1.0

Table Of Contents
CHAPTER 14 Understanding Policies
241
quarantine.showUpdatesAvailMsg
quarantine.descriptor.Type
quarantine.descriptor.custom.script
Notice that quarantine.configurationBlock is followed by a very
long string of parameters and settings. These are key quarantine settings; be
careful not to modify those parameters and settings.
6. At the beginning of each line, add guest.zone.<zone_number>. Thus
for zone 0, you change quarantine.configurationBlock to
guest.zone.0.quarantine.configurationBlock and so on.
7. Save and close <vmname>.vmpl.
8. Start VMware ACE Manager, then launch the Network Quarantine Wizard from
the policy editor and set the network quarantine policies you want to apply to
the virtual machine when it is connected to zone 1.
If you do not want to define policies for any additional zones, skip to step 12.
9. Repeat the steps you took for zone 0, except that the lines referring to the
specific zone must use the number 1 in place of the number 0.
This means the three lines you add to specify the zone are the following:
guest.zone.1.present = "1"
guest.zone.1.key = "1"
guest.zone.1.descriptionName = "<zone_name>"
Similarly, in the block of lines you copy, you change
quarantine.configurationBlock to
guest.zone.1.quarantine.configurationBlock, and so on.
10. Save and close <vmname>.vmpl.
11. Take the same steps for any other zones you want to define for this virtual
machine. You may set policies for any or all of the zones defined in app.vmpl,
but you may skip any zones for which you want to apply the default network
quarantine policies.
12. Launch the Network Quarantine Wizard from the policy editor and set the
default network quarantine policies for the virtual machine. The default policies
are applied when the host is not in any of the zones you have configured.
Switching Network Connection Type Based on Zones
You may find it useful to configure the virtual machine’s Ethernet adapter to use
bridged networking in some zones and NAT in other zones. For zones in which you
are using host quarantine to restrict the hosts network access, it is generally simpler to