5.1

Table Of Contents
7
Point to the Source cell of the new rule and click
.
a In View, select a container from which the communication originated.
Objects for the selected container are displayed.
b
Select one or more objects and click
.
You can create a new security group or IPSet. Once you create the new object, it is added to the source
column by default. For information on creating a new security group or IPSet, see “Grouping
Objects,” on page 24.
c To specify a source port, click Advance options and type the port number or range.
d Select Negate Source to exclude this source port from the rule.
Option Result
Negate Source selected Rule applied to traffic coming from all sources except for the source you specified
in Step 7c.
Negate Source not selected Rule applies to traffic coming from the source you specified in Step 7c.
e Click OK.
8
Point to the Destination cell of the new rule and click .
a In View, select a container which the communication is targeting.
Objects for the selected container are displayed.
b
Select one or more objects and click .
You can create a new security group or IPSet. Once you create the new object, it is added to the
destination column by default. For information on creating a new security group or IPSet, see
“Grouping Objects,” on page 24.
c To specify a destination port, click Advance options and type the port number or range.
d Select Negate Destination to exclude this destination port from the rule.
Option Rule Applied To
Negate Destination selected Traffic going to all destinations except for the destination you specified in
Step 8c.
Negate Destination not selected Traffic going to the destination you specified in Step 8c.
e Click OK.
9
Point to the Action cell of the new rule and click .
a Click Block to block traffic from or to the specified source and destination.
b Click Log to log all sessions matching this rule.
Enabling logging can affect performance.
c Type comments if required.
d Click OK.
10 Click Publish Changes to push the new rule to all vShield App instances.
What to do next
n
Disable a rule by clicking or enable a rule by clicking .
Chapter 13 vShield App Firewall Management
VMware, Inc. 165