
VMware, Inc. 13
1
VMware
®
vShieldisasuiteofsecurityvirtualappliancesbuiltforVMwarevCenter™ServerandVmware
ESX™integration.vShieldisacriticalsecuritycomponentforprotectingvirtualizeddatacentersfromattacks
andmisusehelpingyouachieveyourcompliance‐mandatedgoals.
ThisguideassumesyouhaveadministratoraccesstotheentirevShieldsystem.The
viewableresourcesinthe
vShieldManageruserinterfacecandifferbasedontheassignedroleandrightsofauser,andlicensing.Ifyou
areunabletoaccessascreenorperformaparticulartask,consultyourvShieldadministrator.
Thischapterincludesthefollowingtopics:
“vShieldComponents”onpage 13
“MigrationofvShieldComponents”onpage 15
“VMwareTools”onpage 15
“PortsRequiredforvShieldCommunication”onpage 15
vShield Components
vShieldincludescomponentsandservicesessentialforprotectingvirtualmachines.vShieldcanbeconfigured
throughaweb‐baseduserinterface,avSphereClientplug‐in,acommandlineinterface(CLI),andRESTAPI.
TorunvShield,youneedonevShieldManagervirtualmachineandatleastonevShieldApporvShield
Edge
module.
vShield Manager
ThevShieldManageristhecentralizednetworkmanagementcomponentofvShieldandisinstalledfromOVA
asavirtualmachinebyusingthevSphereClient.UsingthevShieldManageruserinterface,administrators
install,configure,andmaintainvShieldcomponents.AvShieldManagercanrunonadifferentESXhostfrom
yourvShield
AppandvShieldEdgemodules.
ThevShieldManagerleveragestheVMwareInfrastructureSDKtodisplayacopyofthevSphereClient
inventorypanel.
FormoreontheusingthevShieldManageruserinterface,seeChapter 2,“vShieldManagerUserInterface
Basics,”onpage 17.
vShield Zones
vShieldZones,includedwiththevShieldManager,providesfirewallprotectionfortrafficbetweenvirtual
machines.ForeachZonesFirewallrule,youcanspecifythesourceIP,destinationIP,sourceport,destination
port,andservice.
Overview of vShield
1
CAUTIONDonotinstallvShieldZones/AppontheESXhostwherevCenterServerisrunning.
Comentarios a estos manuales