VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Bedienungsanleitung Seite 50

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 162
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 49
vShield Administration Guide
50 VMware, Inc.
Specify a Remote Syslog Server
YoucansendvShieldEdgeevents,suchasviolatedfirewallrules,toasyslogserver.
To specify a remote syslog server
1InthevSphereClient,gotoInventory>Networking.
2 SelectaninternalportgroupthatisprotectedbyavShieldEdge.
3ClickthevShieldEdgetab.
4ClicktheStatuslink.
5UnderRemoteSyslogServers,placethecursorinthetoptextboxandtypetheIPaddressofaremote
syslogserver.
6ClickCommittosavetheconfiguration.
Managing the vShield Edge Firewall
ThevShieldEdgeprovidesfirewallprotectionforincomingandoutgoingsessions.Thedefaultfirewallpolicy
allowsalltraffictopass.Inadditiontothedefaultfirewallpolicy,youcanconfigureasetofrulestoallowor
denytrafficsessionstoandfromspecificsourcesanddestinations.Youmanagethedefault
firewallpolicyand
firewallrulesetseparatelyforeachvShieldEdgeagent.
YoucanchangetheDefaultPolicyfromAllowtoDenyonavShieldEdgetodenyanysessionsthatdonot
matchanyofthecurrentfirewallrules.
Create a vShield Edge Firewall Rule
vShieldEdgefirewallrulespolicetrafficbasedonthefollowingcriteria:
YoucanadddestinationandsourceportrangestoarulefordynamicservicessuchasFTPandRPC,which
requiremultipleportstocompleteatransmission.Ifyoudonotallowalloftheportsthatmustbeopenedfor
atransmission,thetransmissionisblocked.
To create a vShield Edge firewall rule
1InthevSphereClient,gotoInventory>Networking.
2 SelectaninternalportgroupthatisprotectedbyavShieldEdge.
3ClickthevShieldEdgetab.
4ClicktheFirewalllink.
Criteria Description
SourceIP IPaddressfromwhichthecommunicationoriginated.
SourcePort Portorrangeofportsfromwhichthecommunicationoriginated.Toenteraport
range,separatethelowandhighendoftherangewithacolon.Forexample,
1000:1100.
DestinationIP IPaddresswhichthecommunicationistargeting.
DestinationPort Portor
rangeofportswhichthecommunicationistargeting.Toenteraportrange,
separatethelowandhighendoftherangewithacolon.Forexample,1000:1100.
Protocol Transportprotocolusedforcommunication.
Direction Directionoftransmission.OptionsareIN,OUT,orBOTH.
Action Actiontoenforceontransmission.OptionsareALLOW
orDENY.Thedefaultaction
onalltrafficisALLOW.
Seitenansicht 49
1 2 ... 45 46 47 48 49 50 51 52 53 54 55 ... 161 162

Kommentare zu diesen Handbüchern

Keine Kommentare