Quick Start Guide
8 VMware, Inc.
vShield Zones Components
ThefollowingcomponentscomprisethevShieldZonessolution:
vShieldManager:ThevShieldZonesmanagementcenterthatmanagesallofthedistributedvShield
agents.Providesformonitoring,configuration,andsoftwareupdatingofyourvShieldagents.
vShieldagent:TheactivesecuritycomponentofvShieldZonesthatinspectstrafficflowandprovides
firewallprotection.YouinstallavShieldagentoneachESXhostyouwanttoprotect.AvShieldagent
installswithinthetrafficpathtomonitoralltrafficintoandoutofanESXhost,as
wellasbetweenvirtual
machinesonthehost.
Evaluating ESX Network Configuration Before Installing vShield Zones
PriortoinstallingvShieldZonesinyourvCenterServerenvironment,considerthenetworkconfigurationof
yourESXhosts.Ataminimum,eachhosthasatleastoneassociatedphysicalNICandonevSwitch,which
hoststheVMKernel,serviceconsole,andvirtualmachines.Inmorerobustenvironments,anESXhostmight
have
multiplededicatedphysicalNICsandmultiplevSwitchestoseparatetheVMKernelandserviceconsole
fromthevirtualmachines.
ThevShieldZonesappliancesinstallasvirtualmachinesonanESXhost.However,installationofavShield
agentrequiressomeplanning.YoucaninstallavShieldagentonanyvSwitchwithadedicated
NIC.vShield
agentinstallationmovesvirtualmachinesfromtheiroriginalvSwitchtoaclonedvSwitch.ThevShieldagent
theninstallsbetweentheoriginalvSwitchandtheclonedvSwitchtocapturealltraffictoandfromthevirtual
machines.TheoriginalvSwitchkeepstheNIC,whilethenewvSwitchdoesnot
associatewithaNIC.Thus,if
youhaveanESXhostwithmultiplevSwitcheshostingavarietyofvirtualmachines,youneedonevShield
agentpervSwitch.AnyvirtualmachinesconnectedtoavSwitchwhereavShieldagentisnotinstalledisnot
protectedbyvShieldZones.
Theinstallationofmultiple
vShieldagentsissimplifiedbyinstallingthevShieldagentOVFandthen
deployingtheoriginalvShieldagentvirtualmachineasatemplate.ThistemplateisreferencedbythevShield
Manager,allowingyoutoinstallmultiplevShieldagentsintoyourvCenterServerenvironmentfromthe
vShieldManageruserinterface.Formoreinformation
onthevShieldagentinstallationprocess,see“vShield
AgentAutomatedInstallationAt‐a‐Glance”onpage 14.
Installing vShield Zones
vShieldZonesinstallationisamulti‐stepprocess.PerformthefollowingtasksinsequencetocompletevShield
Zonesinstallationsuccessfully.
Obtain vShield Zones Virtual Appliances
vShieldZonesvirtualappliancesarepackagedusingtheOpenVirtualizationFormat(OVF).Thispackaging
simplifiestheinstallationbyallowingyoutousethevSphereClienttoimportthevirtualapplianceintothe
datastoreandvirtualmachineinventory.
ContactyourVMwareaccountteamtoobtainavShieldZonessoftwarepackage,whichconsists
ofonevShield
ManagerandonevShieldagent.OnevShieldagentvirtualappliancecanbeusedformultiplevShieldagent
installations.
Onceyouhaveobtainedthepackage,downloadittoaPCwherethevSphereClientisinstalled.
N
OTEThevShieldZonessystemwasbuilttoprotectvirtualmachines,andnottheVMKernelorservice
console.