14
VM-Series
Deployment
Guide
Monitor Changes in the Virtual Environment
About the VM-Series Firewall
The following example shows how dynamic address groups can simplify network security enforcement. The
example workflow shows how to:
Enable the VM Monitoring agent on the firewall, to monitor the VMware ESX(i) host or vCenter Server and
register VM IP addresses and the associated tags.
Create dynamic address groups and define the tags to filter. In this example, two address groups are created.
One that only filters for dynamic tags and another that filters for both static and dynamic tags to populate
the members of the group.
Validate that the members of the dynamic address group are populated on the firewall.
Use dynamic address groups in policy. This example uses two different security policies:
–
A security policy for all Linux servers that are deployed as FTP servers; this rule matches on
dynamically registered tags.
–
A security policy for all Linux servers that are deployed as web servers; this rule matches on a dynamic
address group that uses static and dynamic tags.
Validate that the members of the dynamic address groups are updated as new FTP or web servers are
deployed. This ensure that the security rules are enforced on these new virtual machines too.
PA-4000 Series, PA-3000 Series
5000
PA-2000 Series, PA-500, PA-200, VM-300, VM-200,
VM-100
1000
Use Dynamic Address Groups in Policy
Step 1
Enable VM Source Monitoring.
See
Enable VM Monitoring to Track Changes on the Virtual
Network
.
Platform
Maximum number of dynamically registered IP addresses