
VMware, Inc. 77
Chapter 13 App Firewall Management
Revert to a Previous App Firewall Configuration
ThevShieldManagersavesasnapshotofAppFirewallsettingseachtimeyoucommitanewrule.Clicking
CommitcausesthevShieldManagertosavethepreviousconfigurationwithatimestampbeforeaddingthe
newrule.ThesesnapshotsareavailablefromtheReverttoSnapshotdrop‐downlist.
To revert to a previous App Firewall configuration
1InthevSphere
Client,gotoInventory>HostsandClusters.
2 Selectadatacenterorclusterresourcefromtheinventorypanel.
3ClickthevShieldApptab.
4ClickAppFirewall.
5FromtheReverttoSnapshotdrop‐downlist,selectasnapshot.
Snapshotsarepresentedintheorderoftimestamps,withthemostrecentsnapshotlisted
atthetop.
6Viewsnapshotconfigurationdetails.
7Dooneofthefollowing:
Toreturntothecurrentconfiguration,selectthe‐optionfromtheReverttoSnapshotdrop‐downlist.
ClickCommittooverwritethecurrentconfigurationwiththesnapshotconfiguration.
Delete an App Firewall Rule
YoucandeleteanyAppFirewallruleyouhavecreated.YoucannotdeletetheanyrulesintheDefaultRules
sectionofthetable.
To delete an App Firewall rule
1ClickanexistingrowintheAppFirewalltable.
2ClickDelete.
3ClickCommit.
Using SpoofGuard
AftersynchronizingwiththevCenterServer,thevShieldManagercollectstheIPaddressesofallvCenter
guestvirtualmachinesfromVMwareToolsoneachvirtualmachine.UptovShield4.1,vShieldtrustedtheIP
addressprovidedbyVMwareToolsonavirtualmachine.However,ifavirtualmachinehasbeen
compromised,
theIPaddresscanbespoofedandmalicioustransmissionscanbypassfirewallpolicies.
SpoofGuardallowsyoutoauthorizetheIPaddressesreportedbyVMwareTools,andalterthemifnecessary
topreventspoofing.SpoofGuardinherentlytruststheMACaddressesofvirtualmachinescollectedfromthe
VMXfilesandvSphereSDK.
OperatingseparatelyfromtheAppFirewallrules,youcanuseSpoofGuardto
blocktrafficdeterminedtobespoofed.
Whenenabled,youcanuseSpoofGuardtomonitorandmanagetheIPaddressesreportedbyyourvirtual
machinesinoneofthefollowingmodes.
AutomaticallyTrustIPAssignmentsOnTheirFirstUse:Thismodeallowsalltrafficfromyourvirtual
machinestopasswhilebuildingatableofMAC‐to‐IPaddressassignments.Youcanreviewthistableat
yourconvenienceandmakeIPaddresschanges.
ManuallyInspectandApproveAllIPAssignmentsBeforeUse:Thismodeblocksalltrafficuntilyou
approveeachMAC‐to‐IPaddressassignment.
NOTESpoofGuardinherentlyallowsDHCPrequestsregardlessofenabledmode.However,ifinmanual
inspectionmode,trafficdoesnotpassuntiltheDHCP‐assignedIPaddresshasbeenapproved.
Commentaires sur ces manuels