vShield Administration Guide
76
VMware, Inc.
SpoofGuard Screen Options
The SpoofGuard screen displays the following options.
Enable SpoofGuard
You must enable SpoofGuard per datacenter to manage IP address assignments.
To enable SpoofGuard
1
In the vShield Manager user interface, go to the
Hosts and Clusters
view.
2
Select a datacenter resource from the resource tree.
3
Click the
SpoofGuard
tab.
4
Click
Edit
to the right side of the Global Status heading.
5
For
IP Assignment Tracking
, click
Enabled
.
6
For
Operation Mode
, select one of the following:
Automatically Trust IP Assignments on Their First Use
: Select this option to trust all IP assignments
upon initial registration with the vShield Manager.
Manually Inspect and Approve All IP Assignments Before Use
: Select this option to require manual
approval of all IP addresses. All traffic to and from unapproved IP addresses is blocked.
7
Click
Ok
.
Approve IP Addresses
If you set SpoofGuard to require manual approval of all IP address assignments, you must approve IP address
assignments to allow traffic from those virtual machines to pass.
To approve an IP address
1
In the vShield Manager user interface, go to the
Hosts and Clusters
view.
2
Select a datacenter resource from the resource tree.
3
Click the
SpoofGuard
tab.
4
Click the
Require Approval
or
Duplicate IP assignments
link.
Table 13-1.
SpoofGuard Screen Options
Option
Description
Global Status
Status of SpoofGuard as either enabled or disabled
Inactive
List of IP addresses where the current IP address does not match the published
IP address.
Active Since Last Published
List of IP addresses that have been validated since the policy was last updated
Unpublished IP assignment changes
List of virtual machines for which you have edited the IP address assignment
but have not yet published
Require Approval
IP address changes that require approval before traffic can flow to or from these
virtual machines
Duplicate IP assignments
IP addresses that are duplicates of an existing assigned IP address within the
selected datacenter
I
MPORTANT
You must upgrade all vShield App instances to vShield App 1.0.0 Update 1 or later before you
enable SpoofGuard.
Содержание VSHIELD APP 1.0.0 UPDATE 1 - API
Страница 9: ...VMware Inc 9 vShield Manager and vShield Zones...
Страница 10: ...vShield Administration Guide 10 VMware Inc...
Страница 14: ...vShield Administration Guide 14 VMware Inc...
Страница 18: ...vShield Administration Guide 18 VMware Inc...
Страница 24: ...vShield Administration Guide 24 VMware Inc...
Страница 34: ...vShield Administration Guide 34 VMware Inc...
Страница 42: ...vShield Administration Guide 42 VMware Inc...
Страница 46: ...vShield Administration Guide 46 VMware Inc...
Страница 47: ...VMware Inc 47 vShield Edge and Port Group Isolation...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 57: ...VMware Inc 57 vShield App and vShield Endpoint...
Страница 58: ...vShield Administration Guide 58 VMware Inc...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 68: ...vShield Administration Guide 68 VMware Inc...
Страница 78: ...vShield Administration Guide 78 VMware Inc...
Страница 85: ...VMware Inc 85 Appendixes...
Страница 86: ...vShield Administration Guide 86 VMware Inc...
Страница 130: ...vShield Administration Guide 130 VMware Inc...
Страница 144: ...vShield Administration Guide 144 VMware Inc...