
vShield Administration Guide
78 VMware, Inc.
SpoofGuard Screen Options
TheSpoofGuardscreendisplaysthefollowingoptions.
Enable SpoofGuard
YoumustenableSpoofGuardperdatacentertomanageIPaddressassignments.
To enable SpoofGuard
1InthevShieldManageruserinterface,gototheHostsandClustersview.
2 Selectadatacenterresourcefromtheresourcetree.
3ClicktheSpoofGuardtab.
4ClickEdittotherightsideoftheGlobalStatusheading.
5ForIPAssignmentTracking,click
Enabled.
6ForOperationMode,selectoneofthefollowing:
AutomaticallyTrustIPAssignmentsonTheirFirstUse:SelectthisoptiontotrustallIPassignments
uponinitialregistrationwiththevShieldManager.
ManuallyInspectandApproveAllIPAssignmentsBeforeUse:Selectthisoptiontorequiremanual
approvalofallIPaddresses.AlltraffictoandfromunapprovedIPaddressesisblocked.
7ClickOk.
Approve IP Addresses
IfyousetSpoofGuardtorequiremanualapprovalofallIPaddressassignments,youmustapproveIPaddress
assignmentstoallowtrafficfromthosevirtualmachinestopass.
To approve an IP address
1InthevShieldManageruserinterface,gototheHostsandClustersview.
2 Selectadatacenterresourcefromtheresourcetree.
3ClicktheSpoofGuard
tab.
4ClicktheRequireApprovalorDuplicateIPassignmentslink.
Table 13-1. SpoofGuard Screen Options
Option Description
GlobalStatus StatusofSpoofGuardaseitherenabledordisabled
Inactive ListofIPaddresseswherethecurrentIPaddressdoesnotmatchthepublished
IPaddress.
ActiveSinceLastPublished ListofIPaddressesthathavebeenvalidatedsincethepolicywaslastupdated
UnpublishedIPassignmentchanges Listofvirtualmachinesforwhichyou
haveeditedtheIPaddressassignment
buthavenotyetpublished
RequireApproval IPaddresschangesthatrequireapprovalbeforetrafficcanflowtoorfromthese
virtualmachines
DuplicateIPassignments IPaddressesthatareduplicatesofanexistingassignedIPaddresswithinthe
selecteddatacenter
IMPORTANTYoumustupgradeallvShieldAppinstancestovShieldApp1.0.0Update1orlaterbeforeyou
enableSpoofGuard.
Commentaires sur ces manuels