2.0

Table Of Contents
VMware, Inc. 133
Chapter 6 Setting and Using Policies and Customizing VMware Player
thehostcomputertoseeifthereisamatchforallthecriteriaforanyadapterinanyof
thezonedefinitions.
Thezonesarecheckedintheordertheyappearinthenetworkaccesstable,fromthe
topdown.Whenthehostconnectstoanetwork,checkingbeginsto
seewhetherthe
networkmatchestheconditionsforazone.Thecheckingstartswiththetopmostzone
inthetableandcontinuesdownthetableuntilamatchismadeortheEverywhereElse
zoneisreached.Whenamatchismade,thezonecheckingstopsandfilter rulesfor
that
zoneareapplied.
Detailsaboutzonematchingare:
Azonecanbespecifiedbyusinguptosixconditions:
Domain
Subnet
DNSservers
DHCPservers
Gatewayservers
WINSservers
Foramatchtooccur,allspecifiedconditionsmustbemet.
Allzoneconditionsexceptthedomainconditionallowuserstospecifyalistof
addresses.Thematchismadeifthehost’saddressmatchesanyoftheaddresslist
entriesinaspecifiedcondition.
Guidelines for Choosing Zone Conditions
Choosethecharacteristicsyouspecifycarefully.
Therearetradeoffsbetweenusingshorterandlongerlistsofconditions.
Ifyouusealongerlist,youminimizethechancesofafalsepositiveora
misidentification.Minimizingthechanceofafalsepositiveoramisidentificationcan
beimportantifyouare
providinganACEpackagetosomeonewhoconnectsahost
computertomultiplenetworksatdifferenttimes.Ifoneoftheothernetworksmatches
thecharacteristicsyoudefineinthezonedefinition,thehostandinstanceaccess
policiesareapplied—evenifthehostisnotconnectedtoyournetwork.
Insome
cases,however,usingalongerlistmightalsoincreasethelikelihoodthatan
usercouldcircumventthedetectionmechanism—forexample,switchingthehostto
usestaticIPinsteadofDHCPandconfiguringthehostwithonlyasubsetofthe
characteristicsdefinedforyourzone(forexample,onlyNetworkaddress,
orNetwork
addressandDNSserverinformation).