VMware VSHIELD APP 1.0 - API Instrukcja Użytkownika Strona 39

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 104
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 38
VMware, Inc. 39
Chapter 5 vShield Edge Management
Ifaserviceconfigurationtagispresent,itmeansreplacetheconfiguration.Ifaserviceconfigurationtag’sblock
isempty,itmeansdeletetheconfiguration.Ifaserviceconfigurationtagisabsent,itmeansdonotchange
anything,andhencethepreviousconfigurationforthatserviceisretainedasis.
Example 5-6. Change configuration of a vShield Edge
Request:
POST https://<vsm-ip>/api/2.0/networks/<internal-portgroup-vc-moref-id>/edge
RequestBody:
seeexamplesbelow.
Install vShield Edge
ThepostcallconfiguresavShieldEdge,asdescribein“InstallingavShieldEdge”onpage 33.
Delete vShield Edge
ThedeletecalluninstallsvShieldEdge,asdescribedin“UninstallingavShieldEdge”onpage 36.
Configuring Edge Services
YouconfigureEdgeservicessuchasNAT,Firewall,DHCP,staticrouting.LoadBalancer,andVPNwiththe
APIshowninExample 56.ThefollowingrequestbodiesshowvariousconfigurationsmadeonvShieldEdge.
Configure DHCP
vShieldEdgeprovidesDHCPservicetobindassignedIPaddressestoMACaddresses,helpingtoprevent
MACspoofingattacks.AllvirtualmachinesprotectedbyavShieldEdgecanobtainIPaddressesdynamically
fromthevShieldEdgeDHCPservice.
vShieldEdgesupportsIPaddresspoolingandonetoonestaticIPaddress
allocationbasedonthevCenter
managedobjectID(vmId)andinterfaceID(interfaceId)oftherequestingclient.AllDHCPsettings
configuredbyRESTrequestsappearunderthevShieldEdge>DHCPtabfortheappropriatevShieldEdgein
thevShieldMana ge ruserinterf a c eandinvSphereClient plugin.
vShieldEdgeDHCPserviceadherestothefollowingrules:
ListensonthevShieldEdgeinternalinterface(nonuplinkinterface)forDHCPdiscovery.
Asstatedabove,vmIDspecifiesthevc-moref-idofthevirtualmachine,andinterfaceIdspecifiesthe
indexofthevNicfortherequestingclient.ThehostNameisanidentificationofthebindingbeingcreated.
ThishostNameisnotpushedasthespecifiedhostnameofthevirtualmachine.
Bydefault,allclientsusetheIPaddressoftheinternalinterfaceofthevShieldEdgeasthedefaultgateway
address.Tooverrideit,specifydefaultGwundertheconfigParamsInterface,perbindingorperpool.
Theclient’sbroadcastandsubnetMaskvaluesarefromtheinternalinterfaceforthecontainernetwork.
configParamsanditselementsareoptional.
leaseTimecanbeinfinite,oranumberofseconds.Ifnotspecified,thedefaultleasetimeis1day.
Loggingisdisabledbydefault.Toenablelogging,adda<log/>elementwithinthe<dhcpConfig>block.
FortheDHCPschema,see“vShieldEdgeSchemas”onpage 88.SampleXMLrequestbody:
Example 5-7. Configure DHCP service
POST https://<vsm-ip>/api/2.0/networks/<internal-portgroup-vc-moref-id>/edge
IMPORTANTWhenyouconfigureavShieldEdgeservice,theserviceisstartedontheappliance.Ifyoudonot
wanttheservicerunning,youmuststoptheserviceusinganappropriatesystemcommand.
Przeglądanie stron 38
1 2 ... 34 35 36 37 38 39 40 41 42 43 44 ... 103 104

Komentarze do niniejszej Instrukcji

Brak uwag