VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual de usuario Pagina 15

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 30
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 14
VMware, Inc. 15
Chapter 2 Preparing for Installation
How Do I Isolate a Group of Virtual Machines?
YoucanusevShieldEdgewiththePortGroupIsolationfeatureorVLANstoisolatevirtualmachinesfromthe
externalnetwork.
1InstallPortGroupIsolationoneachESXhostthatavDSspans.
2 CreateaportgrouponthevDS.
3EnablePortGroupIsolationonthevDS.
4InstallavShieldEdgeonthe
portgroup.
5Movethevirtualmachinestotheportgroup.
6ConfigurevShieldEdgeNATrulesfortrafficinandoutoftheportgroup.
vShield Manager Uptime
ThevShieldManagershouldberunonanESXhostthatisnotaffectedbydowntime,suchasfrequentreboots
ormaintenancemodeoperations.YoucanuseHAorDRStoincreasetheresilienceofthevShieldManager.If
theESXhostonwhichthevShieldManagerresidesisexpectedto
requiredowntime,vMotionthevShield
ManagervirtualappliancetoanotherESXhost.Thus,morethanoneESXhostisrecommended.
Communication Between vShield Components
ThemanagementinterfacesofvShieldcomponentsshouldbeplacedinacommonnetwork,suchasthe
vSpheremanagementnetwork.ThevShieldManagerrequiresconnectivitytothevCenterServer,aswellas
allvShieldAppandvShieldEdgeinstances.vShieldcomponentscancommunicateoverroutedconnections
aswellasdifferentLANs.
Hardening Your vShield Virtual Machines
YoucanaccessthevShieldManagerandothervShieldcomponentsbyusingawebbaseduserinterface,
commandlineinterface,andRESTAPI.vShieldincludesdefaultlogincredentialsforeachoftheseaccess
options.AfterinstallationofeachvShieldvirtualmachine,youshouldhardenaccessbychangingthedefault
logincredentials.
vShield Manager User Interface
YouaccessthevShieldManageruserinterfacebyopeningawebbrowserwindowandnavigatingtotheIP
addressofthevShieldManagersmanagementport.Thedefaultuseraccount,admin,hasglobalaccesstothe
vShieldManager.Afterinitiallogin,youshouldchangethedefaultpasswordoftheadminuseraccount.
See
“ChangethePasswordofthevShieldManagerUserInterfaceDefaultAccount”onpage 20.
Command Line Interface
YoucanaccessthevShieldManager,vShieldApp,andvShieldEdgevirtualappliancesbyusingacommand
lineinterfaceviavSphereClientconsolesession.Eachvirtualapplianceusesthesamedefaultusername
(admin)andpassword(default)combinationasthevShieldManageruserinterface.EnteringEnabledmode
alsousesthe
passworddefault.
FormoreonhardeningtheCLI,seethevShieldAdministrationGuide.
NOTEYoucanalsouseVLANstoisolatevirtualmachinesprotectedbyavShieldEdge.Ifyouuse
VLANs,theinternalportgroupconnectedtoavShieldEdgemusthaveaVLANtagthatisdifferentfrom
theexternalportgroup.
NOTEThevShieldManagermustbeinthesamevCenterServerenvironmentasthevShieldcomponentsto
bemanaged.YoucannotusethevShieldManageracrossdifferentvCenterServerenvironments.
Vista de pagina 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 29 30

Comentarios a estos manuales

Sin comentarios