VMware, Inc. 151
Appendix C Troubleshooting
Firewall Block Rule Not Blocking Matching Traffic
Problem
IconfiguredanAppFirewallruletoblockspecifictraffic.IusedFlowMonitoringtoviewtraffic,andthetraffic
Iwantedtoblockisbeingallowed.
Solution
Checktheorderingandscopeoftherule.Thisincludesthecontainerlevelatwhichtheruleisbeingenforced.
IssuesmightoccurwhenanIPaddress‐basedruleisconfiguredunderthewrongcontainer.
Checkwheretheaffectedvirtualmachineresides.IsthevirtualmachinebehindavShieldApp?If
not,then
thereisnoagenttoenforcetherule.Selectthevirtualmachineintheresourcetree.TheAppFirewalltabfor
thisvirtualmachinedisplaysalloftherulesthataffectthisvirtualmachine.
PlaceanyunprotectedvirtualmachinesontoavShield‐protectedswitchorprotectthevSwitchthat
thevirtual
machineisonbyinstallingavShield.
EnableloggingfortheAppFirewallruleinquestion.ThismightslownetworktrafficthroughthevShieldApp.
VerifyvShieldAppconnectivity.CheckforthevShieldAppbeingoutofsyncontheSystemStatuspage.Ifout
ofsync,clickForceSync
.Ifitisstillnotinsync,gototheSystemEventlogtodeterminethecause.
No Flow Data Displaying in Flow Monitoring
Problem
IhaveinstalledthevShieldManagerandavShieldApp.WhenIopenedtheFlowMonitoringtab,Ididnot
seeanydata.
Solution
Thismightbetheresultofoneormoreofthefollowingconditions.
YoudidnotallowenoughtimeforthevShieldApptomonitortrafficsessions.Allowafewminutesafter
vShieldAppinstallationtocollecttrafficdata.YoucanrequestdatacollectionbyclickingGetLateston
theFlowMonitoringtab.
TrafficisdestinedtovirtualmachinesthatarenotprotectedbyavShieldApp.Makesureyourvirtual
machinesareprotectedbyavShieldApp.Virtualmachinesmustbeinthesameportgroupasthe
vShield Appprotected(p0)port.
ThereisnotraffictothevirtualmachinesprotectedbyavShieldApp.
CheckthesystemstatusofeachvShieldAppforout‐of‐syncissues.
Troubleshooting Port Group Isolation Issues
Validate Installation of Port Group Isolation
To validate installation of Port Group Isolation
1MakesurethatthesameportgroupandvirtualmachinesarenotalsoconfiguredforvCloudService
DirectornetworkisolationorLabManagercross‐hostfencing.Doubleencapsulationmodeisnot
supportedcurrently.
2VerifythatthePortGroupIsolationbundleisinstalled:esxupdate query
3Verifythatvshdisrunning.
ESXi:ps | grep vsh.Theresultsmightcontainmorethanoneinstance,whichisok.
ESXClassic:ps –eaf | grep vshd
Comentarios a estos manuales