VMware VSHIELD APP 1.0 - API Bedienungsanleitung Seite 39

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 104
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 38
VMware, Inc. 39
Chapter 5 vShield Edge Management
Ifaserviceconfigurationtagispresent,itmeansreplacetheconfiguration.Ifaserviceconfigurationtag’sblock
isempty,itmeansdeletetheconfiguration.Ifaserviceconfigurationtagisabsent,itmeansdonotchange
anything,andhencethepreviousconfigurationforthatserviceisretainedasis.
Example 5-6. Change configuration of a vShield Edge
Request:
POST https://<vsm-ip>/api/2.0/networks/<internal-portgroup-vc-moref-id>/edge
RequestBody:
seeexamplesbelow.
Install vShield Edge
ThepostcallconfiguresavShieldEdge,asdescribein“InstallingavShieldEdge”onpage 33.
Delete vShield Edge
ThedeletecalluninstallsvShieldEdge,asdescribedin“UninstallingavShieldEdge”onpage 36.
Configuring Edge Services
YouconfigureEdgeservicessuchasNAT,Firewall,DHCP,staticrouting.LoadBalancer,andVPNwiththe
APIshowninExample 56.ThefollowingrequestbodiesshowvariousconfigurationsmadeonvShieldEdge.
Configure DHCP
vShieldEdgeprovidesDHCPservicetobindassignedIPaddressestoMACaddresses,helpingtoprevent
MACspoofingattacks.AllvirtualmachinesprotectedbyavShieldEdgecanobtainIPaddressesdynamically
fromthevShieldEdgeDHCPservice.
vShieldEdgesupportsIPaddresspoolingandonetoonestaticIPaddress
allocationbasedonthevCenter
managedobjectID(vmId)andinterfaceID(interfaceId)oftherequestingclient.AllDHCPsettings
configuredbyRESTrequestsappearunderthevShieldEdge>DHCPtabfortheappropriatevShieldEdgein
thevShieldMana ge ruserinterf a c eandinvSphereClient plugin.
vShieldEdgeDHCPserviceadherestothefollowingrules:
ListensonthevShieldEdgeinternalinterface(nonuplinkinterface)forDHCPdiscovery.
Asstatedabove,vmIDspecifiesthevc-moref-idofthevirtualmachine,andinterfaceIdspecifiesthe
indexofthevNicfortherequestingclient.ThehostNameisanidentificationofthebindingbeingcreated.
ThishostNameisnotpushedasthespecifiedhostnameofthevirtualmachine.
Bydefault,allclientsusetheIPaddressoftheinternalinterfaceofthevShieldEdgeasthedefaultgateway
address.Tooverrideit,specifydefaultGwundertheconfigParamsInterface,perbindingorperpool.
Theclient’sbroadcastandsubnetMaskvaluesarefromtheinternalinterfaceforthecontainernetwork.
configParamsanditselementsareoptional.
leaseTimecanbeinfinite,oranumberofseconds.Ifnotspecified,thedefaultleasetimeis1day.
Loggingisdisabledbydefault.Toenablelogging,adda<log/>elementwithinthe<dhcpConfig>block.
FortheDHCPschema,see“vShieldEdgeSchemas”onpage 88.SampleXMLrequestbody:
Example 5-7. Configure DHCP service
POST https://<vsm-ip>/api/2.0/networks/<internal-portgroup-vc-moref-id>/edge
IMPORTANTWhenyouconfigureavShieldEdgeservice,theserviceisstartedontheappliance.Ifyoudonot
wanttheservicerunning,youmuststoptheserviceusinganappropriatesystemcommand.
Seitenansicht 38
1 2 ... 34 35 36 37 38 39 40 41 42 43 44 ... 103 104

Kommentare zu diesen Handbüchern

Keine Kommentare