VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Instrukcja Użytkownika Strona 15

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 30
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 14
VMware, Inc. 15
Chapter 2 Preparing for Installation
How Do I Isolate a Group of Virtual Machines?
YoucanusevShieldEdgewiththePortGroupIsolationfeatureorVLANstoisolatevirtualmachinesfromthe
externalnetwork.
1InstallPortGroupIsolationoneachESXhostthatavDSspans.
2 CreateaportgrouponthevDS.
3EnablePortGroupIsolationonthevDS.
4InstallavShieldEdgeonthe
portgroup.
5Movethevirtualmachinestotheportgroup.
6ConfigurevShieldEdgeNATrulesfortrafficinandoutoftheportgroup.
vShield Manager Uptime
ThevShieldManagershouldberunonanESXhostthatisnotaffectedbydowntime,suchasfrequentreboots
ormaintenancemodeoperations.YoucanuseHAorDRStoincreasetheresilienceofthevShieldManager.If
theESXhostonwhichthevShieldManagerresidesisexpectedto
requiredowntime,vMotionthevShield
ManagervirtualappliancetoanotherESXhost.Thus,morethanoneESXhostisrecommended.
Communication Between vShield Components
ThemanagementinterfacesofvShieldcomponentsshouldbeplacedinacommonnetwork,suchasthe
vSpheremanagementnetwork.ThevShieldManagerrequiresconnectivitytothevCenterServer,aswellas
allvShieldAppandvShieldEdgeinstances.vShieldcomponentscancommunicateoverroutedconnections
aswellasdifferentLANs.
Hardening Your vShield Virtual Machines
YoucanaccessthevShieldManagerandothervShieldcomponentsbyusingawebbaseduserinterface,
commandlineinterface,andRESTAPI.vShieldincludesdefaultlogincredentialsforeachoftheseaccess
options.AfterinstallationofeachvShieldvirtualmachine,youshouldhardenaccessbychangingthedefault
logincredentials.
vShield Manager User Interface
YouaccessthevShieldManageruserinterfacebyopeningawebbrowserwindowandnavigatingtotheIP
addressofthevShieldManagersmanagementport.Thedefaultuseraccount,admin,hasglobalaccesstothe
vShieldManager.Afterinitiallogin,youshouldchangethedefaultpasswordoftheadminuseraccount.
See
“ChangethePasswordofthevShieldManagerUserInterfaceDefaultAccount”onpage 20.
Command Line Interface
YoucanaccessthevShieldManager,vShieldApp,andvShieldEdgevirtualappliancesbyusingacommand
lineinterfaceviavSphereClientconsolesession.Eachvirtualapplianceusesthesamedefaultusername
(admin)andpassword(default)combinationasthevShieldManageruserinterface.EnteringEnabledmode
alsousesthe
passworddefault.
FormoreonhardeningtheCLI,seethevShieldAdministrationGuide.
NOTEYoucanalsouseVLANstoisolatevirtualmachinesprotectedbyavShieldEdge.Ifyouuse
VLANs,theinternalportgroupconnectedtoavShieldEdgemusthaveaVLANtagthatisdifferentfrom
theexternalportgroup.
NOTEThevShieldManagermustbeinthesamevCenterServerenvironmentasthevShieldcomponentsto
bemanaged.YoucannotusethevShieldManageracrossdifferentvCenterServerenvironments.
Przeglądanie stron 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 29 30

Komentarze do niniejszej Instrukcji

Brak uwag