1.0

Table Of Contents
CHAPTER 14 Understanding Policies
235
connected to that network zone. These settings go in <vmname>.vmpl in the
affected virtual machine’s folder inside the project folder. For details, see Defining
Guest Policies on page 240.
Defining Zones
Zone descriptions describe the characteristics of a network zone. VMware ACE
examines the network or networks directly connected to network adapters on the
host computer to see if there is a match for all the criteria in any of the zone
definitions. If there is a match, the policies for that zone are enforced.
The characteristics you can define in the zone descriptions include such things as IP
addresses for a subnet, IP addresses of certain key servers on the network, and DNS
names for machines or networks.
Choose the characteristics you specify carefully.
There are trade-offs between using shorter and longer lists of parameters.
If you use a longer list, you minimize the chances of a “false-positive” or a
misidentification. This can be important if you are providing a VMware ACE package
to someone who connects a host computer to multiple networks at different times. If
one of the other networks matches the characteristics you define in the zone
definition, the host policies are applied — even if the host is not connected to your
network.
In some cases, however, using a longer list may also increase the likelihood that an
end user could circumvent the detection mechanism — for example, switching the
host to use static IP instead of DHCP and configuring the host with only a subset of
the characteristics defined for your zone (for example, only IP address, or IP address
and DNS server information).
Another point to consider is that the addresses or names of certain servers may
change over time. Such changes may also introduce detection issues.
Using a smaller set of information — for example, using only the IP address and
netmask — in a zone description lessens the chance that the detection mechanism
will fail to restrict a host or guest that should be restricted, but it also increases the
chance that a false positive or misidentification can occur. Such false positives are
especially likely if your network is using a common netblock, such as 10/8, 172.16/12
or 192.168/16, that is also used by other networks.
Exit VMware ACE Manager if it is running, then use a text editor to add the zone
descriptions to app.vmpl in the main folder for the project.
Each zone description must start with the following: