Upgrading everyday security Commpact Bedienungsanleitung Seite 48

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 58
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 47
Upgrade to NSX Firewall
You can upgrade to NSX Firewall only from vShield App version 5.5. If you have a prior version of vShield
App in your infrastructure, you must upgrade to version 5.5 before upgrading to version 6.0. For
information on upgrading to version 5.5, see vShield Installation and Upgrade Guide version 5.5.
When vShield Manager 5.5 is upgraded to NSX Manager 6.0, vShield App 5.5 rules are migrated to NSX in
the following way:
1 A new section is created for each namespace (datacenter and virtual wire) configured in vShield App
version 5.5. Each section includes the corresponding firewall rules.
2 All rules in each section have the same value in the AppliedTo field - datacenter ID for datacenter
namespace, virtual wire ID for virtual wire namespace, and port group ID for port group based
namespace.
3 Containers created at different namespace levels are moved to the global level.
4 Section order is as below to ensure that firewall behavior after the upgrade remains the same:
Section_Namespace_Portgroup-1
..................
Section_Namespace_Portgroup-N
Section_Namespace_VirtualWire-1
..................
Section_Namespace_VirtualWire-N
Section_Namespace_Datacenter_1
..................
Section_Namespace_Datacenter_N
Default_Section_DefaultRule
Source ports have been moved from the rule level in 5.5 to services and applications in NSX 6.0. If your
vShield App firewall rules included a source port, the following changes are made during the rules
upgrade:
n
Generated applications are translated into raw service objects. Source port is included as part of service.
n
For user defined applications, new applications are created with source ports.
n
Application groups are expanded and for each application, a corresponding new application is created
with source port.
After the upgrade, you must modify the rules to use their application sets.
These rules are displayed in the Firewall table, but you cannot edit them. To use NSX Firewall, you must
follow the procedure below.
Prerequisites
1 vShield Manager has been upgraded to NSX Manager.
2 Virtual wires have been upgraded to NSX Logical Switches. For non-VXLAN users, network
virtualization components have been installed.
NSX Installation and Upgrade Guide
48 VMware, Inc.
Seitenansicht 47
1 2 ... 43 44 45 46 47 48 49 50 51 52 53 ... 57 58

Kommentare zu diesen Handbüchern

Keine Kommentare