
VMware, Inc. 75
Chapter 13 App Firewall Management
Create a Layer 2/Layer 3 App Firewall Rule
TheLayer2/Layer3firewallenablesconfigurationofallowordenyrulesforcommonDataLinkLayerand
NetworkLayerrequests,suchasICMPpingsandtraceroutes.YoucanchangethedefaultLayer2/Layer3rules
fromallowtodenybasedonyournetworksecuritypolicy.
Layer2/Layer3firewallrules
allowordenytrafficbasedonthefollowingcriteria:
To create a Layer 2/Layer 3 firewall rule
1InthevSphereClient,gotoInventory>HostsandClusters.
2 Selectadatacenterresourcefromtheresourcetree.
3ClickthevShieldApptab.
4ClickAppFirewall.
5ClickL2/L3Rules.
6ClickAdd.
Anewrowisaddedatthebottomofthe
DataCenterRulessectionofthetable.
7Double‐clickeachcellinthenewrowtotypeorselecttheappropriateinformation.
YoucantypeIPaddressesintheSourceandDestinationfields
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommit.
Creating and Protecting Security Groups
TheSecurityGroupsfeatureenablesyoutocreatecustomcontainerstowhichyoucanassignresources,such
asvirtualmachinesandnetworkadapters,forAppFirewallprotection.Afterasecuritygroupisdefined,you
addthesecuritygrouptoafirewallruleforprotection.
Add a Security Group
InthevSphereClient,youcanaddasecuritygroupatthedatacenterresourcelevel.
To add a security group by using the vSphere Client
1ClickadatacenterresourcefromthevSphereClient.
2ClickthevShieldApptab.
3ClickSecurityGroups.
4ClickAddGroup.
Criteria Description
Source(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)from
whichthecommunicationoriginated
Destination(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)which
thecommunicationistargeting
Protocol Transportprotocolusedforcommunication
NOTELayer2/Layer3firewallrulescanalsobecreatedfromtheFlowMonitoringreport.See“A d d anApp
FirewallRulefromtheFlowMonitoringReport”onpage 67.
Commentaires sur ces manuels