5.1

Table Of Contents
5 For Operation Mode, select one of the following:
Option Description
Automatically Trust IP Assignments
on Their First Use
Select this option to trust all IP assignments upon initial registration with the
vShield Manager.
Manually Inspect and Approve All IP
Assignments Before Use
Select this option to require manual approval of all IP addresses. All traffic
to and from unapproved IP addresses is blocked.
6 Click Allow local address as valid address in this namespace to allow local IP addresses in your setup.
When you power on a virtual machine but it is unable to connect to the DHCP server, a local IP address
is assigned to it. This local IP address is considered valid only if the SpoofGuard mode is set to Allow
local address as valid address in this namespace. Otherwise, the local IP address is ignored.
7 Click OK.
Approve IP Addresses
If you set SpoofGuard to require manual approval of all IP address assignments, you must approve IP address
assignments to allow traffic from those virtual machines to pass.
Procedure
1 In the vSphere Client, select a datacenter, virtual wire, or port group with an independent namespace.
Firewall Rule Level Method
Datacenter
a Go to Inventory > Hosts and Clusters.
b Select a datacenter.
c Click the vShield tab.
Virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
d Click the Security tab.
Port group with an independent
namespace
a Go to Inventory > Networking.
b Select a Port group with an independent namespace.
c Click the vShield tab.
2 Click the SpoofGuard tab.
3 Click one of the option links.
4 Select the virtual NIC for which you want to approve the IP address.
5 Click Approve Detected IP.
6 Click Publish Now.
Edit an IP Address
You can edit the IP address assigned to a MAC address to correct the assigned IP address.
NOTE SpoofGuard accepts a unique IP address from virtual machines. However, you can assign an IP address
only once. An approved IP address is unique across the vShield system. Duplicate approved IP addresses are
not allowed.
vShield Administration Guide
170 VMware, Inc.