![VMware VSHIELD APP 1.0 - Скачать руководство пользователя страница 27](http://html1.mh-extra.com/html/vmware/vshield-app-1-0/vshield-app-1-0_admin-manual_1043347027.webp)
VMware, Inc.
27
4
vShield
Zones
provides
firewall
protection
access
policy
enforcement.
Traffic
details
include
sources,
destinations,
direction
of
sessions,
applications,
and
ports
being
used.
Traffic
details
can
be
used
to
create
firewall
allow
or
deny
rules.
This
chapter
includes
the
following
topics:
“Using
Zones
Firewall”
on
page 27
“Create
a
Zones
Firewall
Rule”
on
page 29
“Create
a
Layer
2/Layer
3
Zones
Firewall
Rule”
on
page 30
“Validating
Active
Sessions
against
the
Current
Zones
Firewall
Rules”
on
page 31
“Revert
to
a
Previous
Zones
Firewall
Configuration”
on
page 31
“Delete
a
Zones
Firewall
Rule”
on
page 32
Using Zones Firewall
Zones
Firewall
is
a
centralized,
hierarchical
firewall
for
ESX
hosts.
Zones
Firewall
enables
you
to
create
rules
that
allow
or
deny
access
to
and
from
your
virtual
machines.
Each
installed
vShield
Zones
enforces
the
App
Zones
rules.
You
can
manage
Zones
Firewall
rules
at
the
datacenter,
cluster,
and
port
group
levels
to
provide
a
consistent
set
of
rules
across
multiple
vShield
Zones
instances
under
these
containers.
As
membership
in
these
containers
can
change
dynamically,
Zones
Firewall
maintains
the
state
of
existing
sessions
without
requiring
reconfiguration
of
firewall
rules.
In
this
way,
Zones
Firewall
effectively
has
a
continuous
footprint
on
each
ESX
host
under
the
managed
containers.
When
creating
Zones
Firewall
rules,
you
create
5
‐
tuple
firewall
rules
based
on
specific
source
and
destination
IP
addresses.
Zones Firewall Management
4
N
OTE
You
can
upgrade
vShield
Zones
to
vShield
App
by
obtaining
a
vShield
App
license.
vShield
App
enhances
vShield
Zones
protection
by
offering
Flow
Monitoring,
custom
container
creation
(Security
Groups),
and
container
‐
based
access
policy
creation
and
enforcement.
You
do
not
have
to
uninstall
vShield
Zones
to
install
vShield
App.
All
vShield
Zones
instances
become
vShield
App
instances,
the
Zones
Firewall
becomes
App
Firewall,
and
the
additional
vShield
App
features
are
enabled.
Содержание VSHIELD APP 1.0 -
Страница 11: ...VMware Inc 11 vShield Manager and vShield Zones...
Страница 12: ...vShield Administration Guide 12 VMware Inc...
Страница 16: ...vShield Administration Guide 16 VMware Inc...
Страница 20: ...vShield Administration Guide 20 VMware Inc...
Страница 26: ...vShield Administration Guide 26 VMware Inc...
Страница 36: ...vShield Administration Guide 36 VMware Inc...
Страница 44: ...vShield Administration Guide 44 VMware Inc...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 49: ...VMware Inc 49 vShield Edge and Port Group Isolation...
Страница 50: ...vShield Administration Guide 50 VMware Inc...
Страница 60: ...vShield Administration Guide 60 VMware Inc...
Страница 61: ...VMware Inc 61 vShield App and vShield Endpoint...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 66: ...vShield Administration Guide 66 VMware Inc...
Страница 72: ...vShield Administration Guide 72 VMware Inc...
Страница 80: ...vShield Administration Guide 80 VMware Inc...
Страница 87: ...VMware Inc 87 Appendixes...
Страница 88: ...vShield Administration Guide 88 VMware Inc...
Страница 132: ...vShield Administration Guide 132 VMware Inc...
Страница 146: ...vShield Administration Guide 146 VMware Inc...