Manage vFirewalls

A vFirewall is a set of filtering rules. vFirewalls protect VMs from attacks to improve security and high availability of data center VMs.

A vFirewall uses a connection status-based detection mechanism. A firewall identifies all packets transmitted on a connection between two peers as a traffic flow. For new application connections, the firewall checks its rules, allows the connections permitted by the rules, and generates a status table that contains status information about the connections. Subsequent packets of the connections are permitted as long as they match the status table.

The system supports the following vFirewall types:

The system supports rules for TCP, UDP, and ICMP, as well as common application protocols such as DNS, HTTP, HTTPS, IMAP, IMAPS, LDAP, MS SQL, MYSQL, POP3, POP3S, RDP, SMTP, SMTPS, and SSH.

The system provides the following firewall rule types:

For application protocols, the default direction of rules is ingress.

Restrictions and guidelines

Add a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Add.

  1. Enter a name and a description for the vFirewall.

  1. Select a firewall type.

  1. Click Add, configure the rule, and then click OK.

  1. Click OK.

Edit a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Edit in the Actions columns for a vFirewall.

  1. Enter a description for the vFirewall.

  1. Manage the rules of the firewall:

  1. Click OK.

Delete a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Delete in the Actions columns for a vFirewall.

  1. In the dialog box that opens, click OK.

Parameters

vFirewall list

Rules

Rule parameters