VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Uživatelský manuál Strana 72

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 162
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 71
vShield Administration Guide
72 VMware, Inc.
AsecuritygroupisatrustzonethatyoucreateandassignresourcestoforAppFirewallprotection.Security
groupsarecontainers,likeavApporacluster.Securitygroupsenablesyoutocreateacontainerbyassigning
resourcesarbitrarily,suchasvirtualmachinesandnetworkadapters.Afterthesecuritygroup
isdefined,you
addthegroupasacontainerinthesourceordestinationfieldofanAppFirewallrule.See“Creatingand
ProtectingSecurityGroups”onpage 75.
Default Rules
Bydefault,theAppFirewallenforcesasetofrulesallowingtraffictopassthroughallvShieldAppinstances.
TheserulesappearintheDefaultRulessectionoftheAppFirewalltable.Thedefaultrulescannotbedeleted
oraddedto.However,youcanchangetheActionelementofeachrule
fromAllowtoDeny.
Layer 4 Rules and Layer 2/Layer 3 Rules
TheAppFirewalltabofferstwosetsofconfigurablerules:L4(Layer4)rulesandL2/L3(Layer2/Layer3)rules.
LayersrefertolayersoftheOpenSystemsInterconnection(OSI)ReferenceModel.
Layer4rulesgovernTCPandUDPtransportofLayer7,orapplicationspecific,traffic.Layer2/Layer3rules
monitortrafficfromICMP,ARP,andotherLayer2andLayer3protocols.YoucanconfigureLayer2/Layer 3
rulesatthedatacenterlevelonly.Bydefault,allLayer4andLayer2/Layer3trafficisallowedtopass.
Hierarchy of App Firewall Rules
EachvShieldAppenforcesAppFirewa llrulesintoptobottomordering.AvShieldAppcheckseachtraffic
sessionagainstthetopruleintheAppFirewalltablebeforemovingdownthesubsequentrulesinthetable.
Thefirstruleinthetablethatmatchesthetrafficparametersisenforced.
The
rulesareenforcedinthefollowinghierarchy:
1 DataCenterHighPrecedenceRules
2 ClusterLevelRules
3 DataCenterLowPrecedenceRules(seenasRulesbelowthislevelhavelowerprecedencethancluster
levelruleswhenadatacenterresourceisselected)
4 SecurePortGroupRules
5 DefaultRules
AppFirewallofferscontainerleveland
custompriorityprecedenceconfigurations:
Containerlevelprecedencereferstorecognizingthedatacenterlev elasbeinghigherinprioritythanthe
clusterlevel.Whenaruleisconfiguredatthedatacenterlevel,theruleisinheritedbyallclustersand
vShieldagentstherein.AclusterlevelruleisonlyappliedtothevShieldAppwithinthe
cluster.
Custompriorityprecedencereferstotheoptionofassigninghighorlowprecedencetorulesatthe
datacenterlevel.Highprecedencerulesworkasnotedinthecontainerlevelprecedencedescription.Low
precedencerulesincludetheDefaultRulesandtheconfigurationofDataCenterLowPrecedencerules.
Thisflexibilityallowsyou
torecognizemultiplelayersofappliedprecedence.
Attheclusterlevel,youconfigurerulesthatapplytoallvShieldAppinstanceswithinthecluster.Because
DataCenterHighPrecedenceRulesareaboveClusterLevelRules,ensureyourClusterLevelRulesare
notinconflictwithDataCenterHighPrecedenceRules.
Planning App Firewall Rule Enforcement
UsingAppFirewall,youcanconfigureallowanddenyrulesbasedonyournetworkpolicy.Thefollowing
examplesrepresenttwocommonfirewallpolicies:
Allowalltrafficbydefault.YoukeepthedefaultallowallrulesandadddenyrulesbasedonFlow
MonitoringdataormanualAppFirewallruleconfiguration.Inthisscenario,ifasessiondoesnotmatch
anyofthedenyrules,thevShieldAppallowsthetraffictopass.
Zobrazit stránku 71
1 2 ... 67 68 69 70 71 72 73 74 75 76 77 ... 161 162

Komentáře k této Příručce

Žádné komentáře