
vShield Administration Guide
74 VMware, Inc.
To create a firewall rule at the cluster level
1InthevSphereClient,gotoInventory>HostsandClusters.
2 Selectaclusterresourcefromtheresourcetree.
3ClickthevShieldApptab.
4ClickAppFirewall.
Bydefault,theL4Rulesoptionisselected.
TocreateL2/L3rules,see“CreateaLayer2/Layer3AppFirewallRule”onpage 75.
5ClickAdd.
AnewrowappearsintheClusterLevelRulessectionofthetable.
6Double‐clickeachcellinthenewrowtoselecttheappropriateinformation.
YoucantypeIPaddressesintheSourceandDestinationfields,andportnumbersintheSourcePortand
DestinationPortfields.
7 (Optional)Selectthenew
rowandclickUptomovetherowupinpriority.
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommittosavetherule.
To create a firewall rule at the port group level
1InthevSphereClient,gotoInventory>Networking.
2 Selectaportgroupfromtheresourcetree.
3ClickthevShieldApptab.
4ClickAppFirewall.
5ClickAdd.
AnewrowisaddedatthebottomoftheSecurePortGroupRulessection.
6Double‐clickeachcellinthenewrowtoselecttheappropriateinformation.
YoucantypeIPaddressesintheSourceandDestinationfields,andportnumbersintheSourcePortand
DestinationPortfields.
7 (Optional)SelectthenewrowandclickUptomovetherowupinpriority.
8 (Optional)SelecttheLogcheckboxtologallsessionsmatchingthisrule.
9ClickCommittosavetherule.
NOTELayer4firewallrulescanalsobecreatedfromtheFlowMonitoringreport.See“A d d anAppFirewall
RulefromtheFlowMonitoringReport”onpage 67.
N
OTELayer4firewallrulescanalsobecreatedfromtheFlowMonitoringreport.See“A d d anAppFirewall
RulefromtheFlowMonitoringReport”onpage 67.
Kommentare zu diesen Handbüchern