VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual do Utilizador Página 14

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 13
vShield Administration Guide
14 VMware, Inc.
vShield Edge
vShieldEdgeprovidesnetworkedgesecurityandgatewayservicestoisolatethevirtualmachinesinaport
group,vDSportgroup,orCisco
®
Nexus1000V.ThevShieldEdgeconnectsisolated,stubnetworkstoshared
(uplink)networksbyprovidingcommongatewayservicessuchasDHCP,VPN,NAT,andLoadBalancing.
CommondeploymentsofvShieldEdgeincludeintheDMZ,VPNExtranets,andmultitenantCloud
environmentswherethevShieldEdgeprovidesperimetersecurityfor
VirtualDatacenters(VDCs).
Standard vShield Edge Services (Including Cloud Director)
Firewall:SupportedrulesincludeIP5tupleconfigurationwithIPandportrangesforstatefulinspection
forTCP,UDP,andICMP.
NetworkAddressTranslation:SeparatecontrolsforSourceandDestinationIPaddresses,aswellasTCP
andUDPporttranslation.
DynamicHostConfigurationProtocol(DHCP):ConfigurationofIPpools,gateways,DNSservers,and
searchdomains.
Advanced vShield Edge Services
SitetoSiteVirtualPrivateNetwork(VPN):UsesstandardizedIPsecprotocolsettingstointeroperatewith
allmajorfirewallvendors.
LoadBalancing:SimpleanddynamicallyconfigurablevirtualIPaddressesandservergroups.
vShieldEdgesupportssyslogexportforallservicestoremoteservers.
vShield App
vShieldAppisaninterior,vNIClevelfirewallthatallowsyoutocreateaccesscontrolpoliciesregardlessof
networktopology.AvShieldAppmonitorsalltrafficinandoutofanESXhost,includingbetweenvirtual
machinesinthesameportgroup.vShieldAppincludestrafficanalysisandcontainerbasedpolicy
creation.
vShieldAppinstallsasahypervisormoduleandfirewallservicevirtualappliance.vShieldAppintegrates
withESXhoststhroughVMsafeAPIsandworkswithVMwarevSphereplatformfeaturessuchasDRS,
vMotion,DPM,andmaintenancemode.
vShieldAppprovidesfirewallingbetweenvirtualmachinesbyplacingafirewallfilteronevery
virtual
networkadapter.Thefirewallfilteroperatestransparentlyanddoesnotrequirenetw orkchangesor
modificationofIPaddressestocreatesecurityzones.YoucanwriteaccessrulesbyusingvCentercontainers,
likedatacenters,cluster,resourcepoolsandvApps,ornetworkobjects,likePortGroupsandVLANs,to
reducethenumber
offirewallrulesandmaketheruleseasiertotrack.
YoushouldinstallvShieldAppinstancesonallESXhostswithinaclustersothatVMwarevMotion™
operationsworkandvirtualmachinesremainprotectedastheymigratebetweenESXhosts.Bydefault,a
vShieldAppvirtualappliancecannotbemovedby
usingvMotion.
TheFlowMonitoringfeaturedisplaysallowedandblockednetworkflowsattheapplicationprotocollevel.
Youcanusethisinformationtoauditnetworktrafficandtroubleshootoperational.
N
OTEYoumustobtainanevaluationorfulllicensetousevShieldEdge.
NOTEYoumustobtainanevaluationorfulllicensetousevShieldApp.
CAUTIONDonotinstallvShieldZones/AppontheESXhostwherevCenterServerisrunning.
Vista de página 13
1 2 ... 9 10 11 12 13 14 15 16 17 18 19 ... 161 162

Comentários a estes Manuais

Sem comentários