1.0

Table Of Contents
www.vmware.com
234
VMware ACE Administrator’s Manual
Using Advanced Network Quarantine
Advanced network quarantine features allow you to control the host computers
access to the network. This is useful if you want to give the virtual machine access to
the network but block or restrict host computer access.
You can apply different policies to the host computer based on the network to which
the host is attached.
Advanced network quarantine features also allow you to apply different policies to the
virtual machine based on the network to which the host is attached.
For example, a mobile worker using an unmanaged laptop computer may have
VMware ACE installed and use the virtual machine, which you manage, to connect to
a corporate VPN from remote locations. When the mobile worker comes to the
corporate office, you may regard the unmanaged laptop computer as a security risk,
because you do not know whether the host operating system is infected by viruses.
Using advanced network quarantine, you can block the host operating system from
the network but still allow the guest operating system running in VMware ACE to
connect to the corporate VPN — or even allow the guest to have full network access.
Note: You can use advanced network quarantine features only if you select
Quarantined access to specific networks and machines in the policy editor, then
select Static quarantine in the Network Quarantine Wizard. You cannot use these
features if you select None in the network quarantine pane of the policy editor, and
you cannot use them with dynamic, version-based or custom network quarantine.
To take advantage of advanced network quarantine, you must use a text editor to
make changes to one or more policy files.
Depending on the policies you want to establish, you must add some or all of the
following:
Zone descriptions — Define characteristics that clearly identify each network for
which you want to set advanced network quarantine policies. These settings go
in app.vmpl in the main folder for the project. For details, see Defining Zones
on page 235.
Host policies — For each zone you have defined, you may set policies to enable
or restrict the host computers network access when it is connected to that
network zone. These settings go in app.vmpl in the main folder for the project.
For details, see Defining Host Policies on page 237.
Guest policies — For each zone you have defined, you may set policies to
control the virtual machines network access when the host computer is