1.0

Table Of Contents
www.vmware.com
232
VMware ACE Administrator’s Manual
compliance detection software. For more information, see Writing Plug-In
Policy Scripts on page 244.
Note: VMware Tools provides services that are essential for custom
quarantine. This means you cannot use custom quarantine with guest
operating systems such as MS-DOS and Windows 3.1
Specifying Access to Networks and Machines
You may allow a virtual machine unrestricted network access, or you may limit access
to specified machines or parts of the network. Depending on your network
configuration and the type of access you need to specify, you may use a whitelist or a
blacklist. You must use one or the other consistently for any one virtual machine. You
cannot mix whitelists and blacklists for one virtual machine.
You can specify access in the following ways:
Allow or deny access to an individual machine using its IP address.
Allow or deny access to an individual machine using its machine name; the
Network Quarantine Wizard looks up the machine’s IP address in DNS and inserts
the address for you.
Allow or deny access to a subnet; you enter the starting address, select Subnet
mask and enter the subnet mask in the field.
You may enter as many items as you like in the list. You may use any mix of machine IP
addresses, machine names and subnets.
In the Networks and Machines panel, you do not need to include network addresses
needed for printers or for DHCP and DNS servers. You can allow network traffic for
those purposes in separate panels.
Allowing Access for Printer, DHCP, DNS and ICMP Traffic
The Network Traffic panel allows you to create special-purpose exceptions to the
restrictions configured on the Networks and Machines panel. You may specify that
certain types of network traffic may go to and from machines and subnets outside the
access list you created on the Networks and Machines panel. This is useful, for
example, if virtual machine users are restricted to a particular subnet but the DNS
server on your network is not on that subnet.
Printer access — Select this option to be sure a Windows virtual machine can
use local and network printers available on the host. Be sure to select this option
if you configure the virtual machine to allow easy printer setup. Easy printer
setup uses network sharing to connect the virtual machine to a printer
configured on the host computer.