5.1

Table Of Contents
vShield App Flow Monitoring 12
Flow Monitoring is a traffic analysis tool that provides a detailed view of the traffic on your virtual network
that passed through a vShield App. The Flow Monitoring output defines which machines are exchanging data
and over which application. This data includes the number of sessions, packets, and bytes transmitted per
session. Session details include sources, destinations, direction of sessions, applications, and ports being used.
Session details can be used to create firewall allow or block rules.
You can use Flow Monitoring as a forensic tool to detect rogue services and examine outbound sessions.
This chapter includes the following topics:
n
“Viewing the Flow Monitoring Data,” on page 155
n
“Add or Edit App Firewall Rule from the Flow Monitoring Report,” on page 158
n
“Change the Date Range of the Flow Monitoring Charts,” on page 159
Viewing the Flow Monitoring Data
You can view traffic sessions inspected by a vShield App within the specified time span. The last 24 hours of
data are displayed by default, the minimum time span is one hour and the maximum is two weeks.
Procedure
1 In the vSphere Client, select a datacenter, virtual machine, port group, network adapter, or virtual wire.
Option Action
Select a datacenter or virtual
machine
a Go to Inventory > Hosts and Clusters.
b Select a datacenter or virtual machine.
c Click the vShield tab.
Select a port group or network
adapter
a Go to Inventory > Networking.
b Select a port group or network adapter.
c Click the vShield tab.
Select a virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
NOTE The Flow Monitoring tab for a virtual wire is available only if vShield
App is installed on at least one of the hosts in the cluster from which the
virtual wire has been created. Flow monitoring data is displayed only for the
traffic passing through the host which has vShield App installed on it.
VMware, Inc.
155