5.1

Table Of Contents
Prevent Spoofing on a VXLAN Virtual Wire
After synchronizing with the vCenter Server, vShield Manager collects the IP addresses of all vCenter guest
virtual machines from VMware Tools on each virtual machine. vShield does not trust all IP address provided
by VMware Tools on a virtual machine. If a virtual machine has been compromised, the IP address can be
spoofed and malicious transmissions can bypass firewall policies.
SpoofGuard allows you to authorize the IP addresses reported by VMware Tools, and alter them if necessary
to prevent spoofing. SpoofGuard inherently trusts the MAC addresses of virtual machines collected from the
VMX files and vSphere SDK. Operating separately from the App Firewall rules, you can use SpoofGuard to
block traffic determined to be spoofed.
For more information, see “Using SpoofGuard,” on page 168.
Editing Network Scopes
You can edit, expand, or contract a network scope.
View and Edit a Network Scope
You can view the VXLAN virtual wires in a selected network scope, the clusters in, and the services available
for that network scope.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Network Scope tab.
All network scopes for the selected datacenter are displayed.
5 In the Name column, click on a network scope.
The Summary tab displays the following information. Click Edit in the appropriate section to make
changes.
n
The Properties section displays the name and description of the network scope and the number of
VXLAN virtual wires based on this network scope.
n
The Network Scope section displays the clusters in the network scope and whether they are ready
for virtualized networking (i.e. whether the clusters have been mapped to a vDS).
n
The Available Services section displays the services available for the network scope.
Expand a Network Scope
You can add clusters to a network scope. This will stretch all existing VXLAN virtual wires to become available
on the newly added clusters.
Prerequisites
The clusters you add to a network scope must be prepared. See “Preparing your Network for VXLAN Virtual
Wires,” on page 48.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
vShield Administration Guide
54 VMware, Inc.