
VMware, Inc. 25
Chapter 5 vShield Edge Management
Manage CLI Credentials on a vShield Edge
YoucansetandchangelogincredentialsfortheCLIonavShieldEdgevirtualapplianceviaREST.
YoucanchangethedefaultCLIlogincredentials(usernameadminandpassworddefault)onavShieldEdge
viaREST.
Youcanuselower‐caseletters,numbers,andunderscoresintheCLIusername.
Theusernamemuststartwith
aletterandbe between1and33charactersinlength.Thepasswordcannothavespacesandmustbeatleast1
characterinlength.
Fortheschema,see“vShieldEdgeCLILoginCredentialsSchema”onpage 74.
Example 5-4. Managing CLI Credentials on a vShield Edge
Request:
PUT <vshield_manager-uri>/api/1.0/network/<vdc-moref-id>/cli/credentials
Managing DHCP
vShieldEdgeprovidesDHCPservicetobindassignedIPaddressestoMACaddresses,preventingMAC
spoofingattacks.AllvirtualmachinesprotectedbyavShieldEdgecanobtainIPaddressesdynamicallyfrom
thevShieldEdgeDHCPservice.
vShieldEdgesupportsIPaddresspoolingandone‐to‐onestaticIPaddressallocationbased
onthevCenter
managedobjectID(vmid)andinterfaceID(interfaceId)oftherequestingclient.
vShieldEdgeDHCPserviceadherestothefollowingrules:
ListensonthevShieldEdgeinternalinterface(InternalInterface)forDHCPdiscovery.
UsestheIPaddressoftheinternalinterfaceonthevShieldEdgeasthedefaultgatewayaddressforall
clients,andthebroadcast andsubnetMaskvaluesoftheinternalinterfaceforthecontainernetwork.
AllDHCPsettingsconfiguredbyusingRESTrequests appearunderthevShieldEdge>DHCPtabforthe
appropriatevShieldEdgeinthevShieldManageruserinterfaceand vSphereClientplug‐in.
FortheDHCPschema,see“DHCPSchema”onpage 79.
Get the DHCP Server Status
Example 5-5. Getting the Status of the DHCP Service on a vShield Edge
Request:
GET <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/dhcp/service
Example:
GET /api/1.0/network/network-244/dhcp/service HTTP/1.1
Authorization: Basic YWRtaW46ZGVmYXVsdA==
Host: 10.112.196.213
Start, Stop, or Restart the DHCP Service
Example 5-6. Starting or Stopping the DHCP Service on a vShield Edge
Request:
PUT <vshield_manager-uri>/api/1.0/network/<internal-portgroup-vc-moref-id>/dhcp/action/
{start | stop | restart}
Komentarze do niniejszej Instrukcji