User`s manual

Workstation User’s Manual
408 VMware, Inc.
Thepacketiscomparedtoeachruleinorderuntilitmatchesaruleoritwascompared
withalloftherules.Whenamatchismade,thepackettorulecomparisonends.
The packetisnotcomparedtosubsequentrulesintheorderedlist.Ifitwascompared
toallru
leswithoutamatch,thedef
aultruleactionisapplied.
To add and edit rulesets and rules for network access
1Inthepolicyeditor,selectNetworkAccess,andclickthelinkinthetablecolumn
thatappliestotheaccesssettingtoedit.
TheZoneandAccessTypeinformationjustbelowtheRulesetNametextbox
showsthenameofthezoneandwhethertheac
cesssettingappliestohostnetwork
accessortothenetworkaccessforACEinstances(guestaccess).
2Usetheruleseteditortochangetheorderofrulesintheset,editrules,andspecify
whetherthehostorguestisallowedtouseDNS,DHCP,orICMP.
Byde
faul
t,DNS,DHCP,andICMPareincludedinthenetworkaccesssetupfor
bothhostandinstanceaccess.VMwarerecommendsthatyoukeepDHCPand
DNSselectedbecausetheyareimportantforzonedetection.
WhetherthefollowingsettingsapplytothehostortotheACEinstance(guest
access)de
pendsonwhetheryouareeditingahostnetworkaccessrulesetora
guestnetworkaccessruleset:
DNSAllowstheguestorhosttouseaDNSservertoresolveIPaddresses.
SelectthisoptioniftheDNSserverisnotincludedinanyothernetworkaccess
settingforthishostorACEinstance.
DHCPAllowsthehostorguesttoobtainitsIPaddressfromaDHCPserver.
SelectthisoptioniftheDHCPserverisnotincludedinanyothernetwork
accesssettingforthehostorACEinstance.
ICMPEnablesyoutousethepingcommand.Forguests,pingenablesyou
tochecknetworkconnectivitytoandfromtheACEinstance.Forhosts,it
enablesyoutochecknetworkconnectivitywithotherhostsinthenetwork
andwiththeACEinstance.
3 (Optional)Toaddoreditarule,dooneofthefoll
owing:
Tochangeaspecificrule’ssettings,clicktherowforthatruleinthetableinthe
ruleseteditorandclickEdit.
Toaddarule,clickAdd.