
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com
Copyright © 2010 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed
at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be
trademarks of their respective companies. Item No: VMW_10Q3_DS_PROD_VSHIELD_APP_USLET_EN_R6
VMware vShield App
Flow Monitoring
•Abilitytoobservenetworkactivitybetweenvirtualmachines
to help define and refine firewall policies, identify botnets and
secure business processes through detailed reporting of
application trac (application, sessions, bytes)
Security Groups
•Administrator-dened,business-relevantgroupingsofany
virtual machines by their virtual NICs
Policy Management
•Managementoffull-featuresthroughvShieldManager;many
features also accessible through vCenter Server interface
•Policyenforcementonsecuritygroups,vCentergroupingsand
TCP 5 tuple (source IP, destination IP, source port, destination
port, protocol)
•Programmableinterfaceformanagementandpolicy
enforcement using REST APIs
•Supportforintegrationwithenterprisesecuritymanagementtools
Logging and Auditing
•Basedonindustry-standardsyslogformat
•AccessiblethroughRESTAPIsandvShieldManager
•Administratordenedloggingon/oforrewallsatrulelevel
Find Out More
For information or to purchase VMware products,
call 877-4-VMWARE (outside of North America dial
650-427-5000), visit www.vmware.com/products,
or search online for an authorized reseller. For detailed
product specifications and systems requirements, refer
to the VMware vShield App Administration Guide.
•Eciently manage dynamic policies – vShield App helps to
simplify policy definition and provides administrators a rich
context for defining and refining internal firewall policies as
business needs evolve over time.
•Reduce botnet risks – vShield App helps security administrators
protect against botnets and other attacks by dynamically allocating
ports to trusted applications.
•Control access to shared resources – vShield App allows
security administrators to restrict access to shared services
such as storage and backup on vSphere hosts based on
IP address.
•Accelerate IT compliance – vShield App increases visibility
and control over virtual machine network security, providing
the logging and auditing controls that enterprises need to
demonstrate compliance with internal policies and external
regulatory requirements.
Key Features
Hypervisor-Level Firewall
•Inbound/outboundconnectioncontrolenforcedatthevirtual
NIC level through hypervisor inspection, supporting multihomed
virtual machines
•Abilitytoenforcebasedonnetwork,applicationport,protocol
type (TCP, UDP), application type
•Dynamicprotectionasvirtualmachinesmigrate
•IP-basedstatefulrewallandapplicationlayergatewayfor
a broad range of protocols including Oracle, Sun Remote
ProcedureCall(RPC),MicrosoftRPC,LDAPandSMTP;
complete list of supported protocols in VMware vShield
App Administration Guide