
vShield Administration Guide
30 VMware, Inc.
5ClickAdd.
AnewrowappearsintheClusterLevelRulessectionofthetable.
6Double‐clickeachcellinthenewrowtoselecttheappropriateinformation.
YoumusttypeIPaddressesintheSourceandDestinationfields,andportnumbersintheSourcePort
andDestinationPortfields.
7 (Optional)Select
thenewrowandclickUptomovetherowupinpriority.
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommittosavetherule.
To create a firewall rule at the port group level
1InthevSphereClient,gotoInventory>Networking.
2 Selectaportgroupfromtheresourcetree.
3ClickthevShield
Zonestab.
4ClickZonesFirewall.
5ClickAdd.
AnewrowisaddedatthebottomoftheSecurePortGroupRulessection.
6Double‐clickeachcellinthenewrowtoselecttheappropriateinformation.
YoumusttypeIPaddressesintheSourceandDestinationfields,andportnumbersintheSourcePort
andDestinationPortfields.
7 (Optional)SelectthenewrowandclickUptomovetherowupinpriority.
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommittosavetherule.
Create a Layer 2/Layer 3 Zones Firewall Rule
TheLayer2/Layer3firewallenablesconfigurationofallowordenyrulesforcommonDataLinkLayerand
NetworkLayerrequests,suchasICMPpingsandtraceroutes.
YoucanchangethedefaultLayer2/Layer3rulesfromallowtodenybasedonyournetworksecuritypolicy.
Layer4firewallrulesallowor
denytrafficbasedonthefollowingcriteria:
To create a Layer 2/Layer 3 firewall rule
1InthevSphereClient,gotoInventory>HostsandClusters.
2 Selectadatacenterresourcefromtheresourcetree.
3ClickthevShieldZonestab.
4ClickZonesFirewall.
5ClickL2/L3Rules.
6ClickAdd.
AnewrowisaddedatthebottomoftheDataCenter
Rulessectionofthetable.
Criteria Description
Source(A.B.C.D/nn) IPaddresswithnetmask(nn)fromwhichthecommunicationoriginated
Destination(A.B.C.D/nn) IPaddresswithnetmask(nn)whichthecommunicationistargeting
Protocol Transportprotocolusedforcommunication
Kommentare zu diesen Handbüchern