VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Uživatelský manuál Strana 76

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 162
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 75
vShield Administration Guide
76 VMware, Inc.
5Doubleclicktherowandtypeanameforthegroup.
6ClickAdd.
Aftersecuritygroupcreationiscomplete,assignresourcestothegroup.
Assign Resources to a Security Group
Youcanassignvirtualmachinesandnetworkadapterstoasecuritygroup.TheseresourceshaveassociatedIP
addressesthatdefinethesourceordestinationparametersforwhichanAppFirewallruleenforcesanaccess
policy.
To assign resources to a security group
1ClickadatacenterresourcefromthevSphereClient.
2ClickthevShieldApptab.
3ClickSecurityGroups.
4Click
thearrownexttothenameofasecuritygrouptoexpandthedetailsofthegroup.
5 SelectavNICfromthedropdownlistandclickAdd.
TheselectedvNICappearsundervNICMembership.
RepeatthesestepsforeachvNICyouwanttoplaceinthissecuritygroup.
6ClickCommit.
Afterassigningresources,addthesecuritygrouptoafirewallruleasacontainer.See“CreateanApp
FirewallRule”onpage 73.
Validating Active Sessions against the Current App Firewall Rules
Bydefault,avShieldEdgematchesfirewallrulesagainsteachnewsession.Afterasessionhasbeen
established,anyfirewallrulechangesdonotaffectactivesessions.
TheCLIcommandvalidate sessionsenablesyoutovalidateactivesessionsthatareinviolationofthe
currentruleset.Youwouldusethisprocedure
forthefollowingscenarios:
Youupdatedthefirewallruleset.Afterafirewallrulesetupdate,youshouldvalidateactivesessionsto
purgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
YouviewedsessionsinFlowMonitoringanddeterminedthatanexistingorhistoricalflowrequiresanew
accessrule.Aftercreatingafirewallrulethatmatchestheoffendingsession,youshouldvalidateactive
sessionstopurgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
AftertheAppFirewall
updateiscomplete,issuethevalidate sessionscommandfromtheCLIofavShield
Apptopurgesessionsthatareinviolationofcurrentpolicy.
To validate active sessions against the current firewall rules
1 UpdateandcommittheAppFirew allrulesetattheappropriatecontainerlevel.
2OpenaconsolesessiononavShieldAppissuethevalidate sessionscommand.
vShieldApp> enable
Password:
vShieldApp# validate sessions
Zobrazit stránku 75
1 2 ... 71 72 73 74 75 76 77 78 79 80 81 ... 161 162

Komentáře k této Příručce

Žádné komentáře