Spoofguard Screen Options; Enable Spoofguard; Approve Ip Addresses - VMware VSHIELD APP 1.0.0 UPDATE 1 Admin Manual

Hide thumbs Also See for VSHIELD APP 1.0.0 UPDATE 1:
Table of Contents

Advertisement

vShield Administration Guide

SpoofGuard Screen Options

The SpoofGuard screen displays the following options.
Table 13-1. SpoofGuard Screen Options
Option
Global Status
Inactive
Active Since Last Published
Unpublished IP assignment changes
Require Approval
Duplicate IP assignments

Enable SpoofGuard

You must enable SpoofGuard per datacenter to manage IP address assignments.
I
You must upgrade all vShield App instances to vShield App 1.0.0 Update 1 or later before you
MPORTANT
enable SpoofGuard.
To enable SpoofGuard
1
In the vShield Manager user interface, go to the Hosts and Clusters view.
2
Select a datacenter resource from the resource tree.
3
Click the SpoofGuard tab.
4
Click Edit to the right side of the Global Status heading.
5
For IP Assignment Tracking, click Enabled.
6
For Operation Mode, select one of the following:
Automatically Trust IP Assignments on Their First Use: Select this option to trust all IP assignments
upon initial registration with the vShield Manager.
Manually Inspect and Approve All IP Assignments Before Use: Select this option to require manual
approval of all IP addresses. All traffic to and from unapproved IP addresses is blocked.
7
Click Ok.

Approve IP Addresses

If you set SpoofGuard to require manual approval of all IP address assignments, you must approve IP address
assignments to allow traffic from those virtual machines to pass.
To approve an IP address
1
In the vShield Manager user interface, go to the Hosts and Clusters view.
2
Select a datacenter resource from the resource tree.
3
Click the SpoofGuard tab.
4
Click the Require Approval or Duplicate IP assignments link.
76
Description
Status of SpoofGuard as either enabled or disabled
List of IP addresses where the current IP address does not match the published
IP address.
List of IP addresses that have been validated since the policy was last updated
List of virtual machines for which you have edited the IP address assignment
but have not yet published
IP address changes that require approval before traffic can flow to or from these
virtual machines
IP addresses that are duplicates of an existing assigned IP address within the
selected datacenter
VMware, Inc.

Advertisement

Table of Contents
loading

Table of Contents