5.1

Table Of Contents
SpoofGuard Screen Options
The SpoofGuard interface contains the following options.
Table 13-1. SpoofGuard Screen Options
Option Description
Active Virtual NICs List of all validated IP addresses
Active Virtual NICs Since Last
Published
List of IP addresses that have been validated since the policy was last updated
Virtual NICs IP Required Approval IP address changes that require approval before traffic can flow to or from these
virtual machines
Virtual NICs with Duplicate IP IP addresses that are duplicates of an existing assigned IP address within the
selected datacenter
Inactive Virtual NICs List of IP addresses where the current IP address does not match the published IP
address
Unpublished Virtual NICs IP List of virtual machines for which you have edited the IP address assignment but
have not yet published
Enable SpoofGuard
Once enabled, you can use SpoofGuard to manage IP address assignments for your entire vCenter inventory.
IMPORTANT You must upgrade all vShield App instances to vShield App 1.0.0 Update 1 or later before you
enable SpoofGuard.
Procedure
1 In the vSphere Client, select a datacenter, virtual wire, or port group with an independent namespace.
SpoofGuard Scope Method
Datacenter
a Go to Inventory > Hosts and Clusters.
b Select a datacenter.
c Click the vShield tab.
Virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
d Click the Security tab.
Port group with an independent
namespace
a Go to Inventory > Networking.
b Select a Port group with an independent namespace.
c Click the vShield tab.
2 Click the SpoofGuard tab.
3 Click Edit at the right side of the SpoofGuard window.
4 For SpoofGuard, click Enable.
Chapter 13 vShield App Firewall Management
VMware, Inc. 169