5.1

Table Of Contents
vShield App Firewall Management 13
vShield App provides firewall protection through access policy enforcement. The App Firewall tab represents
the vShield App firewall access control list.
This chapter includes the following topics:
n
“Using App Firewall,” on page 161
n
“Working with Firewall Rules,” on page 163
n
“Using SpoofGuard,” on page 168
Using App Firewall
The App Firewall service is a centralized firewall for ESX hosts. App Firewall enables you to create rules that
allow or block access to and from your virtual machines. Each installed vShield App enforces the App Firewall
rules.
You can manage App Firewall rules on a namespace level to provide a consistent set of rules across multiple
vShield App instances under these containers. Namespace levels include datacenter, virtual wire, and port
group with an independent namespace. As membership in these containers can change dynamically, App
Firewall maintains the state of existing sessions without requiring reconfiguration of firewall rules. In this way,
App Firewall effectively has a continuous footprint on each ESX host under the managed containers.
Namespaces in a Multi Tenant Environment
The namespace feature allows vShield App to work in a multi tenant mode. Each tenant can have its own
firewall rules and security groups.
By default, all port groups in a datacenter share the same IP space. You can assign an independent namespace
to a port group, and then the datacenter level firewall rules no longer apply to that port group.
To assign an independent IP address to a port group
1 In the vSphere Client, go to Inventory > Networking.
2 Select a port group from the resource tree.
3 Click the vShield tab.
4 Click Namespace.
5 Click Change to Independent namespace.
6 Click Reload to view the updated information.
VMware, Inc.
161