5.1

Table Of Contents
10
Point to the Source cell of the new rule and click
.
a Select VnicGroup or IPAddresses.
VnicGroup displays vShield Edge (vse), internal (represents all internal interfaces), external
(represents all uplink interfaces), and all internal and external interfaces for the vShield Edge.
IPAddresses displays all IP address groups.
b Select one or more interface or IP address group.
If you select vse, the rule applies to traffic generated by the vShield Edge. If you select internal or
external, the rule applies to traffic coming from any internal or uplink interface of the selected vShield
Edge instance. The rule is automatically updated when you configure additional interfaces.
If you select IPAddresses, you can create a new IP address group. Once you create the new group, it
is automatically added to the source column. For information on creating an IPAddress, see “Create
an IP Address Group,” on page 24.
You can specify the source port by clicking
next to Advance options. VMware recommends that
you avoid specifying the source port from release 5.1 onwards. Instead, you can create a service for
a protocol-port combination. See “Create a Service,” on page 21.
c Click OK.
11
Point to the Destination cell of the new rule and click .
a Select VnicGroup or IPAddresses.
VnicGroup displays vShield Edge (vse), internal (represents all internal interfaces), external
(represents all uplink interfaces), and all internal and uplink interfaces for the vShield Edge.
IPAddresses displays all IP address groups.
b Select one or more interface or IP address group.
If you select vse, the rule applies to traffic generated by the vShield Edge. If you select internal or
external, the rule applies to traffic going to any internal or uplink interface of the selected vShield
Edge instance. If you add an interface to the vShield Edge instance, the rule automatically applies to
the new interface.
If you select IPAddresses, you can create a new IP address group. Once you create the new group, it
is automatically added to the destination column. For information on creating an IPAddress, see
“Create an IP Address Group,” on page 24.
c Click OK.
12
Point to the Service cell of the new rule and click
.
Select a service. To create a new service, click New. Once you create the new service, it is automatically
added to the Service column. For more information on creating a new service, see “Create a Service,” on
page 21.
NOTE vShield Edge only supports services defined with L3 protocols.
13
Point to the Action cell of the new rule and click
.
a Click Deny to block traffic from or to the specified source and destination.
b Click Log to log all sessions matching this rule.
Enabling logging can affect performance.
c Type comments if required.
d
Click next to Advance options.
vShield Administration Guide
72 VMware, Inc.