vShield Endpoint
N
You must obtain an evaluation or full license to use vShield Endpoint.
OTE
vShield Endpoint delivers an introspection-based antivirus solution. vShield Endpoint uses the hypervisor to
scan guest virtual machines from the outside without a bulky agent. vShield Endpoint is efficient in avoiding
resource bottlenecks while optimizing memory use.
vShield Endpoint installs as a hypervisor module and security virtual appliance from a third-party antivirus
vendor (VMware partners) on an ESX host.
vShield Endpoint provides the following features:
On-demand file scanning in a service virtual machine.
On-access file scanning in a service virtual machine.
Migration of vShield Components
The vShield Manager and vShield Edge virtual appliances can be automatically or manually migrated based
on DRS and HA policies. The vShield Manager must always be up, so you must migrate the vShield Manager
whenever the current ESX host undergoes a reboot or maintenance mode routine.
Each vShield Edge should move with its secured port group to maintain security settings and services.
vShield App and Port Group Isolation services cannot be moved to another ESX host. If the ESX host on which
these services reside requires a manual maintenance mode operation, you must de-select the Move powered
off and suspended virtual machines to other hosts in the cluster check box to ensure these virtual appliances
are not migrated. These services restart after the ESX host comes online.
VMware Tools
Each vShield virtual appliance includes VMware Tools. Do not upgrade or uninstall the version of VMware
Tools included with a vShield virtual appliance.
Ports Required for vShield Communication
The vShield Manager requires the following ports to be open:
REST API: 80/TCP and 443/TCP
Graphical User Interface: 80/TCP to 443/TCP and initiates connections to vSphere vCenter SDK.
SSH access to the CLI (not enabled by default): 22/TCP
VMware, Inc.
Chapter 1 Overview of vShield
13
Need help?
Do you have a question about the VSHIELD APP 1.0.0 UPDATE 1 and is the answer not in the manual?