VMware vShield 4.1 User guide

Category
System management software
Type
User guide

This manual is also suitable for

vShield Administration Guide
vShield Manager 4.1.0 Update 1
vShield Zones 4.1.0 Update 1
vShield Edge 1.0.0 Update 1
vShield App 1.0.0 Update 1
vShield Endpoint 1.0.0 Update 1
This document supports the version of each product listed and
supports all subsequent versions until the document is replaced
by a new edition. To check for more recent editions of this
document, see http://www.vmware.com/support/pubs.
EN-000374-02
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.com
2 VMware, Inc.
vShield Administration Guide
You can find the most up-to-date technical documentation on the VMware Web site at:
http://www.vmware.com/support/
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
docfeedback@vmware.com
Copyright © 2010 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and
intellectual property laws. VMware products are covered by one or more patents listed at
http://www.vmware.com/go/patents.
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks
and names mentioned herein may be trademarks of their respective companies.
VMware, Inc. 3
Contents
AboutThisBook 9
vShieldManagerandvShieldZones
1 OverviewofvShield 13
vShieldComponents 13
vShieldManager 13
vShieldZones 13
vShieldEdge 14
vShieldApp 14
vShieldEndpoint 15
MigrationofvShieldComponents 15
VMwareTools 15
PortsRequiredforvShieldCommunication 15
2 vShieldManagerUserInterfaceBasics 17
LoggingintothevShieldManagerUserInterface 17
AccessingtheOnlineHelp 18
vShieldManagerUserInterface 18
vShieldManagerInventoryPanel 18
vShieldManagerConfigurationPanel 19
3 ManagementSystemSettings 21
IdentifyYourvCenterServer 21
RegisterthevShieldManagerasavSphereClientPlugin 22
IdentifyDNSServices 22
SetthevShieldManagerDateandTime 23
IdentifyaProxyServer 23
DownloadaTechnicalSupportLogfromaComponent 23
BackUpvShieldManagerData 24
ViewvShieldManagerSystemStatus 24
AddanSSLCertificatetoIdentifythevShieldManager
WebService 24
4 ZonesFirewallManagement 27
UsingZonesFirewall 27
DefaultRules 28
Layer4RulesandLayer2/Layer3Rules 28
HierarchyofZonesFirewallRules 28
PlanningZonesFirewallRuleEnforcement 28
CreateaZonesFirewallRule 29
CreateaLayer2/Layer3ZonesFirewallRule 30
ValidatingActiveSessionsagainsttheCurrentZonesFirewallRules 31
ReverttoaPreviousZonesFirewallConfiguration 31
DeleteaZones
FirewallRule 32
vShield Administration Guide
4 VMware, Inc.
5 UserManagement 33
ManagingUserRights 33
ManagingtheDefaultUserAccount 34
AddaUser 34
AssignaRoleandRightstoaUser 34
EditaUserAccount 34
DeleteaUserAccount 35
6 UpdatingSystemSoftware 37
ViewtheCurrentSystemSoftware 37
UploadanUpdate 37
ReviewtheUpdateHistory 38
7 BackingUpvShieldManagerData 39
BackUpYourvShieldManagerDataonDemand 39
ScheduleaBackupofvShieldManagerData 40
RestoreaBackup 40
8 SystemEventsandAuditLogs 41
ViewtheSystemEventReport 41
SystemEventNotifications 42
vShieldManagerVirtualApplianceEvents 42
vShieldAppEvents 42
SyslogFormat 42
ViewtheAuditLog 43
9 UninstallingvShieldComponents 45
UninstallavShieldApporvShieldZones 45
UninstallavShieldEdgefromaPortGroup 46
UninstallPortGroupIsolationfromanESXHost 46
UninstallavShieldEndpointModule 47
UnregisteranSVMfromavShieldEndpointModule 47
UninstallthevShieldEndpointModulefromthevSphereClient 47
10 vShieldEdgeManagement 49
ViewtheStatusofavShieldEdge 49
SpecifyaRemoteSyslogServer 50
ManagingthevShieldEdgeFirewall 50
CreateavShieldEdgeFirewallRule 50
ValidateActiveSessionsAgainstCurrentvShieldEdgeFirewallRules 51
ManageNATRules 51
ManageDHCPService 52
ManageVPNService 53
ManageLoadBalancerService 55
StartorStopvShieldEdgeServices 56
UpgradevShieldEdgeSoftware 56
VMware, Inc. 5
vShieldEdgeandPortGroupIsolation
vShieldAppandvShieldEndpoint
11 vShieldAppManagement 61
SendvShieldAppSystemEventstoaSyslogServer 61
BackUptheRunningCLIConfigurationofavShieldApp 62
ViewtheCurrentSystemStatusofavShieldApp 62
ForceavShieldApptoSynchronizewiththevShieldManager 62
RestartavShieldApp 63
ViewTrafficStatisticsbyvShieldAppInterface 63
12 FlowMonitoring 65
UsingFlowMonitoring 65
ViewaSpecificApplicationintheFlowMonitoringCharts 66
ChangetheDateRangeoftheFlowMonitoringCharts 66
ViewtheFlowMonitoringReport 66
AddanAppFirewallRulefromtheFlowMonitoringReport 67
DeleteAllRecordedFlows 68
EditingPortMappings 68
AddanApplicationPortPairMapping 68
DeleteanApplicationPortPairMapping 69
HidethePortMappingsTable 69
13 AppFirewallManagement 71
UsingAppFirewall 71
SecuringContainersandDesigningSecurityGroups 71
DefaultRules 72
Layer4RulesandLayer2/Layer3Rules 72
HierarchyofAppFirewallRules 72
PlanningAppFirewallRuleEnforcement 72
CreateanAppFirewallRule 73
CreateaLayer2/Layer3AppFirewallRule 75
CreatingandProtectingSecurityGroups 75
AddaSecurityGroup 75
AssignResourcestoaSecurity
Group 76
ValidatingActiveSessionsagainsttheCurrentAppFirewallRules 76
ReverttoaPreviousAppFirewallConfiguration 77
DeleteanAppFirewallRule 77
UsingSpoofGuard 77
SpoofGuardScreenOptions 78
EnableSpoofGuard 78
ApproveIPAddresses 78
EditanIPAddress 79
DeleteanIPAddress 79
14 vShieldEndpointEventsandAlarms 81
ViewvShieldEndpointStatus 81
Alarms 82
HostAlarms 82
SVMAlarms 82
VMAlarms 83
VMware, Inc. 6
Events 83
AuditMessages 86
Appendixes
A CommandLineInterface 89
LoggingInandOutoftheCLI 89
CLICommandModes 89
CLISyntax 90
MovingAroundintheCLI 90
GettingHelpwithintheCLI 91
SecuringCLIUserAccountsandthePrivilegedModePassword 91
AddaCLIUserAccount 91
DeletetheadminUserAccountfromtheCLI 92
ChangetheCLIPrivilegedModePassword 92
CommandReference 93
AdministrativeCommands 93
CLIMode
Commands 94
ConfigurationCommands 97
DebugCommands 104
ShowCommands 109
DiagnosticsandTroubleshootingCommands 125
UserAdministrationCommands 128
TerminalCommands 130
DeprecatedCommands 131
B vShieldEdgeVPNConfigurationExamples 133
BasicScenario 133
Terminology 134
IKEPhase1andPhase2134
Phase1:MainModeTransactions 135
Phase2:QuickModeTransactions 135
ConfiguringthevShieldEdgeVPNParameters 135
UsingaCisco2821IntegratedServicesRouter 137
ConfigureInterfacesandDefaultRoute 137
ConfigureIKEPolicy 137
MatchEachPeerwithItsPreSharedSecret 138
DefinetheIPSECTransform 138
CreatetheIPSECAccess
List 138
BindthePolicywithaCryptoMapandLabelIt 138
BindtheCryptoMaptotheOutgoingInterface 138
ExampleConfiguration 138
UsingaCiscoASA5510 139
UsingaWatchGuardFireboxX500 141
Troubleshooting 141
SuccessfulNegotiation(bothPhase1andPhase2) 141
Phase1PolicyNotMatching 142
Phase2NotMatching 143
PFSMismatch 143
PSKNotMatching 144
PacketCapturefor
aSuccessfulNegotiation 144
VMware, Inc. 7
C Troubleshooting 149
TroubleshootingvShieldManagerInstallation 149
vShieldOVAFileExtractedtoaPCWherevSphereClientIsNotInstalled 149
vShieldOVAFileCannotBeInstalledinvSphereClient 149
CannotLogIntoCLIAfterthevShieldManagerVirtualMachineStarts 150
CannotLogIntothevShieldManagerUserInterface 150
TroubleshootingOperationIssues 150
vShieldManagerCannotCommunicate
withavShieldApp 150
CannotConfigureavShieldApp 150
FirewallBlockRuleNotBlockingMatchingTraffic 151
NoFlowDataDisplayinginFlowMonitoring 151
TroubleshootingPortGroupIsolationIssues 151
ValidateInstallationofPortGroupIsolation 151
VerifyInstallorUninstallScript 152
ValidatetheDataPath 152
DetailsofthefenceutilUtility 153
TroubleshootingvShieldEdgeIssues 154
VirtualMachines
AreNotGettingIPAddressesfromtheDHCPServer 154
LoadBalancerDoesNotWork 154
LoadBalancerThrowsError502BadGatewayforHTTPRequests 155
VPNDoesNotWork 155
TroubleshootingvShieldEndpointIssues 155
ThinAgentLogging 155
ComponentVersionCompatibility 156
Index 157
VMware, Inc. 8
VMware, Inc. 9
Thismanual,thevShieldAdministrationGuide,describeshowtoinstall,configure,monitor,andmaintainthe
VMware
®
vShield™systembyusingthevShieldManageruserinterface,thevSphereClientplugin,and
commandlineinterface(CLI).Theinformationincludesstepbystepconfigurationinstructions,and
suggestedbestpractices.
Intended Audience
ThismanualisintendedforanyonewhowantstoinstallorusevShieldinaVMwarevCenterenvironment.
Theinformationinthismanualiswrittenforexperiencedsystemadministratorswhoarefamiliarwithvirtual
machinetechnologyandvirtualdatacenteroperations.ThismanualassumesfamiliaritywithVMware
Infrastructure4.x,includingVMwareESX,
vCenterServer,andthevSphereClient.
VMware Technical Publications Glossary
VMwareTechnicalPublicationsprovidesaglossaryoftermsthatmightbeunfamiliartoyou.Fordefinitions
oftermsastheyareusedinVMwaretechnicaldocumentationgotohttp://www.vmware.com/support/pubs.
Document Feedback
VMwarewelcomesyoursuggestionsforimprovingourdocumentation.Ifyouhavecomments,sendyour
feedbacktodocfeedback@vmware.com.
vShield Documentation
ThefollowingdocumentscomprisethevShielddocumentationset:
vShieldAdministrationGuide,thisguide
vShieldQuickStartGuide
vShieldAPIProgrammingGuide
Technical Support and Education Resources
Thefollowingsectionsdescribethetechnicalsupportresourcesavailabletoyou.Toaccessthecurrentversion
ofthisbookandotherbooks,gotohttp://www.vmware.com/support/pubs.
Online and Telephone Support
Touseonlinesupporttosubmittechnicalsupportrequests,viewyourproductandcontractinformation,and
registeryourproducts,gotohttp://www.vmware.com/support.
Customerswithappropriatesupportcontractsshouldusetelephonesupportforthefastestresponseon
priority1issues.Gotohttp://www.vmware.com/support/phone_support.
About This Book
vShield Administration Guide
10 VMware, Inc.
Support Offerings
TofindouthowVMwaresupportofferingscanhelpmeetyourbusinessneeds,goto
http://www.vmware.com/support/services.
VMware Professional Services
VMwareEducationServicescoursesofferextensivehandsonlabs,casestudyexamples,andcoursematerials
designedtobeusedasonthejobreferencetools.Coursesareavailableonsite,intheclassroom,andlive
online.Foronsitepilotprograms andimplementationbestpractices,VMwareConsultingServicesprovides
offeringsto helpyouassess,plan,
build,andmanageyourvirtualenvironment.Toaccessinformationabout
educationclasses,certificationprograms,andconsultingservices,gotohttp://www.vmware.com/services.
VMware, Inc. 11
vShield Manager and vShield Zones
vShield Administration Guide
12 VMware, Inc.
VMware, Inc. 13
1
VMware
®
vShieldisasuiteofsecurityvirtualappliancesbuiltforVMwarevCenter™ServerandVmware
ESX™integration.vShieldisacriticalsecuritycomponentforprotectingvirtualizeddatacentersfromattacks
andmisusehelpingyouachieveyourcompliancemandatedgoals.
ThisguideassumesyouhaveadministratoraccesstotheentirevShieldsystem.The
viewableresourcesinthe
vShieldManageruserinterfacecandifferbasedontheassignedroleandrightsofauser,andlicensing.Ifyou
areunabletoaccessascreenorperformaparticulartask,consultyourvShieldadministrator.
Thischapterincludesthefollowingtopics:
“vShieldComponents”onpage 13
“MigrationofvShieldComponents”onpage 15
“VMwareTools”onpage 15
“PortsRequiredforvShieldCommunication”onpage 15
vShield Components
vShieldincludescomponentsandservicesessentialforprotectingvirtualmachines.vShieldcanbeconfigured
throughawebbaseduserinterface,avSphereClientplugin,acommandlineinterface(CLI),andRESTAPI.
TorunvShield,youneedonevShieldManagervirtualmachineandatleastonevShieldApporvShield
Edge
module.
vShield Manager
ThevShieldManageristhecentralizednetworkmanagementcomponentofvShieldandisinstalledfromOVA
asavirtualmachinebyusingthevSphereClient.UsingthevShieldManageruserinterface,administrators
install,configure,andmaintainvShieldcomponents.AvShieldManagercanrunonadifferentESXhostfrom
yourvShield
AppandvShieldEdgemodules.
ThevShieldManagerleveragestheVMwareInfrastructureSDKtodisplayacopyofthevSphereClient
inventorypanel.
FormoreontheusingthevShieldManageruserinterface,seeChapter 2,“vShieldManagerUserInterface
Basics,”onpage 17.
vShield Zones
vShieldZones,includedwiththevShieldManager,providesfirewallprotectionfortrafficbetweenvirtual
machines.ForeachZonesFirewallrule,youcanspecifythesourceIP,destinationIP,sourceport,destination
port,andservice.
Overview of vShield
1
CAUTIONDonotinstallvShieldZones/AppontheESXhostwherevCenterServerisrunning.
vShield Administration Guide
14 VMware, Inc.
vShield Edge
vShieldEdgeprovidesnetworkedgesecurityandgatewayservicestoisolatethevirtualmachinesinaport
group,vDSportgroup,orCisco
®
Nexus1000V.ThevShieldEdgeconnectsisolated,stubnetworkstoshared
(uplink)networksbyprovidingcommongatewayservicessuchasDHCP,VPN,NAT,andLoadBalancing.
CommondeploymentsofvShieldEdgeincludeintheDMZ,VPNExtranets,andmultitenantCloud
environmentswherethevShieldEdgeprovidesperimetersecurityfor
VirtualDatacenters(VDCs).
Standard vShield Edge Services (Including Cloud Director)
Firewall:SupportedrulesincludeIP5tupleconfigurationwithIPandportrangesforstatefulinspection
forTCP,UDP,andICMP.
NetworkAddressTranslation:SeparatecontrolsforSourceandDestinationIPaddresses,aswellasTCP
andUDPporttranslation.
DynamicHostConfigurationProtocol(DHCP):ConfigurationofIPpools,gateways,DNSservers,and
searchdomains.
Advanced vShield Edge Services
SitetoSiteVirtualPrivateNetwork(VPN):UsesstandardizedIPsecprotocolsettingstointeroperatewith
allmajorfirewallvendors.
LoadBalancing:SimpleanddynamicallyconfigurablevirtualIPaddressesandservergroups.
vShieldEdgesupportssyslogexportforallservicestoremoteservers.
vShield App
vShieldAppisaninterior,vNIClevelfirewallthatallowsyoutocreateaccesscontrolpoliciesregardlessof
networktopology.AvShieldAppmonitorsalltrafficinandoutofanESXhost,includingbetweenvirtual
machinesinthesameportgroup.vShieldAppincludestrafficanalysisandcontainerbasedpolicy
creation.
vShieldAppinstallsasahypervisormoduleandfirewallservicevirtualappliance.vShieldAppintegrates
withESXhoststhroughVMsafeAPIsandworkswithVMwarevSphereplatformfeaturessuchasDRS,
vMotion,DPM,andmaintenancemode.
vShieldAppprovidesfirewallingbetweenvirtualmachinesbyplacingafirewallfilteronevery
virtual
networkadapter.Thefirewallfilteroperatestransparentlyanddoesnotrequirenetw orkchangesor
modificationofIPaddressestocreatesecurityzones.YoucanwriteaccessrulesbyusingvCentercontainers,
likedatacenters,cluster,resourcepoolsandvApps,ornetworkobjects,likePortGroupsandVLANs,to
reducethenumber
offirewallrulesandmaketheruleseasiertotrack.
YoushouldinstallvShieldAppinstancesonallESXhostswithinaclustersothatVMwarevMotion™
operationsworkandvirtualmachinesremainprotectedastheymigratebetweenESXhosts.Bydefault,a
vShieldAppvirtualappliancecannotbemovedby
usingvMotion.
TheFlowMonitoringfeaturedisplaysallowedandblockednetworkflowsattheapplicationprotocollevel.
Youcanusethisinformationtoauditnetworktrafficandtroubleshootoperational.
N
OTEYoumustobtainanevaluationorfulllicensetousevShieldEdge.
NOTEYoumustobtainanevaluationorfulllicensetousevShieldApp.
CAUTIONDonotinstallvShieldZones/AppontheESXhostwherevCenterServerisrunning.
VMware, Inc. 15
Chapter 1 Overview of vShield
vShield Endpoint
vShieldEndpointdeliversanintrospectionbasedantivirussolution.vShieldEndpointusesthehypervisorto
scanguestvirtualmachinesfromtheoutsidewithoutabulkyagent.vShieldEndpointisefficientinavoiding
resourcebottleneckswhileoptimizingmemoryuse.
vShieldEndpointinstallsasahypervisormoduleandsecurityvirtualappliancefromathird
partyantivirus
vendor(VMwarepartners)onanESXhost.
vShieldEndpointprovidesthefollowingfeatures:
Ondemandfilescanninginaservicevirtualmachine.
Onaccessfilescanninginaservicevirtualmachine.
Migration of vShield Components
ThevShieldManagerandvShieldEdgevirtualappliancescanbeautomaticallyormanuallymigratedbased
onDRSandHApolicies.ThevShieldManagermustalwaysbeup,soyoumustmigratethevShieldManager
wheneverthecurrentESXhostundergoesarebootormaintenancemoderoutine.
EachvShieldEdgeshouldmove
withitssecuredportgrouptomaintainsecuritysettingsandservices.
vShieldAppandPortGroupIsolationservicescannotbemovedtoanotherESXhost.IftheESXhostonwhich
theseservicesresiderequiresamanualmaintenancemodeoperation,youmustdeselecttheMovepowered
offandsuspendedvirtual
machinestootherhostsintheclustercheckboxtoensurethesevirtualappliances
arenotmigrated.TheseservicesrestartaftertheESXhostcomesonline.
VMware Tools
EachvShieldvirtualapplianceincludesVMwareTools.DonotupgradeoruninstalltheversionofVMware
ToolsincludedwithavShieldvirtualappliance.
Ports Required for vShield Communication
ThevShieldManagerrequiresthefollowingportstobeopen:
RESTAPI:80/TCPand443/TCP
GraphicalUserInterface:80/TCPto443/TCPandinitiatesconnectionstovSpherevCenterSDK.
SSHaccesstotheCLI(notenabledbydefault):22/TCP
N
OTEYoumustobtainanevaluationorfulllicensetousevShieldEndpoint.
vShield Administration Guide
16 VMware, Inc.
VMware, Inc. 17
2
ThevShieldManageruserinterfaceoffersconfigurationanddataviewingoptionsspecifictovShielduse.By
utilizingtheVMwareInfrastructureSDK,thevShieldManagerdisplaysyourvSphereClientinventorypanel
foracompleteviewofyourvCenterenvironment.
Thechapterincludesthefollowingtopics:
“LoggingintothevShieldManagerUserInterface”onpage 17
“A c c e s s i n g theOnlineHelp”onpage 18
“vShieldManagerUserInterface”onpage 18
Logging in to the vShield Manager User Interface
YouaccessthevShieldManagermanagementinterfacebyusingaWebbrowser.
To log in to the vShield Manager user interface
1OpenaWebbrowserwindowandtypetheIPaddressassignedtothevShieldManager.
ThevShieldManageruserinterfaceopensinanSSHsession.
2Acceptthesecuritycertificate.
ThevShieldManagerloginscreenappears.
3LogintothevShieldManager
userinterfacebyusingtheusernameadminandthepassworddefault.
Youshouldchangethedefaultpasswordasoneofyourfirsttaskstopreventunauthorizeduse.See“Edit
aUserAccount”onpage 34.
4ClickLogIn.
vShield Manager User Interface
Basics
2
NOTEYoucanregisterthevShieldManagerasavSphereClientplugin.ThisallowsyoutoconfigurevShield
componentsfromwithinthevSphereClient.Formore,see“RegisterthevShieldManagerasavSphereClient
Plugin”onpage 22.
NOTETouseanSSLcertificateforauthentication,see“A d d anSSLCertificatetoIdentifythevShield
ManagerWebService”onpage 24.
vShield Administration Guide
18 VMware, Inc.
Accessing the Online Help
TheOnlineHelpcanbeaccessedbyclickingintheupperrightofthevShieldManageruserinterface.
vShield Manager User Interface
ThevShieldManageruserinterfaceisdividedintotwopanels:theinventorypanelandtheconfiguration
panel.Youselectaviewandaresourcefromtheinventorypaneltoopentheavailabledetailsand
configurationoptionsintheconfigurationpanel.
Whenclicked,eachinventoryobjecthasaspecificsetoftabs
thatappearintheconfigurationpanel.
vShield Manager Inventory Panel
ThevShieldManagerinventorypanelhierarchymimicsthevSphereClientinventoryhierarchy.Resources
includetherootfolder,datacenters,clusters,portgroups,ESXhosts,andvirtualmachines,includingyour
installedvShieldAppandvShieldEdgemodules.Asaresult,thevShieldManagermaintainssolidaritywith
yourvCenterServerinventorytopresenta
completeviewofyourvirtualdeployment.ThevShieldManager
istheonlyvirtualmachinethatdoesnotappearinthevShieldManagerinventorypanel.vShieldManager
settingsareconfiguredfromtheSettings&Reportsresourceatoptheinventorypanel.
Theinventorypaneloffersmultipleviews:Hosts&Clusters,Networks,andSecured
PortGroups.TheHosts
&Clustersviewdisplaysthedatacenters,clusters,resourcepools,andESXhostsinyourinventory.The
NetworksviewdisplaystheVLANnetworksandportgroupsinyourinventory.TheSecuredPortGroups
viewdisplaystheportgroupsprotectedbyvShieldEdgeinstances.TheHosts&Clusters
andNetworksviews
areconsistentwiththesameviewsinthevSphereClient.
TherearedifferencesintheiconsforvirtualmachinesandvShieldcomponentsbetweenthevShieldManager
andthevSphereClientinventorypanels.CustomiconsareusedtoshowthedifferencebetweenvShield
componentsandvirtualmachines,andthe
differencebetweenprotectedandunprotectedvirtualmachines.
Refreshing the Inventory Panel
Torefreshthelistofresourcesintheinventorypanel,click .Therefreshactionrequeststhelatestresource
informationfromthevCenterServer.Bydefault,thevShieldManagerrequestsresourceinformationfromthe
vCenterServereveryfiveminutes.
Searching the Inventory Panel
Tosearchtheinventorypanelforaspecificresource,typeastringinthefieldatopthevShieldManager
inventorypanelandclick .
Table 2-1. vShield Virtual Machine Icons in the vShield Manager Inventory Panel
Icon Description
ApoweredonvShieldAppinactiveprotectionstate.
ApoweredoffvShieldApp.
ApoweredonvirtualmachinethatisprotectedbyavShieldApp.
ApoweredonvirtualmachinethatisnotprotectedbyavShieldApp.
VMware, Inc. 19
Chapter 2 vShield Manager User Interface Basics
vShield Manager Configuration Panel
ThevShieldManagerconfigurationpanelpresentsthesettingsthatcanbeconfiguredbasedonthesel ected
inventoryresourceandtheoutputofvShieldoperation.Eachresourceoffersmultipletabs,eachtabpresenting
informationorconfigurationformscorrespondingtotheresource.
Becauseeachresourcehasadifferentpurpose,sometabsarespecific
tocertainresources.Also,sometabshave
asecondlevelofoptions.
vShield Administration Guide
20 VMware, Inc.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54
  • Page 55 55
  • Page 56 56
  • Page 57 57
  • Page 58 58
  • Page 59 59
  • Page 60 60
  • Page 61 61
  • Page 62 62
  • Page 63 63
  • Page 64 64
  • Page 65 65
  • Page 66 66
  • Page 67 67
  • Page 68 68
  • Page 69 69
  • Page 70 70
  • Page 71 71
  • Page 72 72
  • Page 73 73
  • Page 74 74
  • Page 75 75
  • Page 76 76
  • Page 77 77
  • Page 78 78
  • Page 79 79
  • Page 80 80
  • Page 81 81
  • Page 82 82
  • Page 83 83
  • Page 84 84
  • Page 85 85
  • Page 86 86
  • Page 87 87
  • Page 88 88
  • Page 89 89
  • Page 90 90
  • Page 91 91
  • Page 92 92
  • Page 93 93
  • Page 94 94
  • Page 95 95
  • Page 96 96
  • Page 97 97
  • Page 98 98
  • Page 99 99
  • Page 100 100
  • Page 101 101
  • Page 102 102
  • Page 103 103
  • Page 104 104
  • Page 105 105
  • Page 106 106
  • Page 107 107
  • Page 108 108
  • Page 109 109
  • Page 110 110
  • Page 111 111
  • Page 112 112
  • Page 113 113
  • Page 114 114
  • Page 115 115
  • Page 116 116
  • Page 117 117
  • Page 118 118
  • Page 119 119
  • Page 120 120
  • Page 121 121
  • Page 122 122
  • Page 123 123
  • Page 124 124
  • Page 125 125
  • Page 126 126
  • Page 127 127
  • Page 128 128
  • Page 129 129
  • Page 130 130
  • Page 131 131
  • Page 132 132
  • Page 133 133
  • Page 134 134
  • Page 135 135
  • Page 136 136
  • Page 137 137
  • Page 138 138
  • Page 139 139
  • Page 140 140
  • Page 141 141
  • Page 142 142
  • Page 143 143
  • Page 144 144
  • Page 145 145
  • Page 146 146
  • Page 147 147
  • Page 148 148
  • Page 149 149
  • Page 150 150
  • Page 151 151
  • Page 152 152
  • Page 153 153
  • Page 154 154
  • Page 155 155
  • Page 156 156
  • Page 157 157
  • Page 158 158
  • Page 159 159
  • Page 160 160
  • Page 161 161
  • Page 162 162

VMware vShield 4.1 User guide

Category
System management software
Type
User guide
This manual is also suitable for

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI