VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual de usuario Pagina 14

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 162
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 13
vShield Administration Guide
14 VMware, Inc.
vShield Edge
vShieldEdgeprovidesnetworkedgesecurityandgatewayservicestoisolatethevirtualmachinesinaport
group,vDSportgroup,orCisco
®
Nexus1000V.ThevShieldEdgeconnectsisolated,stubnetworkstoshared
(uplink)networksbyprovidingcommongatewayservicessuchasDHCP,VPN,NAT,andLoadBalancing.
CommondeploymentsofvShieldEdgeincludeintheDMZ,VPNExtranets,andmultitenantCloud
environmentswherethevShieldEdgeprovidesperimetersecurityfor
VirtualDatacenters(VDCs).
Standard vShield Edge Services (Including Cloud Director)
Firewall:SupportedrulesincludeIP5tupleconfigurationwithIPandportrangesforstatefulinspection
forTCP,UDP,andICMP.
NetworkAddressTranslation:SeparatecontrolsforSourceandDestinationIPaddresses,aswellasTCP
andUDPporttranslation.
DynamicHostConfigurationProtocol(DHCP):ConfigurationofIPpools,gateways,DNSservers,and
searchdomains.
Advanced vShield Edge Services
SitetoSiteVirtualPrivateNetwork(VPN):UsesstandardizedIPsecprotocolsettingstointeroperatewith
allmajorfirewallvendors.
LoadBalancing:SimpleanddynamicallyconfigurablevirtualIPaddressesandservergroups.
vShieldEdgesupportssyslogexportforallservicestoremoteservers.
vShield App
vShieldAppisaninterior,vNIClevelfirewallthatallowsyoutocreateaccesscontrolpoliciesregardlessof
networktopology.AvShieldAppmonitorsalltrafficinandoutofanESXhost,includingbetweenvirtual
machinesinthesameportgroup.vShieldAppincludestrafficanalysisandcontainerbasedpolicy
creation.
vShieldAppinstallsasahypervisormoduleandfirewallservicevirtualappliance.vShieldAppintegrates
withESXhoststhroughVMsafeAPIsandworkswithVMwarevSphereplatformfeaturessuchasDRS,
vMotion,DPM,andmaintenancemode.
vShieldAppprovidesfirewallingbetweenvirtualmachinesbyplacingafirewallfilteronevery
virtual
networkadapter.Thefirewallfilteroperatestransparentlyanddoesnotrequirenetw orkchangesor
modificationofIPaddressestocreatesecurityzones.YoucanwriteaccessrulesbyusingvCentercontainers,
likedatacenters,cluster,resourcepoolsandvApps,ornetworkobjects,likePortGroupsandVLANs,to
reducethenumber
offirewallrulesandmaketheruleseasiertotrack.
YoushouldinstallvShieldAppinstancesonallESXhostswithinaclustersothatVMwarevMotion™
operationsworkandvirtualmachinesremainprotectedastheymigratebetweenESXhosts.Bydefault,a
vShieldAppvirtualappliancecannotbemovedby
usingvMotion.
TheFlowMonitoringfeaturedisplaysallowedandblockednetworkflowsattheapplicationprotocollevel.
Youcanusethisinformationtoauditnetworktrafficandtroubleshootoperational.
N
OTEYoumustobtainanevaluationorfulllicensetousevShieldEdge.
NOTEYoumustobtainanevaluationorfulllicensetousevShieldApp.
CAUTIONDonotinstallvShieldZones/AppontheESXhostwherevCenterServerisrunning.
Vista de pagina 13
1 2 ... 9 10 11 12 13 14 15 16 17 18 19 ... 161 162

Comentarios a estos manuales

Sin comentarios