5.1

Table Of Contents
Procedure
1 Do one of the following.
Firewall Rule Level Method
Datacenter
a In the vSphere client, Go to Inventory > Hosts and Clusters.
b Select a datacenter.
c Click the vShield tab.
d Click the App Firewall tab.
Virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
d Click the Security tab.
e Ensure that you are in the Firewall tab.
Port group with an independent
namespace
a In the vSphere client, Go to Inventory > Networking.
b Select a Port group with an independent namespace.
c Click the vShield tab.
d Click the App Firewall tab.
2 Select the rule that you want to move.
3
Click the Move rule up ( ) or Move rule down ( ) icon.
4 Click Publish Changes.
Using SpoofGuard
After synchronizing with the vCenter Server, the vShield Manager collects the IP addresses of all vCenter guest
virtual machines from VMware Tools on each virtual machine. Up to vShield 4.1, vShield trusted the IP address
provided by VMware Tools on a virtual machine. However, if a virtual machine has been compromised, the
IP address can be spoofed and malicious transmissions can bypass firewall policies.
SpoofGuard allows you to authorize the IP addresses reported by VMware Tools, and alter them if necessary
to prevent spoofing. SpoofGuard inherently trusts the MAC addresses of virtual machines collected from the
VMX files and vSphere SDK. Operating separately from the App Firewall rules, you can use SpoofGuard to
block traffic determined to be spoofed.
When enabled, you can use SpoofGuard to monitor and manage the IP addresses reported by your virtual
machines in one of the following modes.
Automatically Trust IP
Assignments On Their
First Use
This mode allows all traffic from your virtual machines to pass while building
a table of vnic-to-IP address assignments. You can review this table at your
convenience and make IP address changes.
Manually Inspect and
Approve All IP
Assignments Before Use
This mode blocks all traffic until you approve each MAC-to-IP address
assignment.
NOTE SpoofGuard inherently allows DHCP requests regardless of enabled mode. However, if in manual
inspection mode, traffic does not pass until the DHCP-assigned IP address has been approved.
vShield Administration Guide
168 VMware, Inc.