetheruleupinpriority.
9ClickCommittosavetherule.
Validate Active Sessions Against Current vShield Edge Firewall Rules
Bydefault,avShieldEdgematchesfirewallrulesagainsteachnewsession.Afterasessionhasbeen
established,anyfirewallrulechangesdonotaffectactivesessions.
TheCLIcommandvalidate sessionsenablesyoutovalidateactivesessionsagainstthecurrentvShield
Edgefirewallrulesettopurgeanysessionsthatare
inviolationofthecurrentruleset.Afterafirewallruleset
update,youshouldvalidateactivesessionstopurgeanyexistingsessionsthatareinviolationoftheupdated
policy.
AfteravShieldEdgefirewallupdateiscomplete,issuethevalidate sessionscommandfromtheCLIofa
vShieldEdgeinstance
topurgesessionsthatareinviolationofcurrentpolicy.
To validate active sessions against the current firewall rules
1 UpdateandcommitthevShieldEdgefirewallruleset.
2OpenaconsolesessiononavShieldEdgeinstancetoissuethevalidate sessionscommand.
vShieldEdge> validate sessions
Manage NAT Rules
ThevShieldEdgeprovidesnetworkaddresstranslation(NAT)servicetoprotecttheIPaddressesofinternal,
privatenetworksfromthepublicnetwork.YoumustconfigureNATrulestoprovideaccesstoservices
runningonprivatelyaddressedvirtualmachines.
TheNATserviceconfigurationisseparatedintoSNATandDNATrules.AnSNAT
ruletranslatesaprivate
internalIPaddressintoapublicIPaddressforoutboundtraffic.ADNATrulemapsapublicIPaddresstoa
privateinternalIPaddress.
To configure an SNAT rule for a vShield Edge
1IntothevSphereClient,gotoInventory>Networking.
2 SelectanInternalportgroupwhereavShieldEdgehasbeen
installed.
3ClickthevShieldEdgetab.
4ClicktheNATlink.
5UnderDirectionOUT(SNAT),clickAdd.
Anewrowappearsinthetable.
6Doubleclickeachcellintherowtoentertheappropriateinformation.
7ClickCommittosavetherule.
Vue de la page 50
1 2 ... 46 47 48 49 50 51 52 53 54 55 56 ... 161 162

Commentaires sur ces manuels

Pas de commentaire