5.1

Table Of Contents
vShield App Management 11
vShield App is a hypervisor-based firewall that protects applications in the virtual datacenter from network-
based attacks. Organizations gain visibility and control over network communications between virtual
machines. You can create access control policies based on logical constructs such as VMware vCenter™
containers and vShield security groups—not just physical constructs such as IP addresses. In addition, flexible
IP addressing offers the ability to use the same IP address in multiple tenant zones to simplify provisioning.
You should install vShield App on each ESX host within a cluster so that VMware vMotion operations work
and virtual machines remain protected as they migrate between ESX hosts. By default, a vShield App virtual
appliance cannot be moved by using vMotion.
This chapter includes the following topics:
n
“Sending vShield App System Events to a Syslog Server,” on page 151
n
“Viewing the Current System Status of a vShield App,” on page 152
n
“Restart a vShield App,” on page 152
n
“Forcing a vShield App to Synchronize with the vShield Manager,” on page 152
n
“Viewing Traffic Statistics by vShield App Interface,” on page 153
n
“Download Technical Support Logs for vShield App,” on page 153
n
“Configuring Fail Safe Mode for vShield App Firewall,” on page 153
n
“Excluding Virtual Machines from vShield App Protection,” on page 153
Sending vShield App System Events to a Syslog Server
You can send vShield App system messages related to firewall events that flow from vShield App appliances
to a syslog server.
Procedure
1 In the vSphere Client, go to Inventory > Hosts and Clusters.
2 Select a host from the resource tree.
3 Click the vShield tab.
4 In the Service Virtual Machines area, expand the vShield App SVM.
5 In the Syslog Servers area, type the IP address of the syslog server.
VMware, Inc.
151