vShield Administration Guide
76 VMware, Inc.
5Double‐clicktherowandtypeanameforthegroup.
6ClickAdd.
Aftersecuritygroupcreationiscomplete,assignresourcestothegroup.
Assign Resources to a Security Group
Youcanassignvirtualmachinesandnetworkadapterstoasecuritygroup.TheseresourceshaveassociatedIP
addressesthatdefinethesourceordestinationparametersforwhichanAppFirewallruleenforcesanaccess
policy.
To assign resources to a security group
1ClickadatacenterresourcefromthevSphereClient.
2ClickthevShieldApptab.
3ClickSecurityGroups.
4Click
thearrownexttothenameofasecuritygrouptoexpandthedetailsofthegroup.
5 SelectavNICfromthedrop‐downlistandclickAdd.
TheselectedvNICappearsundervNICMembership.
RepeatthesestepsforeachvNICyouwanttoplaceinthissecuritygroup.
6ClickCommit.
Afterassigningresources,addthesecuritygrouptoafirewallruleasacontainer.See“CreateanApp
FirewallRule”onpage 73.
Validating Active Sessions against the Current App Firewall Rules
Bydefault,avShieldEdgematchesfirewallrulesagainsteachnewsession.Afterasessionhasbeen
established,anyfirewallrulechangesdonotaffectactivesessions.
TheCLIcommandvalidate sessionsenablesyoutovalidateactivesessionsthatareinviolationofthe
currentruleset.Youwouldusethisprocedure
forthefollowingscenarios:
Youupdatedthefirewallruleset.Afterafirewallrulesetupdate,youshouldvalidateactivesessionsto
purgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
YouviewedsessionsinFlowMonitoringanddeterminedthatanexistingorhistoricalflowrequiresanew
accessrule.Aftercreatingafirewallrulethatmatchestheoffendingsession,youshouldvalidateactive
sessionstopurgeanyexistingsessionsthatareinviolationoftheupdatedpolicy.
AftertheAppFirewall
updateiscomplete,issuethevalidate sessionscommandfromtheCLIofavShield
Apptopurgesessionsthatareinviolationofcurrentpolicy.
To validate active sessions against the current firewall rules
1 UpdateandcommittheAppFirew allrulesetattheappropriatecontainerlevel.
2OpenaconsolesessiononavShieldAppissuethevalidate sessionscommand.
vShieldApp> enable
Password:
vShieldApp# validate sessions
Comentários a estes Manuais