VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual do Utilizador Página 151

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 150
VMware, Inc. 151
Appendix C Troubleshooting
Firewall Block Rule Not Blocking Matching Traffic
Problem
IconfiguredanAppFirewallruletoblockspecifictraffic.IusedFlowMonitoringtoviewtraffic,andthetraffic
Iwantedtoblockisbeingallowed.
Solution
Checktheorderingandscopeoftherule.Thisincludesthecontainerlevelatwhichtheruleisbeingenforced.
IssuesmightoccurwhenanIPaddressbasedruleisconfiguredunderthewrongcontainer.
Checkwheretheaffectedvirtualmachineresides.IsthevirtualmachinebehindavShieldApp?If
not,then
thereisnoagenttoenforcetherule.Selectthevirtualmachineintheresourcetree.TheAppFirewalltabfor
thisvirtualmachinedisplaysalloftherulesthataffectthisvirtualmachine.
PlaceanyunprotectedvirtualmachinesontoavShieldprotectedswitchorprotectthevSwitchthat
thevirtual
machineisonbyinstallingavShield.
EnableloggingfortheAppFirewallruleinquestion.ThismightslownetworktrafficthroughthevShieldApp.
VerifyvShieldAppconnectivity.CheckforthevShieldAppbeingoutofsyncontheSystemStatuspage.Ifout
ofsync,clickForceSync
.Ifitisstillnotinsync,gototheSystemEventlogtodeterminethecause.
No Flow Data Displaying in Flow Monitoring
Problem
IhaveinstalledthevShieldManagerandavShieldApp.WhenIopenedtheFlowMonitoringtab,Ididnot
seeanydata.
Solution
Thismightbetheresultofoneormoreofthefollowingconditions.
YoudidnotallowenoughtimeforthevShieldApptomonitortrafficsessions.Allowafewminutesafter
vShieldAppinstallationtocollecttrafficdata.YoucanrequestdatacollectionbyclickingGetLateston
theFlowMonitoringtab.
TrafficisdestinedtovirtualmachinesthatarenotprotectedbyavShieldApp.Makesureyourvirtual
machinesareprotectedbyavShieldApp.Virtualmachinesmustbeinthesameportgroupasthe
vShield Appprotected(p0)port.
ThereisnotraffictothevirtualmachinesprotectedbyavShieldApp.
CheckthesystemstatusofeachvShieldAppforoutofsyncissues.
Troubleshooting Port Group Isolation Issues
Validate Installation of Port Group Isolation
To validate installation of Port Group Isolation
1MakesurethatthesameportgroupandvirtualmachinesarenotalsoconfiguredforvCloudService
DirectornetworkisolationorLabManagercrosshostfencing.Doubleencapsulationmodeisnot
supportedcurrently.
2VerifythatthePortGroupIsolationbundleisinstalled:esxupdate query
3Verifythatvshdisrunning.
ESXi:ps | grep vsh.Theresultsmightcontainmorethanoneinstance,whichisok.
ESXClassic:ps –eaf | grep vshd
Vista de página 150
1 2 ... 146 147 148 149 150 151 152 153 154 155 156 ... 161 162

Comentários a estes Manuais

Sem comentários