Create A Layer 2/Layer 3 App Firewall Rule; Creating And Protecting Security Groups; Add A Security Group - VMware VSHIELD APP 1.0.0 UPDATE 1 Admin Manual

Hide thumbs Also See for VSHIELD APP 1.0.0 UPDATE 1:
Table of Contents

Advertisement

Create a Layer 2/Layer 3 App Firewall Rule

The Layer 2/Layer 3 firewall enables configuration of allow or deny rules for common Data Link Layer and
Network Layer requests, such as ICMP pings and traceroutes. You can change the default Layer 2/Layer 3 rules
from allow to deny based on your network security policy.
Layer 2/Layer 3 firewall rules allow or deny traffic based on the following criteria:
Criteria
Source (A.B.C.D/nn)
Destination (A.B.C.D/nn)
Protocol
To create a Layer 2/Layer 3 firewall rule
1
In the vSphere Client, go to Inventory > Hosts and Clusters.
2
Select a datacenter resource from the resource tree.
3
Click the vShield App tab.
4
Click App Firewall.
5
Click L2/L3 Rules.
6
Click Add.
A new row is added at the bottom of the DataCenter Rules section of the table.
7
Double-click each cell in the new row to type or select the appropriate information.
You can type IP addresses in the Source and Destination fields
8
(Optional) Select the Log check box to log all sessions matching this rule.
9
Click Commit.
N
Layer 2/Layer 3 firewall rules can also be created from the Flow Monitoring report. See
OTE
Firewall Rule from the Flow Monitoring Report"

Creating and Protecting Security Groups

The Security Groups feature enables you to create custom containers to which you can assign resources, such
as virtual machines and network adapters, for App Firewall protection. After a security group is defined, you
add the security group to a firewall rule for protection.

Add a Security Group

In the vSphere Client, you can add a security group at the datacenter resource level.
To add a security group by using the vSphere Client
1
Click a datacenter resource from the vSphere Client.
2
Click the vShield App tab.
3
Click Security Groups.
4
Click Add Group.
VMware, Inc.
Description
Container, direction in relation to container, or IP address with netmask (nn) from
which the communication originated
Container, direction in relation to container, or IP address with netmask (nn) which
the communication is targeting
Transport protocol used for communication
on page 65.
Chapter 13 App Firewall Management
"Add an App
73

Advertisement

Table of Contents
loading

Table of Contents