VMware Cloud Community
JijunLiu
Contributor
Contributor

vShield App: Deny All Ingress only Allow DHCP, DNS take no effect

hello everyone,

we create a VApp in vCenter, and we want to deny all the Ingress to the VAPP and allow all the Egress from the VApp.

so we add some rule in vShield App Firewall, all the rules were created L2 Rule.

ANY -> VAPP1 -> any  deny

VAPP1 ->ANY -> any    allow

but our DHCP server and DNS server were blocked too, so the VM in the VApp cannot get the ip address automatic.

so we create rule to allow DHCP service and DNS in the top.

ANY -> VAPP1 -> dhcp,dns   allow

but  now take no effect

can someone give me some help?

thanks very much.

0 Kudos
3 Replies
abhilashhb
VMware Employee
VMware Employee

Go through the below VMware blog posts that clearly explain with examples, how to configure firewall rules for vShield App.

vCloud Networking and Security 5.1 App Firewall – Part 1

vCloud Networking and Security 5.1 App Firewall – Part 2

Abhilash B
LinkedIn : https://www.linkedin.com/in/abhilashhb/

0 Kudos
abhilashhb
VMware Employee
VMware Employee

Hope the links helped you.

Abhilash B
LinkedIn : https://www.linkedin.com/in/abhilashhb/

0 Kudos
JijunLiu
Contributor
Contributor

thanks for your reply , but it not resolve my problem

0 Kudos