VMware, Inc.
31
Chapter 4 Zones Firewall Management
7
Double
‐
click
each
cell
in
the
new
row
to
type
or
select
the
appropriate
information.
You
can
type
IP
addresses
in
the
Source
and
Destination
fields
8
(Optional)
Select
the
Log
check
box
to
log
all
sessions
matching
this
rule.
9
Click
Commit
.
Validating Active Sessions against the Current Zones Firewall Rules
By
default,
a
vShield
Zones
instance
matches
firewall
rules
against
each
new
session.
After
a
session
has
been
established,
any
firewall
rule
changes
do
not
affect
active
sessions.
The
CLI
command
validate sessions
enables
you
to
validate
active
sessions
against
the
current
Zones
Firewall
rule
set
to
purge
any
sessions
that
are
in
violation
of
the
current
rule
set.
After
a
firewall
rule
set
update,
you
should
validate
active
sessions
to
purge
any
existing
sessions
that
are
in
violation
of
the
updated
policy.
After
the
Zones
Firewall
update
is
complete,
issue
the
validate sessions
command
from
the
CLI
of
a
vShield
Zones
instance
to
purge
sessions
that
are
in
violation
of
current
policy.
To validate active sessions against the current firewall rules
1
Update
and
commit
the
Zones
Firewall
rule
set
at
the
appropriate
container
level.
2
Open
a
console
session
on
a
vShield
Zones
instance
issue
the
validate sessions
command.
vShieldZones> enable
Password:
vShieldZones# validate sessions
Revert to a Previous Zones Firewall Configuration
The
vShield
Manager
saves
a
snapshot
of
App
Firewall
settings
each
time
you
commit
a
new
rule.
Clicking
Commit
causes
the
vShield
Manager
to
save
the
previous
configuration
with
a
timestamp
before
adding
the
new
rule.
These
snapshots
are
available
from
the
Revert
to
Snapshot
drop
‐
down
menu.
To revert to a previous App Firewall configuration
1
In
the
vSphere
Client,
go
to
Inventory
>
Hosts
and
Clusters
.
2
Select
a
datacenter
or
cluster
resource
from
the
inventory
panel.
3
Click
the
vShield
Zones
tab.
4
Click
Zones
Firewall
.
5
From
the
Revert
to
Snapshot
drop
‐
down
list,
select
a
snapshot.
Snapshots
are
presented
in
the
order
of
timestamps,
with
the
most
recent
snapshot
listed
at
the
top.
6
View
snapshot
configuration
details.
7
Do
one
of
the
following:
To
return
to
the
current
configuration,
select
the
‐
option
from
the
Revert
to
Snapshot
drop
‐
down
list.
Click
Commit
to
overwrite
the
current
configuration
with
the
snapshot
configuration.
Содержание VSHIELD APP 1.0 -
Страница 11: ...VMware Inc 11 vShield Manager and vShield Zones...
Страница 12: ...vShield Administration Guide 12 VMware Inc...
Страница 16: ...vShield Administration Guide 16 VMware Inc...
Страница 20: ...vShield Administration Guide 20 VMware Inc...
Страница 26: ...vShield Administration Guide 26 VMware Inc...
Страница 36: ...vShield Administration Guide 36 VMware Inc...
Страница 44: ...vShield Administration Guide 44 VMware Inc...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 49: ...VMware Inc 49 vShield Edge and Port Group Isolation...
Страница 50: ...vShield Administration Guide 50 VMware Inc...
Страница 60: ...vShield Administration Guide 60 VMware Inc...
Страница 61: ...VMware Inc 61 vShield App and vShield Endpoint...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 66: ...vShield Administration Guide 66 VMware Inc...
Страница 72: ...vShield Administration Guide 72 VMware Inc...
Страница 80: ...vShield Administration Guide 80 VMware Inc...
Страница 87: ...VMware Inc 87 Appendixes...
Страница 88: ...vShield Administration Guide 88 VMware Inc...
Страница 132: ...vShield Administration Guide 132 VMware Inc...
Страница 146: ...vShield Administration Guide 146 VMware Inc...