vShield Administration Guide
152 VMware, Inc.
4Verifythatthekernelmoduleisloaded:vmkload_mod –l | grep vshd -ni
5Verifythatthemirrorvirtualmachineispoweredon.
OntheESXhost,lookforapoweredonvirtualmachinewithnahe vshield-infra-ni-<string>.
6VerifythatthePortGroupIsolationvirtualmachineisconnectedtothecorrectportgroup.
7VerifythattheVMXfilesfortheprotectedvirtualmachinescontainthefilterentries.
OpentheVMXfileandsearchforfilter15.Thereshouldbethreeentries.Makesuretheseentriesare
presentonthecorrectEthernetcard.EachVMXfileshouldhaveonlythreeentriespervNICrelatedtothe
fencemodule(filter15).Ifthe
entriesarerepeated,thatmeansthattheVMXfilehadisolationentries
fromapreviousconfigurationthatwasnotcleanedupandlaterduplicateentrieswereadded.
8VerifythatallvirtualmachinesbelongingtotheportgrouphaveidenticalfiltersettingsintheVMXfiles.
9Verifythatthevshdconfigurationisintact.
aGoto/etc/opt/vmware/vslad/config.
bReviewthefilesinthisdirectory.Ensureallfilescontainsomedata.Theyshouldnotbeempty.
Ifalloftheaboveiscorrect,theESXhostissetupproperlyforPortGroupIsolation.
Verify Install or Uninstall Script
Theinstallationscriptcreatesthefollowingentities.
Createsausernamedvslauserandsetsadefaultpassword.
Toseeiftheuserwasadded:vi /etc/passwd
Addstherolevslauserandassociatestheuservslausertotherole.
Addsentriestostartvshdandthescriptsvm-autostart acrosseveryreboot.
YoucanverifythisonESXibylookingforentriesrelatedtovshdandsvm‐autostartinthefile
/etc/chkConfig.db.OnESX,youcanverifythisbydoingfind / -name *vsh*andconfirmingthat
therearescriptsnamedS<value>vsladandsvm-autostart
.
AddsanentrytotheserviceslistonESXtoexposeVSHDservices.Youcanverifythisentrybyopening
thefile/etc/vmware/hostd/proxy.xmlandsearchingforwordvsh.
Theremovalscriptremovesalloftheoperationscreatedbytheinstallationscript.
Removesuservslauser.
Removestherolevslauser.
Removestheinitentriesforvshdandsvm-autostart.
Removesthevshdentryfromproxy.xml.
Validate the Data Path
To troubleshoot packet drops, such as a ping between virtual machines in the same isolated port
group
1Makesurethataddresses,routes,netmasks,andgatewaysareconfiguredcorrectly.
2Installtcpdumponavirtualmachineintheisolatedportgroup.
3Runapacketcaptureinsidethatvirtualmachine.
4Pingfromtheproblematicvirtualmachinetothevirtualmachinewherecapturesarerunning.
IfanARPpacketisreceived,thatmeansthatbroadcastpacketsarereceived.IfyoudonotreceiveanARP
packet,thatmeansnoneofthepacketswerereceived.
Kommentare zu diesen Handbüchern