vShield Administration Guide
28 VMware, Inc.
Default Rules
Bydefault,ZonesFirewallenforcesasetofrulesallowingtraffictopassthroughallvShieldZonesinstances.
TheserulesappearintheDefaultRulessectionoftheZonesFirewalltable.Thedefaultrulescannotbedeleted
oraddedto.However,youcanchangetheActionelementofeachrulefrom
AllowtoDeny.
Layer 4 Rules and Layer 2/Layer 3 Rules
ZonesFirew allofferstwosetsofconfigurablerules:L4(Layer4)rulesandL2/L3(Layer2/Layer3)rules.Layers
refertolayersoftheOpenSystemsInterconnection(OSI)ReferenceModel.
Layer4rulesgovernTCPandUDPtransportofLayer7,orapplication‐specific,traffic.Layer2/Layer3rules
monitortraffic
fromICMP,ARP,andotherLayer2andLayer3protocols.YoucanconfigureLayer2/Layer 3
rulesatthedatacenterlevelonly.Bydefault,allLayer4andLayer2/Layer3trafficisallowedtopass.
Hierarchy of Zones Firewall Rules
EachvShieldZonesinstanceenforcesZonesFirewallrulesintop‐to‐bottomordering.AvShieldZones
instancecheckseachtrafficsessionagainstthetopruleintheZonesFirewalltablebeforemovingdownthe
subsequentrulesinthetable.Thefirstruleinthetablethatmatchesthetrafficparametersis
enforced.
ZonesFirewallrulesareenforcedinthefollowinghierarchy:
1 DataCenterHighPrecedenceRules
2 ClusterLevelRules
3 DataCenterLowPrecedenceRules(seenasRulesbelowthislevelhavelowerprecedencethancluster
levelruleswhenadatacenterresourceisselected)
4 SecurePortGroupRules
5 DefaultRules
ZonesFirewalloffers
container‐levelandcustompriorityprecedenceconfigurations:
Container‐levelprecedencereferstorecognizingthedatacenterlev elasbeinghigherinprioritythanthe
clusterlevel.Whenaruleisconfiguredatthedatacenterlevel,theruleisinheritedbyallclustersand
vShieldagentstherein.Acluster‐levelruleisonlyappliedtothevShieldZonesinstanceswithin
the
cluster.
Custompriorityprecedencereferstotheoptionofassigninghighorlowprecedencetorulesatthe
datacenterlevel.Highprecedencerulesworkasnotedinthecontainer‐levelprecedencedescription.Low
precedencerulesincludetheDefaultRulesandtheconfigurationofDataCenterLowPrecedencerules.
Thisflexibilityallowsyou
torecognizemultiplelayersofappliedprecedence.
Attheclusterlevel,youconfigurerulesthatapplytoallvShieldZonesinstanceswithinthecluster.
BecauseDataCenterHighPrecedenceRulesareaboveClusterLevelRules,ensureyourClusterLevel
RulesarenotinconflictwithDataCenterHighPrecedenceRules.
Planning Zones Firewall Rule Enforcement
UsingZonesFirewall,youcanconfigureallowanddenyrulesbasedonyournetworkpolicy.Thefollowing
examplesrepresenttwocommonfirewallpolicies:
Allowalltrafficbydefault.YoukeepthedefaultallowallrulesandadddenyrulesbasedonFlow
MonitoringdataormanualAppFirewallconfiguration.Inthisscenario,ifasessiondoesnotmatchany
ofthedenyrules,thevShieldAppallowsthetraffictopass.
Denyalltrafficbydefault.YoucanchangetheActionstatusofthedefaultrulesfromAllowtoDeny,and
addallowrulesexplicitlyforspecificsystemsandapplications.Inthisscenario,ifasessiondoesnot
matchanyoftheallowrules,thevShieldAppdropsthesessionbeforeit
reachesitsdestination.Ifyou
changeallofthedefaultrulestodenyanytraffic,thevShieldAppdropsallincomingandoutgoingtraffic.
Comentarios a estos manuales