VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manuel d'utilisateur Page 76

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 162
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 75
vShield Administration Guide
76 VMware, Inc.
5Doubleclicktherowandtypeanameforthegroup.
6ClickAdd.
Aftersecuritygroupcreationiscomplete,assignresourcestothegroup.
Assign Resources to a Security Group
Youcanassignvirtualmachinesandnetworkadapterstoasecuritygroup.TheseresourceshaveassociatedIP
addressesthatdefinethesourceordestinationparametersforwhichanAppFirewallruleenforcesanaccess
policy.
To assign resources to a security group
1ClickadatacenterresourcefromthevSphereClient.
2ClickthevShieldApptab.
3ClickSecurityGroups.
4Click
thearrownexttothenameofasecuritygrouptoexpandthedetailsofthegroup.
5 SelectavNICfromthedropdownlistandclickAdd.
TheselectedvNICappearsundervNICMembership.
RepeatthesestepsforeachvNICyouwanttoplaceinthissecuritygroup.
6ClickCommit.
Afterassigningresources,addthesecuritygrouptoafirewallruleasacontainer.See“CreateanApp
FirewallRule”onpage 73.
Validating Active Sessions against the Current App Firewall Rules
Bydefault,avShieldEdgematchesfirewallrulesagainsteachnewsession.Afterasessionhasbeen
established,anyfirewallrulechangesdonotaffectactivesessions.
TheCLIcommandvalidate sessionsenablesyoutovalidateactivesessionsthatareinviolationofthe
currentruleset.Youwouldusethisprocedure
forthefollowingscenarios:
Youupdatedthefirewallruleset.Afterafirewallrulesetupdate,youshouldvalidateactivesessionsto
purgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
YouviewedsessionsinFlowMonitoringanddeterminedthatanexistingorhistoricalflowrequiresanew
accessrule.Aftercreatingafirewallrulethatmatchestheoffendingsession,youshouldvalidateactive
sessionstopurgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
AftertheAppFirewall
updateiscomplete,issuethevalidate sessionscommandfromtheCLIofavShield
Apptopurgesessionsthatareinviolationofcurrentpolicy.
To validate active sessions against the current firewall rules
1 UpdateandcommittheAppFirew allrulesetattheappropriatecontainerlevel.
2OpenaconsolesessiononavShieldAppissuethevalidate sessionscommand.
vShieldApp> enable
Password:
vShieldApp# validate sessions
Vue de la page 75
1 2 ... 71 72 73 74 75 76 77 78 79 80 81 ... 161 162

Commentaires sur ces manuels

Pas de commentaire