Vcenter Security Hardening - Firewall - Only specific IP addresses are allowed to access Vcenter

1. Scene

        1. Only specific IP addresses are allowed to access Vcenter.

        2. Reject all others.

2. Operation steps

        1. Log in to the Vcenter management interface       

                https://<Vcenter-ip>:5480

        2. Click Firewall-Add

        3. Add rules

                1. First add the IP address and mask that are allowed to access .

                        1. Put your Esxi host management address first, otherwise it will be hosted.

                        2. Then there is your management PC.

                        3. If it involves other VSphere ecology, such as NSX-T, it also needs to be released.

                For example:

                2. Perform 0.0.0.0/0 to match all other IP addresses to deny access.

                

                3. At this time, except the allowed IP address can be accessed, the rest of the addresses are blocked by the firewall. 

2. Firewall rules

                 1. Just focus on accepting and rejecting.

                2. Other options are not used in this scene.

Guess you like

Origin blog.csdn.net/weixin_46510209/article/details/131992908