VMware, Inc. 15
Chapter 2 Preparing for Installation
How Do I Isolate a Group of Virtual Machines?
YoucanusevShieldEdgewiththePortGroupIsolationfeatureorVLANstoisolatevirtualmachinesfromthe
externalnetwork.
1InstallPortGroupIsolationoneachESXhostthatavDSspans.
2 CreateaportgrouponthevDS.
3EnablePortGroupIsolationonthevDS.
4InstallavShieldEdgeonthe
portgroup.
5Movethevirtualmachinestotheportgroup.
6ConfigurevShieldEdgeNATrulesfortrafficinandoutoftheportgroup.
vShield Manager Uptime
ThevShieldManagershouldberunonanESXhostthatisnotaffectedbydowntime,suchasfrequentreboots
ormaintenancemodeoperations.YoucanuseHAorDRStoincreasetheresilienceofthevShieldManager.If
theESXhostonwhichthevShieldManagerresidesisexpectedto
requiredowntime,vMotionthevShield
ManagervirtualappliancetoanotherESXhost.Thus,morethanoneESXhostisrecommended.
Communication Between vShield Components
ThemanagementinterfacesofvShieldcomponentsshouldbeplacedinacommonnetwork,suchasthe
vSpheremanagementnetwork.ThevShieldManagerrequiresconnectivitytothevCenterServer,aswellas
allvShieldAppandvShieldEdgeinstances.vShieldcomponentscancommunicateoverroutedconnections
aswellasdifferentLANs.
Hardening Your vShield Virtual Machines
YoucanaccessthevShieldManagerandothervShieldcomponentsbyusingaweb‐baseduserinterface,
commandlineinterface,andRESTAPI.vShieldincludesdefaultlogincredentialsforeachoftheseaccess
options.AfterinstallationofeachvShieldvirtualmachine,youshouldhardenaccessbychangingthedefault
logincredentials.
vShield Manager User Interface
YouaccessthevShieldManageruserinterfacebyopeningawebbrowserwindowandnavigatingtotheIP
addressofthevShieldManager’smanagementport.Thedefaultuseraccount,admin,hasglobalaccesstothe
vShieldManager.Afterinitiallogin,youshouldchangethedefaultpasswordoftheadminuseraccount.
See
“ChangethePasswordofthevShieldManagerUserInterfaceDefaultAccount”onpage 20.
Command Line Interface
YoucanaccessthevShieldManager,vShieldApp,andvShieldEdgevirtualappliancesbyusingacommand
lineinterfaceviavSphereClientconsolesession.Eachvirtualapplianceusesthesamedefaultusername
(admin)andpassword(default)combinationasthevShieldManageruserinterface.EnteringEnabledmode
alsousesthe
passworddefault.
FormoreonhardeningtheCLI,seethevShieldAdministrationGuide.
NOTEYoucanalsouseVLANstoisolatevirtualmachinesprotectedbyavShieldEdge.Ifyouuse
VLANs,theinternalportgroupconnectedtoavShieldEdgemusthaveaVLANtagthatisdifferentfrom
theexternalportgroup.
NOTEThevShieldManagermustbeinthesamevCenterServerenvironmentasthevShieldcomponentsto
bemanaged.YoucannotusethevShieldManageracrossdifferentvCenterServerenvironments.