VMware VSHIELD MANAGER 4.1 - API Manual de usuario Pagina 25

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 30
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 24
VMware, Inc. 25
Chapter 4 Installing vShield Edge, vShield App, and vShield Endpoint
10 ClickInstallatthetopoftheform.
YoucanfollowthevShieldAppinstallationstepsfromtheRecentTaskspaneofthevSphereClientscreen.
11 Afterinstallationofallcomponentsiscomplete,dothefollowing:
vShieldApp:Atthispoint,vShieldAppinstallationiscomplete.GotothevShieldApp>App
Firewalltabatthedatacenter,cluster,orportgroupcontainerleveltoconfigurefirewallrules.Each
vShieldAppinheritsglobalfirewallrulessetinthevShieldManager.Thedefaultfirewallruleset
allows
alltraffictopass.Youmustconfigureblockingrulestoexplicitlyblocktraffic.Toconfigure
AppFirewallrules,seethevShieldAdministrationGuide.
PortGroupIsolation:YoumustenablethePortGroupIsolationfeatureoneachvDS.After
enablementiscomplete,installavShieldEdgeoneachvDSportgroup.See“PrepareavNetworkfor
PortGroupIsolation”onpage 25.
vShieldEndpoint:Tocompleteinstallation,see“InstallingvShieldEndpoint”onpage 27.
Prepare a vNetwork for Port Group Isolation
PortGroupIsolationcreatesabarrierbetweenthevirtualmachinesprotectedbyavShieldEdgeandthe
externalnetwork.WhenyouenablePortGroupIsolationandinstallavShieldEdgeonavDSportgroup,you
isolateeachsecuredvDSportgroupfromtheexternalnetwork.WhenPortGroupIsolationis
enabled,traffic
isnotallowedaccesstothevirtualmachinesinthesecuredportgroupunlessNATrulesorVLANtagsare
configured.
TousePortGroupIsolation,youmustenablethisfeatureoneachvDSonwhichyouwillinstallavShieldEdge.
1EnablePortGroupIsolationoneachvDS.
2Install
avShieldEdgeoneachvDSportgroupyouplantosecure.
3MovethevirtualmachinestosecuredvDSportgroups.
AfterPortGroupIsolationisinstalledoneachESXhost,youmustenablePortGroupIsolationoneachvDS
whereyouwillinstallavShieldEdge.ThisallowsthePort
GroupIsolationservicetobeusedonanyport
groupinavDS.
To enable Port Group Isolation on a vDS
1LogintothevSphereClient.
2GotoView>Inventory>Networking.
3RightclickavDS.
4 SelectvShield>EnableIsolation.
AbrowserwindowopenstoconfirmthatPortGroupIsolationhasbeenenabled.
AfterPortGroupIsolation
installationiscomplete,installavShieldEdgeinstanceoneachvDSportgroup.
Install a vShield Edge
EachvShieldEdgevirtualappliancehasExternalandInternalnetworkinterfaces.TheInternalinterface
connectstothesecuredportgroupandactsasthegatewayforallprotectedvirtualmachinesintheportgroup.
ThesubnetassignedtotheInternalinterfacecanbeRFC1918private space.TheExternalinterfaceof
the
vShieldEdgeconnectstoanuplinkportgroupthathasaccesstoasharedcorporatenetworkoraservicethat
providesaccesslayernetworking.
EachvShieldEdgerequiresatleastoneIPaddresstonumbertheExternalinterface.MultipleexternalIP
addressescanbeconfiguredforLoadBalancer,Siteto
SiteVPN,andNATservices.TheInternalinterfacecan
haveaprivateIPaddressblockthatoverlapswithothervShieldEdgesecuredportgroups.
N
OTEPortGroupIsolationisanoptionalfeaturethatisnotrequiredforvShieldEdgeoperation.PortGroup
IsolationisavailableforvDSbasedvShieldEdgeinstallationsonly.
Vista de pagina 24
1 2 ... 20 21 22 23 24 25 26 27 28 29 30

Comentarios a estos manuales

Sin comentarios