VMware, Inc.
53
Chapter 10 vShield Edge Management
5
Under Static Bindings, click
Add Bindings
.
A new row appears in the table.
6
Double-click each cell in the row to enter or select the appropriate information.
The Primary Name Server and Secondary Name Server fields refer to DNS service. You must enter the IP
address of a DNS server for hostname-to-IP address resolution.
7
Click
Commit
to save the rule.
8
If DHCP service has not been enabled, enable DHCP service.
See
“Start or Stop vShield Edge Services”
on page 56.
Manage VPN Service
vShield Edge modules support site-to-site IPSec VPN between a vShield Edge and remote sites.
Figure 10-1.
vShield Edge Providing VPN Access from a Remote Site to a Secured Port Group
At this time, vShield Edge supports pre-shared key mode, IP unicast traffic, and no dynamic routing protocol
between the vShield Edge and remote VPN routers. Behind each remote VPN router, you can configure
multiple subnets to connect to the internal network behind a vShield Edge through IPSec tunnels. These
subnets and the internal network behind a vShield Edge must have non-overlapping address ranges.
You can deploy a vShield Edge agent behind a NAT device. In this deployment, the NAT device translates the
VPN address of a vShield Edge into a publicly accessible address facing the Internet. Remote VPN routers use
this public address to access the vShield Edge.
Remote VPN routers can be located behind a NAT device as well. You must provide both the VPN native
address and the NAT public address to set up the tunnel.
On both ends, static one-to-one NAT is required for the VPN address.
Summary of Contents for VSHIELD APP 1.0.0 UPDATE 1 - API
Page 9: ...VMware Inc 9 vShield Manager and vShield Zones...
Page 10: ...vShield Administration Guide 10 VMware Inc...
Page 14: ...vShield Administration Guide 14 VMware Inc...
Page 18: ...vShield Administration Guide 18 VMware Inc...
Page 24: ...vShield Administration Guide 24 VMware Inc...
Page 34: ...vShield Administration Guide 34 VMware Inc...
Page 42: ...vShield Administration Guide 42 VMware Inc...
Page 46: ...vShield Administration Guide 46 VMware Inc...
Page 47: ...VMware Inc 47 vShield Edge and Port Group Isolation...
Page 48: ...vShield Administration Guide 48 VMware Inc...
Page 57: ...VMware Inc 57 vShield App and vShield Endpoint...
Page 58: ...vShield Administration Guide 58 VMware Inc...
Page 62: ...vShield Administration Guide 62 VMware Inc...
Page 68: ...vShield Administration Guide 68 VMware Inc...
Page 78: ...vShield Administration Guide 78 VMware Inc...
Page 85: ...VMware Inc 85 Appendixes...
Page 86: ...vShield Administration Guide 86 VMware Inc...