VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Uživatelský manuál Strana 28

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 90
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 27
vShield API Programming Guide
28 VMware, Inc.
Managing NAT
ThevShieldEdgeprovidesnetworkaddresstranslation(NAT)servicetoprotecttheIPaddressesofinternal,
privatenetworksfromthepublicnetwork.YoucanconfigureNATrulestoprovideaccesstoservicesrunning
onprivatelyaddressedvirtualmachines.TheNATserviceconfigurationisseparatedintoSNAT(Secure
NetworkAddressTranslation)and
DNAT(DestinationNetworkAddressTranslation)rules.
AllSNATand DNATrulesconfiguredbyusingRESTrequests appearunderthevShieldEdge>NATtabfor
theappropriatevShieldEdgeinthevShieldMana geruserinte rf a c eandvSphereClientplugin.
FortheNATschema,see“NATSchema”onpage 77.
Managing SNAT Rules
ThevShieldEdgeusesSNATtomapinternaladdressestoallocatedpublicaddresses.IfyouusePortGroup
Isolation,youmustconfigureSNATrulestoallowtrafficfromtheinternalnetworktotheexternalnetwork.
Get the SNAT Rule Set
Example 5-13. Get the SNAT rule set on a vShield Edge
Request:
GET <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/snat/rules
Example:
GET /api/1.0/network/network-244/snat/rules HTTP/1.1
Authorization: Basic YWRtaW46ZGVmYXVsdA==
Host: localhost
Post an SNAT Rule Set
YoucanpostanSNATrulesetforavShieldEdgeviaREST.ThevShieldManagerprocessesthepostedXML
fileasacompleterulesetforthespecificvShieldEdge.Thecurrentrulesetisreplacedwiththisnewsetof
rules.
Example 5-14. Post an SNAT Rule Set on a vShield Edge
Request:
POST <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/snat/rules
<VShieldEdgeConfig>
<NATConfig>
<NATRule>
<externalIpAddress>
<ipAddress>IpOrAny</ipAddress>
or
<IpRange>
<rangeStart>ip_address</rangeStart>
<rangeEnd>ip_address</rangeEnd>
</IpRange>
</externalIpAddress>
<internalIpAddress>
<ipAddress>IpOrAny</ipAddress>
or
<IpRange>
<rangeStart>ip_address</rangeStart>
<rangeEnd>ip_address</rangeEnd>
</IpRange>
Zobrazit stránku 27
1 2 ... 23 24 25 26 27 28 29 30 31 32 33 ... 89 90

Komentáře k této Příručce

Žádné komentáře