VMware, Inc. 51
Chapter 10 vShield Edge Management
5ClickAdd.
Anewrowappearsinthetable.
6Double‐clickeachcellintherowtoenterorselecttheappropriateinformation.
YoumusttypeIPaddressesintheSourceandDestinationfields.
7 (Optional)ClickLogtosendlogeventstoaspecifiedsyslogserverwhenthefirewallruleisviolated.
8 (Optional)SelectthenewrowandclickMoveUptomovetheruleupinpriority.
9ClickCommittosavetherule.
Validate Active Sessions Against Current vShield Edge Firewall Rules
Bydefault,avShieldEdgematchesfirewallrulesagainsteachnewsession.Afterasessionhasbeen
established,anyfirewallrulechangesdonotaffectactivesessions.
TheCLIcommandvalidate sessionsenablesyoutovalidateactivesessionsagainstthecurrentvShield
Edgefirewallrulesettopurgeanysessionsthatare
inviolationofthecurrentruleset.Afterafirewallruleset
update,youshouldvalidateactivesessionstopurgeanyexistingsessionsthatareinviolationoftheupdated
policy.
AfteravShieldEdgefirewallupdateiscomplete,issuethevalidate sessionscommandfromtheCLIofa
vShieldEdgeinstance
topurgesessionsthatareinviolationofcurrentpolicy.
To validate active sessions against the current firewall rules
1 UpdateandcommitthevShieldEdgefirewallruleset.
2OpenaconsolesessiononavShieldEdgeinstancetoissuethevalidate sessionscommand.
vShieldEdge> validate sessions
Manage NAT Rules
ThevShieldEdgeprovidesnetworkaddresstranslation(NAT)servicetoprotecttheIPaddressesofinternal,
privatenetworksfromthepublicnetwork.YoumustconfigureNATrulestoprovideaccesstoservices
runningonprivatelyaddressedvirtualmachines.
TheNATserviceconfigurationisseparatedintoSNATandDNATrules.AnSNAT
ruletranslatesaprivate
internalIPaddressintoapublicIPaddressforoutboundtraffic.ADNATrulemapsapublicIPaddresstoa
privateinternalIPaddress.
To configure an SNAT rule for a vShield Edge
1IntothevSphereClient,gotoInventory>Networking.
2 SelectanInternalportgroupwhereavShieldEdgehasbeen
installed.
3ClickthevShieldEdgetab.
4ClicktheNATlink.
5UnderDirectionOUT(SNAT),clickAdd.
Anewrowappearsinthetable.
6Double‐clickeachcellintherowtoentertheappropriateinformation.
7ClickCommittosavetherule.
Comentarios a estos manuales