5.1

Table Of Contents
Procedure
1 In the vSphere Client, select a datacenter, virtual wire, or port group with an independent namespace.
Firewall Rule Level Method
Datacenter
a Go to Inventory > Hosts and Clusters.
b Select a datacenter.
c Click the vShield tab.
Virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
d Click the Security tab.
Port group with an independent
namespace
a Go to Inventory > Networking.
b Select a Port group with an independent namespace.
c Click the vShield tab.
2 Click the SpoofGuard tab.
3 Click the Virtual NICs IP Required Approval or Virtual NICs with Duplicate IP link.
4
Point to the Approved IP cell and click .
5 Type the new IP address.
6 Click OK.
7 Click Publish Now.
Delete an IP Address
You can delete a MAC-to-IP address assignment from the SpoofGuard table to clean the table of a virtual
machine that is no longer active. Any deleted instance can reappear in the SpoofGuard table based on viewed
traffic and the current enabled state of SpoofGuard.
Procedure
1 In the vSphere Client, select a datacenter, virtual wire, or port group with an independent namespace.
Firewall Rule Level Method
Datacenter
a Go to Inventory > Hosts and Clusters.
b Select a datacenter.
c Click the vShield tab.
Virtual wire
a Go to Inventory > Hosts and Clusters and select the Network
Virtualization tab.
b Click the Networks tab.
c In the Name column, click the virtual wire for which you want to add a
rule.
d Click the Security tab.
Port group with an independent
namespace
a Go to Inventory > Networking.
b Select a Port group with an independent namespace.
c Click the vShield tab.
2 Click the SpoofGuard tab.
3 Click one of the option links.
4 Click Clear Approved IP.
Chapter 13 vShield App Firewall Management
VMware, Inc. 171