
VMware, Inc. 53
6
YoucanconfigurevShieldAppfirewallrulesandsyslogservicebyusingRESTAPIcalls.
Thischapterincludesthefollowingtopics:
“ModifyingtheStateofaDatacenter”onpage 53
“ConfiguringFirewallRulesforvCenter”onpage 54
“ConfiguringthevShieldAppFirewall”onpage 54
“WorkingwithSpoofGuard”onpage 56
“WorkingwithNamespaces”onpage 57
“ConfiguringSyslogServiceforavShieldApp”onpage 58
“UpgradingvShieldApp”onpage 59
Modifying the State of a Datacenter
ThestateofadatacenterisdeterminedbytheversionofthevShieldManageronthatdatacenter.Fora5.0
vShieldManager,thedatacenterisintheregularstatewhichmeansonlythe5.0APIcallsaresupported.
WhenthevShieldManageronadatacenterisupgradedfromapreviousrelease,
thedatacenterisinthe
backwardCompatiblemodewhichmeansthatonlytheAPIsfromthepreviousreleasearesupported.When
thevShieldAppcomponentsonthatdatacenterareupgradedto5.0,thedatacenterstateisautomatically
changedfrombackwardCompatibletobackwardCompatibleReadyForSwitch.ThismeansthatthevShield
Appcomponentsarerunning
inbackwardcompatiblemode,soonlytheAPIsfromthepreviousreleaseare
supported.
WhenthedatacenterisinthebackwardCompatibleReadyForSwitchstate,youcanswitchthedatacenter
statetomigrating.Inthemigratingstate,datafromtheoldvShieldAppismigratedtothe5.0vShieldApp.
Oncethedatamigration
iscomplete,thedatacenterstateswitchesautomaticallytoregular.
Retrieve Datacenter State
Youcanretrievethestateofthedatacenter.
Example 6-1. Retrieve the datacenter state
Example:
GET https://<vsm-ip>/api/2.0/app/firewall/datacenter-2/state
vShield App Management
6
IMPORTANTAllvShieldRESTrequestsrequireauthorization.See“UsingthevShieldRESTAPI”onpage 12
fordetailsaboutbasicauthorization.
Komentáře k této Příručce