Dave Convery, VMware vExpert and Virtualization Architect at Anexinet, published a short but very interesting report on current limitations of vShield Zones, the firewall that VMware acquired from Blue Lane Technologies in October 2008 and that offers for free as part of vSphere 4.0 Advanced, Enterprise and Enterprise Plus editions.
He specifically mentions three shortcomings related to:
- Networking
…there is an unprotected Port Group (ORIGINAL Network). This needs to be added to the vSwitch AFTER the vShield Agent is installed. If the ORIGINAL Network is already a part of the vSwitch, it will need to be removed BEFORE installing the vShield Agent. In order to avoid an outage, you will need to disable DRS and manually vMotion all VMs off of the ESX/ESXi host before installing the vShield Agent and modifying the port groups.






