
VMware, Inc. 71
13
vShieldAppprovidesfirewallprotectionthroughaccesspolicyenforcement.TheAppFirewalltabrepresents
thevShieldAppfirewallaccesscontrollist.
Thischapterincludesthefollowingtopics:
“UsingAppFirewall”onpage 71
“CreateanAppFirewallRule”onpage 73
“CreateaLayer2/Layer3AppFirewallRule”onpage 75
“CreatingandProtectingSecurityGroups”onpage 75
“ValidatingActiveSessionsagainsttheCurrentAppFirewallRules”onpage 76
“ReverttoaPreviousAppFirewallConfiguration”onpage 77
“DeleteanAppFirewallRule”onpage 77
“UsingSpoofGuard”onpage 77
Using App Firewall
TheAppFirewallserviceisacentralized,hierarchicalfirewallforESXhosts.AppFirewallenablesyouto
createrulesthatallowordenyaccesstoandfromyourvirtualmachines.EachinstalledvShieldAppenforces
theAppFirewallrules.
YoucanmanageAppFirewallrulesatthedatacenter,cluster,andport
grouplevelstoprovideaconsistentset
ofrulesacrossmultiplevShieldAppinstancesunderthesecontainers.Asmembershipinthesecontainerscan
changedynamically,AppFirewallmaintainsthestateofexistingsessionswithoutrequiringreconfiguration
offirewallrules.Inthisway,AppFirewalleffectivelyhasacontinuousfootprintoneach
ESXhostunderthe
managedcontainers.
Securing Containers and Designing Security Groups
WhencreatingAppFirewallrules,youcancreaterulesbasedontraffictoorfromaspecificcontainerthat
encompassesalloftheresourceswithinthatcontainer.Forexample,youcancreatearuletodenyanytraffic
frominsideofaclusterthattargetsaspecificdestinationoutsideofthe
cluster.Youcancreatearuletodeny
anyincomingtrafficthatisnottaggedwithaVLANID.Whenyouspecifyacontainerasthesourceor
destination,allIPaddresseswithinthatcontainerareincludedintherule.
App Firewall Management
13
NOTEAppFirewallrulesapplytovShieldAppinstances,butnotvShieldEdgeorvShieldEndpointinstances.
TheZonesFirewalltabbecomestheAppFirewalltabwhenthevShieldApplicenseisactivated.
Komentarze do niniejszej Instrukcji