![VMware VSHIELD APP 1.0.0 UPDATE 1 - API Скачать руководство пользователя страница 25](http://html1.mh-extra.com/html/vmware/vshield-app-1-0-0-update-1-api/vshield-app-1-0-0-update-1-api_admin-manual_1043350025.webp)
VMware, Inc.
25
4
vShield Zones provides firewall protection access policy enforcement. Traffic details include sources,
destinations, direction of sessions, applications, and ports being used. Traffic details can be used to create
firewall allow or deny rules.
This chapter includes the following topics:
“Using Zones Firewall”
on page 25
“Create a Zones Firewall Rule”
on page 27
“Create a Layer 2/Layer 3 Zones Firewall Rule”
on page 28
“Validating Active Sessions against the Current Zones Firewall Rules”
on page 29
“Revert to a Previous Zones Firewall Configuration”
on page 29
“Delete a Zones Firewall Rule”
on page 30
Using Zones Firewall
Zones Firewall is a centralized, hierarchical firewall for ESX hosts. Zones Firewall enables you to create rules
that allow or deny access to and from your virtual machines. Each installed vShield Zones enforces the App
Zones rules.
You can manage Zones Firewall rules at the datacenter, cluster, and port group levels to provide a consistent
set of rules across multiple vShield Zones instances under these containers. As membership in these containers
can change dynamically, Zones Firewall maintains the state of existing sessions without requiring
reconfiguration of firewall rules. In this way, Zones Firewall effectively has a continuous footprint on each ESX
host under the managed containers.
When creating Zones Firewall rules, you create 5-tuple firewall rules based on specific source and destination IP
addresses.
Zones Firewall Management
4
N
OTE
You can upgrade vShield Zones to vShield App by obtaining a vShield App license. vShield App
enhances vShield Zones protection by offering Flow Monitoring, custom container creation (Security Groups),
and container-based access policy creation and enforcement.
You do not have to uninstall vShield Zones to install vShield App. All vShield Zones instances become vShield
App instances, the Zones Firewall becomes App Firewall, and the additional vShield App features are enabled.
Содержание VSHIELD APP 1.0.0 UPDATE 1 - API
Страница 9: ...VMware Inc 9 vShield Manager and vShield Zones...
Страница 10: ...vShield Administration Guide 10 VMware Inc...
Страница 14: ...vShield Administration Guide 14 VMware Inc...
Страница 18: ...vShield Administration Guide 18 VMware Inc...
Страница 24: ...vShield Administration Guide 24 VMware Inc...
Страница 34: ...vShield Administration Guide 34 VMware Inc...
Страница 42: ...vShield Administration Guide 42 VMware Inc...
Страница 46: ...vShield Administration Guide 46 VMware Inc...
Страница 47: ...VMware Inc 47 vShield Edge and Port Group Isolation...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 57: ...VMware Inc 57 vShield App and vShield Endpoint...
Страница 58: ...vShield Administration Guide 58 VMware Inc...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 68: ...vShield Administration Guide 68 VMware Inc...
Страница 78: ...vShield Administration Guide 78 VMware Inc...
Страница 85: ...VMware Inc 85 Appendixes...
Страница 86: ...vShield Administration Guide 86 VMware Inc...
Страница 130: ...vShield Administration Guide 130 VMware Inc...
Страница 144: ...vShield Administration Guide 144 VMware Inc...