VMware VSHIELD MANAGER 4.1 - API Uživatelský manuál Strana 11

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 30
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 10
VMware, Inc. 11
Chapter 1 Introduction to vShield
Protecting Virtual Machines in a Cluster
InFigure 13,vShieldAppinstancesareinstalledoneachESXhostinacluster.Virtualmachinesareprotected
whenmovedviavMotion™orDRSbetweenESXhostsinthecluster.EachvAppsharesandmaintainsstate
ofalltransmissions.
Figure 1-3. vShield App Instances Installed on Each ESX Host in a Cluster
Common Deployments of vShield Edge
YoucanuseavShieldEdgewiththePortGroupIsolationfeaturetoisolateastubnetwork,usingNATtoallow
trafficinandoutofthenetwork.Ifyoudeployinternalstubnetworks,youcanusevShieldEdgetosecure
communicationbetweennetworksbyusingLANtoLANencryptionvia
VPNtunnels.
vShieldEdgecanbedeployedasaselfserviceapplicationwithinVMwareCloudDirector.
Common Deployments of vShield App
YoucanusevShieldApptocreatesecurityzoneswithinavDC.YoucanimposefirewallpoliciesonvCenter
containersorSecurityGroups,whicharecustomcontainersyoucancreatebyusingthevShieldManageruser
interface.Containerbasedpoliciesenableyoutocreatemixedtrustzonesclusterswithoutrequiring
an
externalphysicalfirewall.
InadeploymentthatdoesnotusevDCs,useavShieldAppwiththeSecurityGroupsfeaturetocreatetrust
zonesandenforceaccesspolicies.
ServiceProviderAdminscanusevShieldApptoimposebroadfirewallpoliciesacrossallguestvirtual
machinesinaninternalnetwork.Forexample,
youcanimposeafirewallpolicyonthesecondvNICofallguest
virtualmachinesthatallowsthevirtualmachinestoconnecttoastorageserver,butblocksthevirtual
machinesfromaddressinganyothervirtualmachines.
Unprotected Cluster
Protected Cluster
Zobrazit stránku 10
1 2 ... 6 7 8 9 10 11 12 13 14 15 16 ... 29 30

Komentáře k této Příručce

Žádné komentáře