VMware, Inc. 407
Chapter 19 Setting and Using Policies and Customizing VMware Player
To add or edit a network zone
1Inthepolicyeditor,selectNetworkAccessanddooneofthefollowing:
Toaddazone,clickAddZoneandclicktheNewZoneentrythatappearsin
thetable.
Toeditazone,clickthenameofthezoneintheZonescolumnofthetable.
2CompletethefieldsinthezoneeditorthatappearsandclickOK.
Using the Ruleset Editor to Configure Host and Guest Access
EachaccesssettingforanACEinstance’shostmachineandfortheACEinstance’sguest
systemisbasedonasetofaccessrules.WheneveryouusetheNetworkAccesswizard,
adefaultrulesetisusedforhostandguestnetworkaccess.Youcanusetheruleset
editortochangethepa
rametersofthoserules.
NetworkaccesspoliciesareappliedbyfilteringontheIPaddress,theprotocolnumber
fromtheIPheader,thedirectionoftraffic,andTCPandUDPportvalues.Thefiltering
doesnotinvolvedeeppacketinspection.ForDNSandDHCPaccess,theTCPandUDP
portsonwhichthoseserv
icestraditionallyresideareopened.
Considerthefollowingaspectsofthefilteringactions:
Ifyoumoveyourservicestodifferentports,thenetworkaccessrulesforthose
servicesnolongerwork.
Thehostorinstanceisopentoalltrafficontheseprotocolsandports.
TounderstandtheparticularsofhowtrafficisbeingblockedorallowedforDNS,
DHCP,andICMPprotocolsandports,seetherulesdisplayedintheruleseteditor.
Add or Edit Rulesets and Rules for Network Access
Therulesintheruleseteditorarelistedintheorderinwhichtheyaretobeevaluated.
Whenanetworktrafficpacketarrivesoristobesentfromthehostorguest,itis
comparedwitheachruleintheruleset,inorderfromthetopdown.Ifthefollow
ing
packetsetting
smatchtheruleconditions,thepacketisallowedorblockedaccordingto
therule’saction:
Sourceaddressforincomingpackets
Destinationaddressforoutgoingpackets,protocol,andports
Comentarios a estos manuales