VMware, Inc.
53
Chapter 10 vShield Edge Management
5
Click
Add
.
A
new
row
appears
in
the
table.
6
Double
‐
click
each
cell
in
the
row
to
enter
or
select
the
appropriate
information.
You
must
type
IP
addresses
in
the
Source
and
Destination
fields.
7
(Optional)
Click
Log
to
send
log
events
to
a
specified
syslog
server
when
the
firewall
rule
is
violated.
8
(Optional)
Select
the
new
row
and
click
Move
Up
to
move
the
rule
up
in
priority.
9
Click
Commit
to
save
the
rule.
Validate Active Sessions Against Current vShield Edge Firewall Rules
By
default,
a
vShield
Edge
matches
firewall
rules
against
each
new
session.
After
a
session
has
been
established,
any
firewall
rule
changes
do
not
affect
active
sessions.
The
CLI
command
validate sessions
enables
you
to
validate
active
sessions
against
the
current
vShield
Edge
firewall
rule
set
to
purge
any
sessions
that
are
in
violation
of
the
current
rule
set.
After
a
firewall
rule
set
update,
you
should
validate
active
sessions
to
purge
any
existing
sessions
that
are
in
violation
of
the
updated
policy.
After
a
vShield
Edge
firewall
update
is
complete,
issue
the
validate sessions
command
from
the
CLI
of
a
vShield
Edge
instance
to
purge
sessions
that
are
in
violation
of
current
policy.
To validate active sessions against the current firewall rules
1
Update
and
commit
the
vShield
Edge
firewall
rule
set.
2
Open
a
console
session
on
a
vShield
Edge
instance
to
issue
the
validate sessions
command.
vShieldEdge> validate sessions
Manage NAT Rules
The
vShield
Edge
provides
network
address
translation
(NAT)
service
to
protect
the
IP
addresses
of
internal,
private
networks
from
the
public
network.
You
must
configure
NAT
rules
to
provide
access
to
services
running
on
privately
addressed
virtual
machines.
The
NAT
service
configuration
is
separated
into
SNAT
and
DNAT
rules.
An
SNAT
rule
translates
a
private
internal
IP
address
into
a
public
IP
address
for
outbound
traffic.
A
DNAT
rule
maps
a
public
IP
address
to
a
private
internal
IP
address.
NAT
rules
adhere
to
the
following
criteria:
Criteria
Description
Original
(Internal)
Source
IP/Range
SNAT
only.
Internal
IP
address
or
IP
address
range
of
protected
virtual
machines.
To
enter
an
IP
address
range,
use
a
hyphen.
For
example,
192.168.10.1
‐
192.168.10.5.
Translated
(External)
Source
IP/Range
SNAT
only.
External
IP
address
or
IP
address
range
used
to
masquerade
internal
addressing
of
protected
virtual
machines.
To
enter
an
IP
address
range,
use
a
hyphen.
For
example,
192.168.10.1
‐
192.168.10.5.
Translated
(Internal)
Destination
IP/Range
and
Port/Range
DNAT
only.
Internal
IP
address
or
IP
address
range
of
protected
virtual
machines.
To
enter
an
IP
address
range,
use
a
hyphen.
For
example,
192.168.10.1
‐
192.168.10.5.
Original
(External)
Destination
IP/Range
and
Port/Range
DNAT
only.
External
IP
address
or
IP
address
range
used
to
masquerade
internal
addressing
of
protected
virtual
machines.
To
enter
an
IP
address
range,
use
a
hyphen.
For
example,
192.168.10.1
‐
192.168.10.5.
Protocol
DNAT
only.
Transport
protocol
used
for
communication.
Log
Select
the
check
box
to
send
NAT
events
to
a
configured
syslog
server.
Содержание VSHIELD APP 1.0 -
Страница 11: ...VMware Inc 11 vShield Manager and vShield Zones...
Страница 12: ...vShield Administration Guide 12 VMware Inc...
Страница 16: ...vShield Administration Guide 16 VMware Inc...
Страница 20: ...vShield Administration Guide 20 VMware Inc...
Страница 26: ...vShield Administration Guide 26 VMware Inc...
Страница 36: ...vShield Administration Guide 36 VMware Inc...
Страница 44: ...vShield Administration Guide 44 VMware Inc...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 49: ...VMware Inc 49 vShield Edge and Port Group Isolation...
Страница 50: ...vShield Administration Guide 50 VMware Inc...
Страница 60: ...vShield Administration Guide 60 VMware Inc...
Страница 61: ...VMware Inc 61 vShield App and vShield Endpoint...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 66: ...vShield Administration Guide 66 VMware Inc...
Страница 72: ...vShield Administration Guide 72 VMware Inc...
Страница 80: ...vShield Administration Guide 80 VMware Inc...
Страница 87: ...VMware Inc 87 Appendixes...
Страница 88: ...vShield Administration Guide 88 VMware Inc...
Страница 132: ...vShield Administration Guide 132 VMware Inc...
Страница 146: ...vShield Administration Guide 146 VMware Inc...