VMware vShield 1.0 Quick start guide

Category
Networking
Type
Quick start guide

VMware vShield vShield 1.0 is a network virtualization solution that provides security, isolation, and micro-segmentation for virtualized environments. It enables administrators to create and manage multiple isolated virtual networks within a single physical network infrastructure, providing greater flexibility and control over network resources. vShield vShield 1.0 includes features such as firewalling, intrusion detection, and traffic shaping, allowing administrators to enforce security policies and optimize network performance.

VMware vShield vShield 1.0 is a network virtualization solution that provides security, isolation, and micro-segmentation for virtualized environments. It enables administrators to create and manage multiple isolated virtual networks within a single physical network infrastructure, providing greater flexibility and control over network resources. vShield vShield 1.0 includes features such as firewalling, intrusion detection, and traffic shaping, allowing administrators to enforce security policies and optimize network performance.

Quick Start Guide
vShield Zones 1.0 Update 1
EN-000166-00
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.com
2 VMware, Inc.
Quick Start Guide
You can find the most up-to-date technical documentation on the VMware Web site at:
http://www.vmware.com/support/
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
docfeedback@vmware.com
© 2009 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property
laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents.
VMware, the VMware “boxes” logo and design, Virtual SMP, and VMotion are registered trademarks or trademarks of
VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks
of their respective companies.
VMware, Inc. 3
Contents
AboutThisBook 5
InstallingvShieldZones 7
Requirements 7
vShieldZonesComponents 8
EvaluatingESXNetworkConfigurationBeforeInstallingvShieldZones 8
InstallingvShieldZones 8
ObtainvShieldZonesVirtualAppliances 8
InstallthevShieldManagerasaVirtualMachineUsingthevSphereClient 9
InstallthevShieldAgentandConvertitintoaTemplate 10
LogIntothevShieldManagerUserInterfacetoConfiguretheSystem 10
Add
avShieldAgent 11
EnableContinuousDiscoverytoIdentifyYourGuestVirtualMachineTraffic 12
AdditionalvCenterConfigurationforvShieldAgents 12
PoweringoffvShieldZonesVirtualMachines 13
vShieldAgentAutomatedInstallationAtaGlance 14
UnderstandingthePortGroupsCreatedfromvShieldAgentInstallation 14
Quick Start Guide
4 VMware, Inc.
VMware, Inc. 5
TheQuickStartGuideprovidesinformationaboutinstallingvShieldZonesintoyourVMware
®
Virtual
Infrastructureenvironment.
Intended Audience
ThisbookisintendedforanyonewhowantstoinstallorusevShieldZones.Theinformationinthisbookis
writtenforexperiencedWindowsorLinuxsystemadministratorswhoarefamiliarwithvirtualmachine
technologyanddatacenteroperations.ThisbookalsoassumesfamiliaritywithVMwareVirtual
Infrastructure,includingvCenterServer4.0,
VMwareESX4.0,andthevSphereClient.
Document Feedback
VMwarewelcomesyoursuggestionsforimprovingourdocumentation.Ifyouhavecomments,sendyour
feedbacktodocfeedback@vmware.com.
VMware Infrastructure Documentation
ThefollowingdocumentscomprisethevShieldZonesdocumentationset:
vShieldZonesAdministrationGuide
vShieldZonesQuickStartGuide
IntroductiontovShieldZones
YoushouldalsohaveaccesstothecombinedvCenterServerandESXdocumentationset.
Technical Support and Education Resources
Thefollowingsectionsdescribethetechnicalsupportresourcesavailabletoyou.Toaccessthecurrentversion
ofthisbookandotherbooks,gotohttp://www.vmware.com/support/pubs.
Online and Telephone Support
Touseonlinesupporttosubmittechnicalsupportrequests,viewyourproductandcontractinformation,and
registeryourproducts,gotohttp://www.vmware.com/support.
Customerswithappropriatesupportcontractsshouldusetelephonesupportforthefastestresponseon
priority1issues.Gotohttp://www.vmware.com/support/phone_support.
Support Offerings
TofindouthowVMwaresupportofferingscanhelpmeetyourbusinessneeds,goto
http://www.vmware.com/support/services.
About This Book
Quick Start Guide
6 VMware, Inc.
VMware Professional Services
VMwareEducationServicescoursesofferextensivehandsonlabs,casestudyexamples,andcoursematerials
designedtobeusedasonthejobreferencetools.Coursesareavailableonsite,intheclassroom,andlive
online.Foronsitepilotprograms andimplementationbestpractices,VMwareConsultingServicesprovides
offeringsto helpyouassess,plan,
build,andmanageyourvirtualenvironment.Toaccessinformationabout
educationclasses,certificationprograms,andconsultingservices,gotohttp://www.vmware.com/services.
VMware, Inc. 7
vShieldZonesprovidesfirewallprotectionandtrafficanalysistoprotectyourVMwarevCenterServervirtual
infrastructure.vShieldZonesvirtualapplianceinstallationhasbeenautomatedformostvirtualdatacenters.
Thischapterincludesthefollowingtopics:
“Requirements”onpage 7
“vShieldZonesComponents”onpage 8
“EvaluatingESXNetworkConfigurationBeforeInstallingvShieldZones”onpage 8
“InstallingvShieldZones”onpage 8
“A d d i t i o n a lvCenterConfigurationforvShieldAgents”onpage 12
“PoweringoffvShieldZonesVirtualMachines”onpage 13
“vShieldAgentAutomatedInstallationAtaGlance”onpage 14
“UnderstandingthePortGroupsCreatedfromvShieldAgentInstallation”onpage 14
Requirements
BeforeinstallingvShieldZones,youmusthave:
AsystemrunningvCenterServer4.0orlater
AtleastonerunningESX4.0installation
APCwiththevSphereClient
Permissionstoaddandpoweronvirtualmachines
Accesstothedatastorewhereyoustorevirtualmachinefiles,andtheaccountpermissionstocopyfilesto
thatdatastore
vShieldManagerandvShieldagentOVFfiles
AstaticIPaddressforthemanagementinterfaceofeachvShieldagentyouinstall
AsinglestaticIPaddressforthevShieldManagermanagementinterface
EnablecookiesonyourWebbrowsertoaccessthevShieldManageruserinterface
Installing vShield Zones
Quick Start Guide
8 VMware, Inc.
vShield Zones Components
ThefollowingcomponentscomprisethevShieldZonessolution:
vShieldManager:ThevShieldZonesmanagementcenterthatmanagesallofthedistributedvShield
agents.Providesformonitoring,configuration,andsoftwareupdatingofyourvShieldagents.
vShieldagent:TheactivesecuritycomponentofvShieldZonesthatinspectstrafficflowandprovides
firewallprotection.YouinstallavShieldagentoneachESXhostyouwanttoprotect.AvShieldagent
installswithinthetrafficpathtomonitoralltrafficintoandoutofanESXhost,as
wellasbetweenvirtual
machinesonthehost.
Evaluating ESX Network Configuration Before Installing vShield Zones
PriortoinstallingvShieldZonesinyourvCenterServerenvironment,considerthenetworkconfigurationof
yourESXhosts.Ataminimum,eachhosthasatleastoneassociatedphysicalNICandonevSwitch,which
hoststheVMKernel,serviceconsole,andvirtualmachines.Inmorerobustenvironments,anESXhostmight
have
multiplededicatedphysicalNICsandmultiplevSwitchestoseparatetheVMKernelandserviceconsole
fromthevirtualmachines.
ThevShieldZonesappliancesinstallasvirtualmachinesonanESXhost.However,installationofavShield
agentrequiressomeplanning.YoucaninstallavShieldagentonanyvSwitchwithadedicated
NIC.vShield
agentinstallationmovesvirtualmachinesfromtheiroriginalvSwitchtoaclonedvSwitch.ThevShieldagent
theninstallsbetweentheoriginalvSwitchandtheclonedvSwitchtocapturealltraffictoandfromthevirtual
machines.TheoriginalvSwitchkeepstheNIC,whilethenewvSwitchdoesnot
associatewithaNIC.Thus,if
youhaveanESXhostwithmultiplevSwitcheshostingavarietyofvirtualmachines,youneedonevShield
agentpervSwitch.AnyvirtualmachinesconnectedtoavSwitchwhereavShieldagentisnotinstalledisnot
protectedbyvShieldZones.
Theinstallationofmultiple
vShieldagentsissimplifiedbyinstallingthevShieldagentOVFandthen
deployingtheoriginalvShieldagentvirtualmachineasatemplate.ThistemplateisreferencedbythevShield
Manager,allowingyoutoinstallmultiplevShieldagentsintoyourvCenterServerenvironmentfromthe
vShieldManageruserinterface.Formoreinformation
onthevShieldagentinstallationprocess,see“vShield
AgentAutomatedInstallationAtaGlance”onpage 14.
Installing vShield Zones
vShieldZonesinstallationisamultistepprocess.PerformthefollowingtasksinsequencetocompletevShield
Zonesinstallationsuccessfully.
Obtain vShield Zones Virtual Appliances
vShieldZonesvirtualappliancesarepackagedusingtheOpenVirtualizationFormat(OVF).Thispackaging
simplifiestheinstallationbyallowingyoutousethevSphereClienttoimportthevirtualapplianceintothe
datastoreandvirtualmachineinventory.
ContactyourVMwareaccountteamtoobtainavShieldZonessoftwarepackage,whichconsists
ofonevShield
ManagerandonevShieldagent.OnevShieldagentvirtualappliancecanbeusedformultiplevShieldagent
installations.
Onceyouhaveobtainedthepackage,downloadittoaPCwherethevSphereClientisinstalled.
N
OTEThevShieldZonessystemwasbuilttoprotectvirtualmachines,andnottheVMKernelorservice
console.
VMware, Inc. 9
Installing vShield Zones
Install the vShield Manager as a Virtual Machine Using the vSphere Client
vShieldManagervirtualmachineinstallationrequirescreatingaportgroupforthevShieldManager.
To add the vShield Manager to your vCenter Server inventory as a virtual machine
1LogintothevSphereClient.
2 SelectanESXhostfromtheinventorypanel.
3GotoFile>DeployOVFTemplate.
TheDeployOVFTemplatewizardopens.
4ClickDeployfromfileandclickBrowsetolocatethefolder
onyourPCcontainingthevShieldManager
OVFfile.
5Completethewizard.
ThevShieldManagerisinstalledintoyourinventory.
6 CreateaportgroupnamedvsmgmtforthevShieldManagerontheESXhostwherethevShieldManager
installed.
EachinstalledvShieldagentrecognizesthisportgroupname,whichpreventsthevShieldagent
from
movingthevShieldManagervirtualmachineduringvShieldagentinstallation.
7EditthesettingsofthevShieldManagervirtualmachinetoconnectatpoweronandsetthenetworklabel
tothevsmgmtportgroup.
aRightclickthevShieldManagervirtualmachineandclickEditSettings.
ThevShieldManager‐VirtualMachine
Propertiesdialogboxopens.
bUndertheHardwaretab,clickNetworkAdapter1.
c SelectConnectatpoweronunderDeviceStatus.
dIntheNetworklabeldropdownlistandselectvsmgmt.
eClickOKtoclosethewindow.
8PoweronthevShieldManagervirtualmachine.
9ClicktheConsoletabfromtherighthandpanetoopenthevShieldManagerCLI.
Thebootingprocessmighttakeacoupleofminutes.
10 Afterthemanager loginpromptappears,logintotheCLIbyusingtheusernameadmin andthe
passworddefault.
11 RunthesetupcommandtolaunchtheCLIsetupwizard.
TheCLIsetupwizardguidesyouthrough
IPaddressassignmentforthevShieldManagersmanagement
interfaceandidentificationofthedefaultnetworkgateway.TheIPaddressofthemanagementinterface
mustbereachablebyallinstalledvShieldagents,aswellasbyaWebbrowserforsystemmanagement.
manager> setup
Use ctrl-d to abort configuration dialog at any prompt.
Default settings are in square brackets '[]'.
Hostname [manager]:
IP Address [10.115.216.66/255.255.255.0]:
Default gateway [10.115.219.253]:
Old configuration will be lost, and system needs to be rebooted
Do you want to save new configuration (y/[n]): y
Please log out and log back in again.
Youdonotneedtologoutatthistime.vShieldManagerinstallationiscomplete.
Quick Start Guide
10 VMware, Inc.
12 Pingthedefaultgatewaytoverifynetworkconnectivity.
manager> ping 10.115.219.253
13 FromyourPC,pingthevShieldManagerIPaddresstovalidatethattheIPaddressisreachable.
14 InstallVMwareToolsonthevShieldManagervirtualmachine.
Install the vShield Agent and Convert it into a Template
InstallthevShieldagentasavirtualmachineandconvertitintoatemplate.AfterthevShieldagentvirtual
machineisconvertedtotemplateformat,thetemplatecanbereferencedbythevShieldManagerforvShield
agentinstallationonmultipleESXinstances.
To add the vShield agent to vCenter Server and convert it to a template
1LogintothevSphereClient.
2 SelectanESX
hostfromtheinventorypanel.
3GotoFile>DeployOVFTemplate.
TheDeployOVFTemplatewizardopens.
4ClickDeployfromfileandclickBrowsetolocatethefolderonyourclientmachinecontainingthevShield
agentOVFfile.
5Completethewizard.
ThevShieldagentisinstalledintoyourinventory.
6Afterthe
wizardcompletesinstallation,convertthevShieldagentintoavirtualmachinetemplate.
ThetemplateenablesautomatedinstallationofmultiplevShieldagentsfromthevShieldManageruser
interface.
Log In to the vShield Manager User Interface to Configure the System
AfterthevShieldManagervirtualappliancehasbeeninstalledandthevShieldagenthasbeenconvertedtoa
template,logintothevShieldManageruserinterfaceandconfigurethevShieldManagertoauthenticatewith
thevCenterServer.ThisauthenticationallowsthevShieldManagertodisplayyourvCenterServerinventory,
install
vShieldagents,andconfigurethefirewalltoprotectyourresources.
To log in to the vShield Manager user interface
1OpenaWebbrowserwindowandtypetheIPaddressassignedtothevShieldManager.
YoumustprependtheIPaddresswithhttps.
2Acceptthesecuritycertificate.
ThevShieldManagerloginscreenappears.
3LogintothevShieldManageruserinterfaceby
usingtheusernameadminandthepassworddefault.
ThevShieldManageruserinterfaceopenstotheConfiguration>vCentertabcontentintherightside
frame.Uponinitiallogin,noinformationisdisplayedinthevShieldManagerasyouhavenotyet
synchronizedcommunicationwiththevCenterServer.
CAUTIONDonotpoweronoreditthevShieldagentvirtualmachineatthistime.Poweringonorediting
thevirtualmachineatthispointcancausenetworkissues,suchasanendlessloop.
VMware, Inc. 11
Installing vShield Zones
4CompletethevCentertabformasfollows:
5ClickCommit.
ThevShieldManagerconnectstothevCenterServer,logsin,andaccessestheVMwareVirtual
InfrastructureSDK.TheinventorytreeontheleftsideofthevShieldManagerscreenshouldmatchyour
vSphereClientHosts&Clustersinventorytreeview.
Add a vShield Agent
YoucanaddvShieldagentstothevCenterServerandvShieldZonesinventoriesbycreatingclonesfromthe
vShieldagenttemplate.
YoushouldinstallonevShieldagentpervSwitchwithanattachedNIC.Anyvirtualmachinesconnectedtoa
vSwitchwhereavShieldagentisnotinstalledarenotprotectedby
vShieldZones.
To add a vShield agent
1LogintothevShieldManager.
2Fromtheinventorytree,clicktheESXhostthatyouwanttoprotect.
3ClicktheInstallvShieldtabthatappearsabovetherightframe.
4ClickConfigureinstallparameters.
5Completetheformasfollows:
Field Action
IPaddress/Name TypetheIPaddressofyourvCenterServer.
UserName TypeyourvSphereClientusername.
Password TypethepasswordassociatedwithyourvSphereClientusername.
NOTEThevShieldManagerdoesnotappearinthevShieldZonesinventorypanel.TheSettings&
ReportsobjectrepresentsthevShieldManagerintheinventorypanel.
NOTEToinstallavShieldagentonavNetworkDistributedSwitch(vNDS),refertothevShieldZones
AdministrationGuide.
Field Action
SelectfromavailablevShields Leavethisfieldblank.UsethisfieldonlywhenyouareaddingavShield
agentwithoutanestablishedtemplate.
Selecttemplatetoclone ClickthisdropdownmenuandselectthevShieldagenttemplate.
Selectadatastoretoplaceclone Clickthisdropdownmenuandselectthedatastore
onwhichtostorethe
vShieldagentclone.
Enteranamefortheclone TypeauniquenameforthevShieldagentclone.Thisnameappearsinyour
vSphereClientandvShieldManagerinventories.
SpecifyIPAddressofvShieldVM TypetheIPaddresstobeassignedtothevShieldagent’smanagement
port.
SpecifyIPMaskforvShield TypetheIPsubnetmaskassociatedwiththeassignedIPaddress.
SpecifyIPAddressofDefault
GatewayforvShield
TypetheIPaddressofthedefaultnetworkgateway
SpecifySecureKeyforvShield
(leaveblankfordefault)
(Optional)TypeakeytobeusedbetweenthevShieldagent
andthevShield
Managerforsecurecommunication.Bydefault,thisentryinthisfieldis
masked.Thisdefaultseedisusedforencryptedcommunicationbetweenthe
vShieldagentandthevShieldManager.Keysarenotsharedacrossthe
network.
SelectavSwitchtoshield Clickthisdropdownmenuandselect
thevSwitchtoprotect.ThevSwitches
eligibleforprotectionarehighlightedingreenintheaccompanyingtable.
Quick Start Guide
12 VMware, Inc.
6ClickContinue.
Theinstallationsummaryscreenappears.Thisscreendisplaysbeforeandafterexampleillustrationsof
installingavShieldagentontheESX.
7ClickInstall.
YoucanfollowthevShieldagentinstallationstepsfromtheRecentTasksstatuspanelocatedatthebottom
ofthevSphereClientwindow.Formoredetails
ontheinstallationprocess,see“vShieldAgentAutomated
InstallationAtaGlance”onpage 14.
vShieldagentinstallationiscomplete.
8Afterinstallationhascompleted,openyourvSphereClient.
9 LocatethevShieldagentinyourinventory.
Notethatitispoweredon.
10 InstallVMwareToolsonthevShieldManagervirtualmachine.
Enable Continuous Discovery to Identify Your Guest Virtual Machine Traffic
AfteryourvShieldManagerandvShieldagentareinstalled,andyourvShieldagentcommunicateswithyour
vShieldManager,youmustenablethecontinuousdiscoveryoperationforthevShieldagenttoprotectyour
virtualmachines.
To enable continuous discovery of virtual machine traffic
1LogintothevShieldManager.
2ClickthevShieldagentfromtheinventorytree.
3ClicktheVMDiscovery
tab.
4ClicktheAutomatedsubhead.
5IntheScheduledDiscoveryStatusdropdownmenu,selectContinuous.
Donotcompleteanyotherfieldsintheform.
6ClickOK.
Thediscoveryoperationbegins.Discoveryrunscontinuously,identifyingtrafficflowsbyapplicationand
protocolspecifications.
7GotoVMDiscovery>Resultstoviewthediscoveryoutput.
DiscoveredtrafficisseparatedbyvirtualmachineIPaddress.Eachdiscoveredvirtualmachineissaved
undertheVMInventorytab,whichisavailableatthedatacenterandclustercontainerlevels,aswellas
atthevirtualmachinelevelwithinthevShieldManager.
Additional vCenter Configuration for vShield Agents
IfyouhaveenabledtheVMwareHAorVMwareDRSfeatures,youmustdisablemovementofvShieldagent
virtualmachines.ThismustbeperformedafterinstallationofeachvShieldagentvirtualmachine.
YoucanmigratethevShieldManagervirtualappliancebyusingVMotionwithoutconsequence.
To disable VMware HA or VMware DRS from moving the vShield agent virtual machines
1LogintothevSphereClient.
2RightclicktheclustercontainingyourvShieldagentvirtualmachinesandclickEditProperties.
N
OTETheexampleillustrationsarestaticanddonotdirectlyreflectyourvirtualnetwork.Thenumbered
installationscriptontherighthandsideofthescreendetailstheactualinstallationsteps.
VMware, Inc. 13
Installing vShield Zones
TheAdminSettingsdialogboxopens.
3UnderVMwareHA,clickVirtualMachineOptions.
LocatethevShieldagentsinthelist.
4ForeachvShieldagentvirtualmachine,selectthefollowingvalues:
VMRestartPriority:Disabled
HostIsolationResponse:LeaveVMpoweredon
5IfyouhaveenabledDRS,clickVirtualMachineOptionsunderVMwareDRS.
LocatethevShieldagentsinthelist.
6ForeachvShieldagentvirtualmachine,selectDisabledforAutomationLevel.
7ClickOKafterallvShieldagentvirtualmachineshavebeenconfigured.
Indefaultoperation,a
vShieldagentraisesanerrorduringattemptedvirtualmachinemigrationbythe
operatororVMotion.Theerrorstatesthattheserverisconnectedtoavirtualintranet.Thisvirtualintranetis
thevSwitchthatavirtualmachineconnectstoontheprotectedsideofthevShieldagent.ThisvSwitchdoes
not
homeaphysicalNIC.ThevShieldagentbridgestraffictotheunprotectedsideofthenetworkthatis
connectedtoaphysicalNIC.
To enable VMotion to disable the virtual intranet check
1 Locatethevpxd.cfgfileonthemachinerunningvCenterServer.Bydefault,thisfileisinstalledat
C:\Documents and Settings\All Users\Application Data\VMware\VMware vCenter Server.
2Editthevpxd.cfgfileinatexteditor.
Addthe
followinglinesasasubleveltotheconfigsection,andatthesamelevelasthevpxdsection.
<migrate>
<test>
<CompatibleNetworks>
<VMOnVirtualIntranet>false</VMOnVirtualIntranet>
</CompatibleNetworks>
</test>
</migrate>
3 Savethevpxd.cfgfile.
4RestarttheVMwarevCenterServerservice.YoucanaccesstheservicemenubygoingtoControlPanel
>AdministrativeTools>Services.
TofurtherconfigurevShieldZones,refertothevShieldZonesAdministrationGuide.
Powering off vShield Zones Virtual Machines
YoucanpoweroffvShieldZonesvirtualmachinesatanytime.WhenyoupoweroffavShieldZonesvirtual
machine,thelastsavedconfigurationisusedwhenthevirtualmachineispoweredon.
To power off vShield Zones virtual machines
1InthevSphereClient,selectthevShieldZonesvirtualmachinesfromtheinventorypanel.
2ClicktheConsoletab
toopenthevShieldZonesCLI.
3LogintotheCLI.
4Afterloggingin,typeenabletoenterPrivilegedmode.
5Typeshutdown.
6AfterCLIshutdowniscompleted,rightclickthevirtualmachinefromtheinventorypanelandselect
Power>PowerOff.
Quick Start Guide
14 VMware, Inc.
vShield Agent Automated Installation At-a-Glance
Wheninstalledfromareferencedtemplate,thevShieldagentinstallationprocessperformsthefollowing
steps:
1CreatesacloneofthevSwitchhost.
ThisvSwitchclonedoesnotincludeaNIC.ThenameofthevSwitchcloneincludesthenameofthe
vSwitchhostwith_VSappended:vSwitch1_VS.
2Createsaprotectedzoneport
group,VSprot_vShieldagentname,andattachesthisportgrouptothevSwitch
host.
3Createsamanagementportgroup,VSmgmt_vShieldagentname,onthevSwitchhostforthevShield
agent’smanagementinterface.
4Createsanunprotectedzoneportgroup,VSunprot_vShieldagentname,andattachesthisportgrouptothe
vSwitchclone.
5 Connectsandpowers
onthevShieldagent.
6 AttachesthevirtualinterfacesonthevShieldagenttotheprotectedandunprotectedportgroups.
7MovesthevirtualmachinesfromthevSwitchhosttothevSwitchclone.
IfthevShieldManagervirtualmachineresidesonthesamevSwitch,itisnotmoved.DuringvShield
Managerinstallation,youcreated
aportgroupcalledvsmgmtinwhichtoplacethevShieldManager.
vShieldagentinstallationrecognizesthisportgroupnameandignoresanyvirtualmachinesinthisport
group.
Figure 1. Installation of a vShield agent on a vSwitch
Understanding the Port Groups Created from vShield Agent Installation
vShieldagentinstallationrequiresthecreationoftwoportgroups.Theseportgroupsdelineatezonesoftrust:
unprotectedandprotected.Theunprotectedzonemonitorsincomingtraffic,whiletheprotectedzone
monitorsoutgoingtraffic.EachportgrouphomesavShieldagentinterface:U0fortheunprotectedzoneand
P0fortheprotected
zone.ConnectingtheseinterfacestothecreatedportgroupsenablesthevShieldagentto
monitorallincomingandoutgoingtraffic.
I
MPORTANTDonotaddvirtualmachinestotheprotectedorunprotectedportgroups.Theseportgroups
areconfiguredwithpromiscuousmodeturnedon,whichallowsthevShieldagenttoseeallpassing
traffic.
ESX
VMkernel
service
console
virtual
machine
vShield
vSwitch0
vSwitch1
vSwitch1_VS
virtual
machine
VMware, Inc. 15
Installing vShield Zones
Theunprotectedandprotectedportgroupsareconfiguredwithpromiscuousmodeenabled.Inpromiscuous
mode,aguestadaptercanlistentoallpassingpackets.Innonpromiscuousmode,aguestadapterlistensto
trafficonlyonitsownMACaddress.Bydefault,guestadaptersaresettononpromiscuousmode.For
protectionpurposes,thevShieldagentmustbeabletoseeallpassingtraffic.Donotaddanyothervirtual
machinestotheseportgroups.
Quick Start Guide
16 VMware, Inc.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16

VMware vShield 1.0 Quick start guide

Category
Networking
Type
Quick start guide

VMware vShield vShield 1.0 is a network virtualization solution that provides security, isolation, and micro-segmentation for virtualized environments. It enables administrators to create and manage multiple isolated virtual networks within a single physical network infrastructure, providing greater flexibility and control over network resources. vShield vShield 1.0 includes features such as firewalling, intrusion detection, and traffic shaping, allowing administrators to enforce security policies and optimize network performance.

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI