Workstation User’s Manual
402 VMware, Inc.
Setting Network Access Policies
Thenetworkaccessfeatureusesapacket‐filteringfirewalltoenableyoutospecify
whichmachinesorsubnetsanACEinstanceoritshostsystemmayaccess.Thismeans
thatyoucan,forexample,configuretheinstancesothatitisallowedtoconnectonlyto
yourVPNserver,whichthencontrolsaccesstoot
herresources.
Youcanalsocustomizethenetworkaccesssettingstofilteronthebasisofnetwork
addresses,trafficdirection,protocol,andports.Youcansetthefollowingtypesof
networkaccessrestrictiondefinitions:
Networkzones
NetworkaccessforanACEinstance’shostmachine(alsoknownas“hostnetwork
access”)
NetworkaccessforanACEinstance’sguestoperatingsystem(alsoknownas
“guestnetworkaccess”)
NetworkaccesspoliciescanbedynamiciftheACEinstanceisassociatedwithanACE
ManagementServer.ThismeansthatafteryoupublishapolicyupdatetoACE
ManagementServer,ACEinstancesgetthenewpolicythenextti
metheycheckfor
policyupdates.YoucanquicklylockACEinstancesoutofallorpartofyournetwork
tohelpcombatthespreadofawormorviruswithoutdeployingupdatepackages.See
theVMware ACEManagementServerAdministrator’sGuide.
Before You Begin Setting Host Policies
Usethefollowingguidelinesasyouplannetworkaccesspolicies:
AhostmachineforACEinstancescanhaveonlyonehostpolicyfile.Ifyoutryto
installanACEpackagewithahostpolicyfileonamachinethatalreadyhasa
differenthostpolicyfile,installationofthenewpackagefails.
AhostpolicyisineffectevenwhennoACEinstancesarerunning.Thepolicystarts
immediatelyafterinstallationandstartsworkingeverytimethehostsystemboots.
Anyrestrictionsonthehost’snetworkaccessalsorestrictnetworkaccessforan
ACEinstancethatusesNATnetworking,becausetheNATconnectionisaffected
byallthepoliciesyouapplytothehost.Ifyousetuprestrictedhostaccessbyusing
theACEruleseteditorandruleseditorratherthantheNetw
orkAccesswizard,
configuretheACE‐enabledvirtualmachine’svirtualNICstousebridged
networking.
IfyouaresettingupamanagedACE‐enabledvirtualmachine,youmustallowthe
hosttoaccessACEManagementServer,communicatingthroughTCPoverthe
appropriateportthatyouconfigure.
Kommentare zu diesen Handbüchern