1.0

Table Of Contents
CHAPTER 14 Understanding Policies
233
DHCP packets — Select this option if the virtual machine needs to get its IP
address from a DHCP server that is not included in the access list.
DNS packets — Select this option if the virtual machine needs to resolve IP
addresses using a DNS server that is not included in the access list.
ICMP packets — Select this option if you need support for the ping command
— for example, to check network connectivity to and from the virtual machine.
Storing Access Lists for Network Quarantine
If you use dynamic quarantine or version-based quarantine, you select the type of
server you want to use to store the list of approved networks and machines. You may
also use a server to store access lists if you are using custom quarantine based on a
script. VMware ACE checks the list on this server to determine what network access is
approved for the virtual machine. You have the following options:
Active Directory server — Select this option if you plan to store the network
quarantine list on your Active Directory server. The Network Quarantine Wizard
adds this information to your Active Directory server for you.
Web server — Select this option if you plan to store the network quarantine list
on a Web server. The wizard creates the file for you. Depending on the choices
you make on the Policy Lookup panel, the wizard copies the file to the Web
server for you or prompts you to copy it.
To update a network quarantine list, open the appropriate virtual machine and run
the Network Quarantine Wizard again. You may go directly to the Networks and
Machines panel for normal access or restricted access. Make the necessary changes
on one panel or both, then click Finish. If you store the network quarantine list on a
Web server, copy the new file to the server. You do not need to send any updates
directly to your end users.