VMware, Inc. 405
Chapter 19 Setting and Using Policies and Customizing VMware Player
Therearetrade‐offsbetweenusingshorterandlongerlistsofconditions.Ifyouusea
longerlist,youminimizethechancesofafalse‐positiveresultoramisidentification.
Minimizingthechanceofafalse‐positiveresultoramisidentificationcanbeimportant
ifyouareprovidinganACEpackagetoso
meonewhoconn
ectsahostcomputerto
multiplenetworksatdifferenttimes.Ifoneoftheothernetworksmatchesthe
characteristicsyoudefineinthezonedefinition,thehostandinstanceaccesspolicies
areapplied,evenifthehostisnotconnectedtoyournetwork.
Insomecases,however,usingalong
erlistmightalsoincreasethelikelihoodthatauser
couldcircumventthedetectionmechanism.Forexample,suchanerrormightbemade
ifyouswitchthehosttouseastaticIPaddressinsteadofDHCPandconfigurethehost
withonlyasubsetofthecharacteristicsdefinedforyo
urzone,suchasonlynetwork
address,ornetworkaddressandDNSserverinformation.
Alsoconsiderthattheaddressesornamesofcertainserverscanchangeovertime.
Such changescanalsointroducedetectionissues.
Usingasmallersetofinformationinazonedescription,suchasonlythenetwork
addressandthesu
bnetmask,issafer.Thedisadvantageisthatitincreasesthechance
thatafalsepositiveormisidentificationcanoccur.Suchfalsepositivesareespecially
likelyifyournetworkisusingacommonnetblock,suchas10/8,172.16/12,or
192.168/16,thatisalsousedbyothernetworks.
Descriptions of the Zone Condition Settings
Eachzonedescriptionmustcontainoneormoreofthefollowingsettingoptions
describingtheconditionsofthezone:
Domain–Specifiesthedomainnameofthenetwork,suchasmycompany.com.
Enteronlyonedomainname.ThevalueofAllowsubdomainsofthisdomain
governstheinterpretationofthisoption.
Allowsubdomainsofthisdomain–ModifiestheDomainoption.Itspecifies
whether,fortheDomainzoneconditiontobemet,adomainnamemustexactly
matchthedomainnamespecifiedintheDomainboxorwhetheramatchofthe
domainnameismadeanytimethestringcontains<domain_name>.Forexample
,
ifthisoptionisselected,corp.mycompany.comisconsideredamatchfor
mycompany.com.Ifthisoptionisnotselected,corp.mycompany.comisnot
consideredamatchformycompany.com.
Networkaddress–SpecifiesanIPaddressorsubnetrangethatthenetworkuses.
Thevalueof<subnet>,ifyouincludeasubnetrange,mustbethenumberofbits
inthenetmask.Anetworkadaptermatchesthisconditionifitisusingan
IP addressthatlieswithinanyofthespec
ifiedranges.
Kommentare zu diesen Handbüchern