
If a system administrator specified syslog server settings and those settings have been applied to the
organization vDC network, then you can log firewall rule events. For information about applying syslog server
settings, see “Apply Syslog Server Settings to an Organization vDC Network,” on page 33. To view the current
syslog server settings see “View Syslog Server Settings for an Organization vDC Network,” on page 33.
Prerequisites
Verify that you have a routed organization vDC network and enable the firewall for the organization vDC
network. See “Configure the Firewall for an Organization vDC Network,” on page 24
Procedure
1 Click Administration and select the organization vDC.
2 On the Org vDC Networks tab, right-click the organization vDC network name and select Configure
Services.
3 Click the Firewall tab and click Add.
4 Type a name for the rule.
5 (Optional) Select Match rule on translated IP to have the rule check against translated IP addresses rather
than original IP addresses and choose a traffic direction to apply this rule on.
6 Type the traffic Source.
Option Description
IP address
Type a source IP address to apply this rule on.
Range of IP addresses
Type a range of source IP addresses to apply this rule on.
CIDR
Type the CIDR notation of traffic to apply this rule on.
internal
Apply this rule to all internal traffic.
external
Apply this rule to all external traffic.
any
Apply this rule to traffic from any source.
7 Select a Source port to apply this rule on from the drop-down menu.
8 Type the traffic Destination.
Option Description
IP address
Type a destination IP address to apply this rule on.
Range of IP addresses
Type a range of destination IP addresses to apply this rule on.
CIDR
Type the CIDR notation of traffic to apply this rule on.
internal
Apply this rule to all internal traffic.
external
Apply this rule to all external traffic.
any
Apply this rule to traffic with any destination.
9 Select the Destination port to apply this rule on from the drop-down menu.
10 Select the Protocol to apply this rule on from the drop-down menu.
11 Select the action.
A firewall rule can allow or deny traffic that matches the rule.
12 Select the Enabled check box.
13 (Optional) Select the Log network traffic for firewall rule check box.
If you enable this option, vCloud Director sends log events to the syslog server for connections affected
by this rule. Each syslog message includes logical network and organization UUIDs.
Chapter 3 Managing Cloud Resources
VMware, Inc. 25
Komentarze do niniejszej Instrukcji