
VMware, Inc. 15
Chapter 1 Overview of vShield
vShield Endpoint
vShieldEndpointdeliversanintrospection‐basedantivirussolution.vShieldEndpointusesthehypervisorto
scanguestvirtualmachinesfromtheoutsidewithoutabulkyagent.vShieldEndpointisefficientinavoiding
resourcebottleneckswhileoptimizingmemoryuse.
vShieldEndpointinstallsasahypervisormoduleandsecurityvirtualappliancefromathird‐
partyantivirus
vendor(VMwarepartners)onanESXhost.
vShieldEndpointprovidesthefollowingfeatures:
On‐demandfilescanninginaservicevirtualmachine.
On‐accessfilescanninginaservicevirtualmachine.
Migration of vShield Components
ThevShieldManagerandvShieldEdgevirtualappliancescanbeautomaticallyormanuallymigratedbased
onDRSandHApolicies.ThevShieldManagermustalwaysbeup,soyoumustmigratethevShieldManager
wheneverthecurrentESXhostundergoesarebootormaintenancemoderoutine.
EachvShieldEdgeshouldmove
withitssecuredportgrouptomaintainsecuritysettingsandservices.
vShieldAppandPortGroupIsolationservicescannotbemovedtoanotherESXhost.IftheESXhostonwhich
theseservicesresiderequiresamanualmaintenancemodeoperation,youmustde‐selecttheMovepowered
offandsuspendedvirtual
machinestootherhostsintheclustercheckboxtoensurethesevirtualappliances
arenotmigrated.TheseservicesrestartaftertheESXhostcomesonline.
VMware Tools
EachvShieldvirtualapplianceincludesVMwareTools.DonotupgradeoruninstalltheversionofVMware
ToolsincludedwithavShieldvirtualappliance.
Ports Required for vShield Communication
ThevShieldManagerrequiresthefollowingportstobeopen:
RESTAPI:80/TCPand443/TCP
GraphicalUserInterface:80/TCPto443/TCPandinitiatesconnectionstovSpherevCenterSDK.
SSHaccesstotheCLI(notenabledbydefault):22/TCP
N
OTEYoumustobtainanevaluationorfulllicensetousevShieldEndpoint.
Comentários a estes Manuais