Upgrading everyday security Commpact Manuel d'utilisateur Page 48

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 58
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 47
Upgrade to NSX Firewall
You can upgrade to NSX Firewall only from vShield App version 5.5. If you have a prior version of vShield
App in your infrastructure, you must upgrade to version 5.5 before upgrading to version 6.0. For
information on upgrading to version 5.5, see vShield Installation and Upgrade Guide version 5.5.
When vShield Manager 5.5 is upgraded to NSX Manager 6.0, vShield App 5.5 rules are migrated to NSX in
the following way:
1 A new section is created for each namespace (datacenter and virtual wire) configured in vShield App
version 5.5. Each section includes the corresponding firewall rules.
2 All rules in each section have the same value in the AppliedTo field - datacenter ID for datacenter
namespace, virtual wire ID for virtual wire namespace, and port group ID for port group based
namespace.
3 Containers created at different namespace levels are moved to the global level.
4 Section order is as below to ensure that firewall behavior after the upgrade remains the same:
Section_Namespace_Portgroup-1
..................
Section_Namespace_Portgroup-N
Section_Namespace_VirtualWire-1
..................
Section_Namespace_VirtualWire-N
Section_Namespace_Datacenter_1
..................
Section_Namespace_Datacenter_N
Default_Section_DefaultRule
Source ports have been moved from the rule level in 5.5 to services and applications in NSX 6.0. If your
vShield App firewall rules included a source port, the following changes are made during the rules
upgrade:
n
Generated applications are translated into raw service objects. Source port is included as part of service.
n
For user defined applications, new applications are created with source ports.
n
Application groups are expanded and for each application, a corresponding new application is created
with source port.
After the upgrade, you must modify the rules to use their application sets.
These rules are displayed in the Firewall table, but you cannot edit them. To use NSX Firewall, you must
follow the procedure below.
Prerequisites
1 vShield Manager has been upgraded to NSX Manager.
2 Virtual wires have been upgraded to NSX Logical Switches. For non-VXLAN users, network
virtualization components have been installed.
NSX Installation and Upgrade Guide
48 VMware, Inc.
Vue de la page 47
1 2 ... 43 44 45 46 47 48 49 50 51 52 53 ... 57 58

Commentaires sur ces manuels

Pas de commentaire