5.1

Table Of Contents
You should install vShield App instances on all ESX hosts within a cluster so that VMware vMotion™
operations work and virtual machines remain protected as they migrate between ESX hosts. By default, a
vShield App virtual appliance cannot be moved by using vMotion.
The Flow Monitoring feature displays allowed and blocked network flows at the application protocol level.
You can use this information to audit network traffic and troubleshoot operational issues.
NOTE You must obtain an evaluation or full license to use vShield App.
vShield Endpoint
vShield Endpoint offloads antivirus and anti-malware agent processing to a dedicated secure virtual appliance
delivered by VMware partners. Since the secure virtual appliance (unlike a guest virtual machine) doesn't go
offline, it can continuously update antivirus signatures thereby giving uninterrupted protection to the virtual
machines on the host. Also, new virtual machines (or existing virtual machines that went offline) are
immediately protected with the most current antivirus signatures when they come online.
vShield Endpoint installs as a hypervisor module and security virtual appliance from a third-party antivirus
vendor (VMware partners) on an ESX host.
NOTE You must obtain an evaluation or full license to use vShield Endpoint.
vShield Data Security
vShield Data Security provides visibility into sensitive data stored within your organization's virtualized and
cloud environments. Based on the violations reported by vShield Data Security, you can ensure that sensitive
data is adequately protected and assess compliance with regulations around the world.
Migration of vShield Components
The vShield Manager and vShield Edge virtual appliances can be automatically or manually migrated based
on DRS and HA policies. The vShield Manager must always be up, so you must migrate the vShield Manager
whenever the current ESX host undergoes a reboot or maintenance mode routine.
Each vShield Edge should move with its datacenter to maintain security settings and services.
vShield App, vShield Endpoint partner appliance, or vShield Data Security cannot be moved to another ESX
host. If the ESX host on which these components reside requires a manual maintenance mode operation, you
must de-select the Move powered off and suspended virtual machines to other hosts in the cluster check
box to ensure these virtual appliances are not migrated. These services restart after the ESX host comes online.
About VMware Tools on vShield Components
Each vShield virtual appliance includes VMware Tools. Do not upgrade or uninstall the version of VMware
Tools included with a vShield virtual appliance.
Ports Required for vShield Communication
vShield requires the following ports to be open:
n
vShield Manager port 443 from the ESX host, the vCenter Server, and the vShield appliances to be deployed
n
UDP123 between vShield Manager and vShield App for time synchronization
n
902/TCP and 903/TCP to and from the vCenter Client and ESX hosts
n
443/TCP from the REST client to vShield Manager for using REST API calls
Chapter 1 Overview of vShield
VMware, Inc. 11