
VMware, Inc. 59
6
YoucanconfigurevShieldAppfirewallrulesandsyslogservicebyusingRESTAPIcalls.
Thischapterincludesthefollowingtopics:
“ModifyingtheStateofaDatacenter”onpage 59
“ConfiguringFirewallRulesforvCenter”onpage 60
“ConfiguringthevShieldAppFirewall”onpage 60
“ConfiguringFail‐SafeModeforvShieldAppFirewall”onpage 70
“WorkingwithSpoofGuard”onpage 71
“WorkingwithNamespaces”onpage 72
“ExcludingVirtualMachinesfromvShieldAppProtection”onpage 77
“ConfiguringSyslogServiceforavShieldApp”onpage 78
“SynchronizingvShieldApp”onpage 78
“QueryingvShieldAppTechnicalSupportLog”onpage 79
“UpgradingvShieldApp”onpage 79
Modifying the State of a Datacenter
ThestateofadatacenterisdeterminedbytheversionofthevShieldManageronthatdatacenter.Fora5.0
vShieldManager,thedatacenterisintheregularstatewhichmeansonlythe5.0APIcallsaresupported.
WhenthevShieldManageronadatacenterisupgradedfromapreviousrelease,
thedatacenterisinthe
backwardCompatiblemodewhichmeansthatonlytheAPIsfromthepreviousreleasearesupported.When
thevShieldAppcomponentsonthatdatacenterareupgradedto5.0,thedatacenterstateisautomatically
changedfrombackwardCompatibletobackwardCompatibleReadyForSwitch.ThismeansthatthevShield
Appcomponentsarerunning
inbackwardcompatiblemode,soonlytheAPIsfromthepreviousreleaseare
supported.
WhenthedatacenterisinthebackwardCompatibleReadyForSwitchstate,youcanswitchthedatacenter
state.WhiledatafromtheoldvShieldAppisbeingmigratedtothe5.0vShieldApp,thedatacenterisinthe
migratingstate.Once
thedatamigrationiscomplete,thedatacenterstateswitchesautomaticallytoregular.
Retrieve Datacenter State
Youcanretrievethestateofthedatacenter.
vShield App Management
6
IMPORTANTAllvShieldRESTrequestsrequireauthorization.See“UsingthevShieldRESTAPI”onpage 15
fordetailsaboutbasicauthorization.
Komentáře k této Příručce