Vshield Endpoint; Migration Of Vshield Components; Vmware Tools; Ports Required For Vshield Communication - VMware VSHIELD APP 1.0.0 UPDATE 1 Admin Manual

Hide thumbs Also See for VSHIELD APP 1.0.0 UPDATE 1:
Table of Contents

Advertisement

vShield Endpoint

N
You must obtain an evaluation or full license to use vShield Endpoint.
OTE
vShield Endpoint delivers an introspection-based antivirus solution. vShield Endpoint uses the hypervisor to
scan guest virtual machines from the outside without a bulky agent. vShield Endpoint is efficient in avoiding
resource bottlenecks while optimizing memory use.
vShield Endpoint installs as a hypervisor module and security virtual appliance from a third-party antivirus
vendor (VMware partners) on an ESX host.
vShield Endpoint provides the following features:
On-demand file scanning in a service virtual machine.
On-access file scanning in a service virtual machine.

Migration of vShield Components

The vShield Manager and vShield Edge virtual appliances can be automatically or manually migrated based
on DRS and HA policies. The vShield Manager must always be up, so you must migrate the vShield Manager
whenever the current ESX host undergoes a reboot or maintenance mode routine.
Each vShield Edge should move with its secured port group to maintain security settings and services.
vShield App and Port Group Isolation services cannot be moved to another ESX host. If the ESX host on which
these services reside requires a manual maintenance mode operation, you must de-select the Move powered
off and suspended virtual machines to other hosts in the cluster check box to ensure these virtual appliances
are not migrated. These services restart after the ESX host comes online.

VMware Tools

Each vShield virtual appliance includes VMware Tools. Do not upgrade or uninstall the version of VMware
Tools included with a vShield virtual appliance.

Ports Required for vShield Communication

The vShield Manager requires the following ports to be open:
REST API: 80/TCP and 443/TCP
Graphical User Interface: 80/TCP to 443/TCP and initiates connections to vSphere vCenter SDK.
SSH access to the CLI (not enabled by default): 22/TCP
VMware, Inc.
Chapter 1 Overview of vShield
13

Advertisement

Table of Contents
loading

Table of Contents