VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Manual do Utilizador Página 73

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 72
VMware, Inc. 73
Chapter 13 App Firewall Management
Denyalltrafficbydefault.YoucanchangetheActionstatusofthedefaultrulesfromAllowtoDeny,and
addallowrulesexplicitlyforspecificsystemsandapplications.Inthisscenario,ifasessiondoesnot
matchanyoftheallowrules,thevShieldAppdropsthesessionbeforeit
reachesitsdestination.Ifyou
changeallofthedefaultrulestodenyanytraffic,thevShieldAppdropsallincomingandoutgoingtraffic.
Create an App Firewall Rule
AppFirewallrulesallowordenytrafficbasedonthefollowingcriteria:
YoucanadddestinationandsourceportrangestoarulefordynamicservicessuchasFTPandRPC,which
requiremultipleportstocompleteatransmission.
To create a firewall rule at the datacenter level
1InthevSphereClient,gotoInventory>HostsandClusters.
2 Select
adatacenterresourcefromtheresourcetree.
3ClickthevShieldApptab.
4ClickAppFirewall.
Bydefault,theL4Rulesoptionisselected.
TocreateL2/L3rules,see“CreateaLayer2/Layer3AppFirewallRule”onpage 75.
5Dooneofthefollowing:
ClickAddtoaddanewruletotheDataCenterLowPrecedenceRules(Rulesbelowthislevelhave
lowerprecedence...).
SelectarowintheDataCenterHighPrecedenceRulessectionofthetableandclickAdd.Anew
appearsbelowtheselectedrow.
6Doubleclickeachcellinthenewrowtoselecttheappropriateinformation.
YoucantypeIPaddressesintheSourceandDestinationfields,andportnumbers
intheSourcePortand
DestinationPortfields.
7 (Optional)SelectthenewrowandclickUptomovetheruleupinpriority.
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommittosavetherule.
Criteria Description
Source(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)from
whichthecommunicationoriginated.
SourcePort Portorrangeofportsfromwhichthecommunicationoriginated.Toenteraport
range,separatethelowandhighendoftherangewithacolon.Forexample,
1000:1100.
Destination
(A.B.C.D/nn) Container,directioninrelationtocontainer,orIPaddresswithnetmask(nn)which
thecommunicationistargeting.
DestinationApplication Theapplicationonthedestinationthesourceistargeting.Ifyouselectaprotocol
fromthedropdownlist,thewellknownportfortheselectedprotocolappearsin
theDestinationPort
field.
DestinationPort Portorrangeofportswhichthecommunicationistargeting.Toenteraportrange,
separatethelowandhighendoftherangewithacolon.Forexample,1000:1100.
Protocol Transportprotocolusedforcommunication.
NOTELayer4firewallrulescanalsobecreatedfromtheFlowMonitoringreport.See“A d d anAppFirewall
RulefromtheFlowMonitoringReport”onpage 67.
Vista de página 72
1 2 ... 68 69 70 71 72 73 74 75 76 77 78 ... 161 162

Comentários a estes Manuais

Sem comentários