vShield App Unexpected Firewall Rule Application
We recently experienced some confusion when creating vShield App firewall rules, so I figured that it would make for a good post. For those who are unaware, vShield App (which is now a component of the vCloud Networking and Security solution) is a virtual firewall. Rather than being a traditional firewall though, which allows for rules based on either layer 2 or layer 3 constructs, this firewall integrates with vCenter and so can have rules based on vCenter constructs. At first glance, this is a little confusing, but once you become familiar with the concept it becomes very empowering. We have a motley collection of Port Groups in this VDI environment. Each Port Group needs different firewall rules to be applied to it. We have a “production” Port Group where the bulk of the customer’s employees sit, we have an “internet only” Port Group for external users and we have a whole bunch of Port Groups that are in between those two extremes for consultants, ...