VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Uživatelský manuál Strana 71

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 162
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 70
VMware, Inc. 71
13
vShieldAppprovidesfirewallprotectionthroughaccesspolicyenforcement.TheAppFirewalltabrepresents
thevShieldAppfirewallaccesscontrollist.
Thischapterincludesthefollowingtopics:
“UsingAppFirewallonpage 71
“CreateanAppFirewallRule”onpage 73
“CreateaLayer2/Layer3AppFirewallRule”onpage 75
“CreatingandProtectingSecurityGroups”onpage 75
“ValidatingActiveSessionsagainsttheCurrentAppFirewallRules”onpage 76
“ReverttoaPreviousAppFirewallConfiguration”onpage 77
“DeleteanAppFirewallRule”onpage 77
“UsingSpoofGuard”onpage 77
Using App Firewall
TheAppFirewallserviceisacentralized,hierarchicalfirewallforESXhosts.AppFirewallenablesyouto
createrulesthatallowordenyaccesstoandfromyourvirtualmachines.EachinstalledvShieldAppenforces
theAppFirewallrules.
YoucanmanageAppFirewallrulesatthedatacenter,cluster,andport
grouplevelstoprovideaconsistentset
ofrulesacrossmultiplevShieldAppinstancesunderthesecontainers.Asmembershipinthesecontainerscan
changedynamically,AppFirewallmaintainsthestateofexistingsessionswithoutrequiringreconfiguration
offirewallrules.Inthisway,AppFirewalleffectivelyhasacontinuousfootprintoneach
ESXhostunderthe
managedcontainers.
Securing Containers and Designing Security Groups
WhencreatingAppFirewallrules,youcancreaterulesbasedontraffictoorfromaspecificcontainerthat
encompassesalloftheresourceswithinthatcontainer.Forexample,youcancreatearuletodenyanytraffic
frominsideofaclusterthattargetsaspecificdestinationoutsideofthe
cluster.Youcancreatearuletodeny
anyincomingtrafficthatisnottaggedwithaVLANID.Whenyouspecifyacontainerasthesourceor
destination,allIPaddresseswithinthatcontainerareincludedintherule.
App Firewall Management
13
NOTEAppFirewallrulesapplytovShieldAppinstances,butnotvShieldEdgeorvShieldEndpointinstances.
TheZonesFirewalltabbecomestheAppFirewalltabwhenthevShieldApplicenseisactivated.
Zobrazit stránku 70
1 2 ... 66 67 68 69 70 71 72 73 74 75 76 ... 161 162

Komentáře k této Příručce

Žádné komentáře