VMware, Inc.
59
11
vShield App is an interior, vNIC-level firewall that allows you to create access control policies regardless of
network topology. A vShield App monitors all traffic in and out of an ESX host, including between virtual
machines in the same port group. vShield App includes traffic analysis and container-based policy creation.
vShield App installs as a hypervisor module and firewall service virtual appliance. vShield App integrates
with ESX hosts through VMsafe APIs and works with VMware vSphere platform features such as DRS,
vMotion, DPM, and maintenance mode.
vShield App provides firewalling between virtual machines by placing a firewall filter on every virtual
network adapter. The firewall filter operates transparently and does not require network changes or
modification of IP addresses to create security zones. You can write access rules by using vCenter containers,
like datacenters, cluster, resource pools and vApps, or network objects, like Port Groups and VLANs, to
reduce the number of firewall rules and make the rules easier to track.
You can monitor the health of vShield App instances by using the vShield Manager user interface and by
sending vShield App system events to a syslog server.
This chapter includes the following topics:
“Send vShield App System Events to a Syslog Server”
on page 59
“Back Up the Running CLI Configuration of a vShield App”
on page 60
“View the Current System Status of a vShield App”
on page 60
Send vShield App System Events to a Syslog Server
You can send vShield App system events to a syslog server.
To send vShield App system events to a syslog server
1
Log in to the vShield Manager user interface.
2
Select a vShield App from the inventory panel.
3
Click the
Configuration
tab.
4
Click
Syslog Servers
.
5
Type the IP address of the syslog server.
6
From the
Log Level
drop-down menu, select the event level at and above which to send vShield App
events to the syslog server.
For example, if you select
Emergency
, then only emergency-level events are sent to the syslog server. If
you select
Critical
, then critical-, alert-, and emergency-level events are sent to the syslog server.
7
Click
Add
to save new settings. You send vShield App events to up to five syslog instances.
vShield App Management
11
Содержание VSHIELD APP 1.0.0 UPDATE 1 - API
Страница 9: ...VMware Inc 9 vShield Manager and vShield Zones...
Страница 10: ...vShield Administration Guide 10 VMware Inc...
Страница 14: ...vShield Administration Guide 14 VMware Inc...
Страница 18: ...vShield Administration Guide 18 VMware Inc...
Страница 24: ...vShield Administration Guide 24 VMware Inc...
Страница 34: ...vShield Administration Guide 34 VMware Inc...
Страница 42: ...vShield Administration Guide 42 VMware Inc...
Страница 46: ...vShield Administration Guide 46 VMware Inc...
Страница 47: ...VMware Inc 47 vShield Edge and Port Group Isolation...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 57: ...VMware Inc 57 vShield App and vShield Endpoint...
Страница 58: ...vShield Administration Guide 58 VMware Inc...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 68: ...vShield Administration Guide 68 VMware Inc...
Страница 78: ...vShield Administration Guide 78 VMware Inc...
Страница 85: ...VMware Inc 85 Appendixes...
Страница 86: ...vShield Administration Guide 86 VMware Inc...
Страница 130: ...vShield Administration Guide 130 VMware Inc...
Страница 144: ...vShield Administration Guide 144 VMware Inc...