2.0

Table Of Contents
VMware ACE Administrator’s Manual
126 VMware, Inc.
wanttosettheresourcesigningoptiontoverifyscriptsonlyornoverificationbecause
signaturecheckingcouldtakealongtime.
Setting Network Access Policies
Networkaccesspoliciesgiveyoufinegrainedandflexiblecontroloverthenetwork
accessyouprovidetousersofyourACEinstances.
Usingapacketfilteringfirewall,thenetworkaccessfeatureofACE2letsyouspecify
exactlywhichmachinesorsubnetsanACEinstanceoritshostsystemmayaccess.
This
meansthatyoucan,forexample,configuretheinstancesoitisallowedtoconnectonly
toyourVPNserver,whichthencontrolsaccesstootherresources.
Youcanalsocustomizethenetworkaccesssettingstofilteronthebasisofnetwork
addresses,trafficdirection,protocol,andports.
WorkstationACEEdition
providesmethodsforyoutoperformthefollowingtasks
fromwithintheuserinterface:
Definenetworkzones
DefinenetworkaccessforyourACEinstances’hostmachines(alsoknownas“host
networkaccess”)
DefinenetworkaccessforyourACEinstances’guestsystems(alsoknownas
“guestnetworkaccess”)
NetworkaccesspoliciescanbedynamiciftheACEinstanceisassociatedwithanACE2
ManagementServer.Thismeans,forexample,thatyoucanquicklylockACEinstances
outofallorpartofyournetworktohelpcombatthespreadofawormorviruswithout
deployingupdatedpackages.
Topicsinthissectioninclude:
“BeforeYouBegin:ReadTheseNotesAboutHostPoliciesonpage127
“GettingStartedwithSettingNetworkAccess”onpage128
“UsingtheNetworkAccessWizardtoConfigureNetworkAccess”onpage129
“UsingtheZone,Ruleset,andRuleEditorstoConfigureNetworkAccess”on
page132
“NetworkPropertiesPackagingonpage141
“UnderstandingtheInteractionofHostAccessandGuestAccessFiltersWith
TunnelingProtocols”onpage142