5.1

Table Of Contents
9 Copy and paste the list.
10 (Optional) Type a description.
11 Click OK.
Managing the vShield Edge Firewall
vShield Edge provides firewall protection for incoming and outgoing sessions. The default firewall policy
blocks all incoming traffic and allows all outgoing traffic.
In addition to the default firewall policy, you can configure a set of rules to allow or block traffic sessions to
and from specific sources and destinations. You can manage the default firewall policy and firewall rule set
separately for each vShield Edge instance.
Add a vShield Edge Firewall Rule
You can add a vShield Edge firewall rule for traffic flowing from or to a vShield Edge interface or IP address
group.
You can add multiple vShield Edge interfaces and/or IP address groups as the source and destination for
firewall rules.
Figure 9-1. Firewall rule for traffic to flow from a vShield Edge interface to an HTTP server
Figure 9-2. Firewall rule for traffic to flow from all internal interfaces (subnets on portgroups connected to
internal interfaces) of a vShield Edge to an HTTP Server
NOTE If you select internal as the source, the rule is automatically updated when you configure additional
internal interfaces.
Figure 9-3. Firewall rule for traffic to allow SSH into a m/c in internal network
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
vShield Administration Guide
70 VMware, Inc.