VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Bedienungsanleitung Seite 77

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 162
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 76
VMware, Inc. 77
Chapter 13 App Firewall Management
Revert to a Previous App Firewall Configuration
ThevShieldManagersavesasnapshotofAppFirewallsettingseachtimeyoucommitanewrule.Clicking
CommitcausesthevShieldManagertosavethepreviousconfigurationwithatimestampbeforeaddingthe
newrule.ThesesnapshotsareavailablefromtheReverttoSnapshotdropdownlist.
To revert to a previous App Firewall configuration
1InthevSphere
Client,gotoInventory>HostsandClusters.
2 Selectadatacenterorclusterresourcefromtheinventorypanel.
3ClickthevShieldApptab.
4ClickAppFirewall.
5FromtheReverttoSnapshotdropdownlist,selectasnapshot.
Snapshotsarepresentedintheorderoftimestamps,withthemostrecentsnapshotlisted
atthetop.
6Viewsnapshotconfigurationdetails.
7Dooneofthefollowing:
Toreturntothecurrentconfiguration,selecttheoptionfromtheReverttoSnapshotdropdownlist.
ClickCommittooverwritethecurrentconfigurationwiththesnapshotconfiguration.
Delete an App Firewall Rule
YoucandeleteanyAppFirewallruleyouhavecreated.YoucannotdeletetheanyrulesintheDefaultRules
sectionofthetable.
To delete an App Firewall rule
1ClickanexistingrowintheAppFirewalltable.
2ClickDelete.
3ClickCommit.
Using SpoofGuard
AftersynchronizingwiththevCenterServer,thevShieldManagercollectstheIPaddressesofallvCenter
guestvirtualmachinesfromVMwareToolsoneachvirtualmachine.UptovShield4.1,vShieldtrustedtheIP
addressprovidedbyVMwareToolsonavirtualmachine.However,ifavirtualmachinehasbeen
compromised,
theIPaddresscanbespoofedandmalicioustransmissionscanbypassfirewallpolicies.
SpoofGuardallowsyoutoauthorizetheIPaddressesreportedbyVMwareTools,andalterthemifnecessary
topreventspoofing.SpoofGuardinherentlytruststheMACaddressesofvirtualmachinescollectedfromthe
VMXfilesandvSphereSDK.
OperatingseparatelyfromtheAppFirewallrules,youcanuseSpoofGuardto
blocktrafficdeterminedtobespoofed.
Whenenabled,youcanuseSpoofGuardtomonitorandmanagetheIPaddressesreportedbyyourvirtual
machinesinoneofthefollowingmodes.
AutomaticallyTrustIPAssignmentsOnTheirFirstUse:Thismodeallowsalltrafficfromyourvirtual
machinestopasswhilebuildingatableofMACtoIPaddressassignments.Youcanreviewthistableat
yourconvenienceandmakeIPaddresschanges.
ManuallyInspectandApproveAllIPAssignmentsBeforeUse:Thismodeblocksalltrafficuntilyou
approveeachMACtoIPaddressassignment.
NOTESpoofGuardinherentlyallowsDHCPrequestsregardlessofenabledmode.However,ifinmanual
inspectionmode,trafficdoesnotpassuntiltheDHCPassignedIPaddresshasbeenapproved.
Seitenansicht 76
1 2 ... 72 73 74 75 76 77 78 79 80 81 82 ... 161 162

Kommentare zu diesen Handbüchern

Keine Kommentare