VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 71

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 70
VMware, Inc. 71
13
vShieldAppprovidesfirewallprotectionthroughaccesspolicyenforcement.TheAppFirewalltabrepresents
thevShieldAppfirewallaccesscontrollist.
Thischapterincludesthefollowingtopics:
“UsingAppFirewallonpage 71
“CreateanAppFirewallRule”onpage 73
“CreateaLayer2/Layer3AppFirewallRule”onpage 75
“CreatingandProtectingSecurityGroups”onpage 75
“ValidatingActiveSessionsagainsttheCurrentAppFirewallRules”onpage 76
“ReverttoaPreviousAppFirewallConfiguration”onpage 77
“DeleteanAppFirewallRule”onpage 77
“UsingSpoofGuard”onpage 77
Using App Firewall
TheAppFirewallserviceisacentralized,hierarchicalfirewallforESXhosts.AppFirewallenablesyouto
createrulesthatallowordenyaccesstoandfromyourvirtualmachines.EachinstalledvShieldAppenforces
theAppFirewallrules.
YoucanmanageAppFirewallrulesatthedatacenter,cluster,andport
grouplevelstoprovideaconsistentset
ofrulesacrossmultiplevShieldAppinstancesunderthesecontainers.Asmembershipinthesecontainerscan
changedynamically,AppFirewallmaintainsthestateofexistingsessionswithoutrequiringreconfiguration
offirewallrules.Inthisway,AppFirewalleffectivelyhasacontinuousfootprintoneach
ESXhostunderthe
managedcontainers.
Securing Containers and Designing Security Groups
WhencreatingAppFirewallrules,youcancreaterulesbasedontraffictoorfromaspecificcontainerthat
encompassesalloftheresourceswithinthatcontainer.Forexample,youcancreatearuletodenyanytraffic
frominsideofaclusterthattargetsaspecificdestinationoutsideofthe
cluster.Youcancreatearuletodeny
anyincomingtrafficthatisnottaggedwithaVLANID.Whenyouspecifyacontainerasthesourceor
destination,allIPaddresseswithinthatcontainerareincludedintherule.
App Firewall Management
13
NOTEAppFirewallrulesapplytovShieldAppinstances,butnotvShieldEdgeorvShieldEndpointinstances.
TheZonesFirewalltabbecomestheAppFirewalltabwhenthevShieldApplicenseisactivated.
Vue de la page 70
1 2 ... 66 67 68 69 70 71 72 73 74 75 76 ... 161 162

Commentaires sur ces manuels

Pas de commentaire