Manage vFirewalls

A vFirewall is a set of filtering rules. vFirewalls protect VMs from attacks to improve security and high availability of data center VMs.

A vFirewall uses a connection status-based detection mechanism. A firewall identifies all packets transmitted on a connection between two peers as a traffic flow. For new application connections, the firewall checks its rules, allows the connections permitted by the rules, and generates a status table that contains status information about the connections. Subsequent packets of the connections are permitted as long as they match the status table.

The system supports the following vFirewall types:

The system supports rules for TCP, UDP, and ICMP, as well as common application protocols such as DNS, HTTP, HTTPS, IMAP, IMAPS, LDAP, MS SQL, MYSQL, POP3, POP3S, RDP, SMTP, SMTPS, and SSH.

The system provides the following firewall rule types:

For application protocols, the default direction of rules is ingress.

Restrictions and guidelines

Add a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Add.

  1. Enter a name and a description for the vFirewall.

  1. Select a firewall type.

  1. Click Add Rule.

  1. To add a rule and return to the Add Virtual Firewall dialog box, configure the rule, and then click OK. To add rules in bulk, configure each rule, click Append, and then click OK after you add all desired rules.

  1. Click OK.

Import a vFirewall

You can import a vFirewall from a vFirewall configuration file that has been exported from the system if you mistakenly delete the original vFirewall on the system or want to fast create a vFirewall. You can import a vFirewall to the cloud management platform that exports the vFirewall configuration file or another cloud management platform. After you import a vFirewall, you can edit or delete its rules. The name of the vFirewall must be unique in the local cloud management platform.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Import, and select a JSON file that contains vFirewall settings. To obtain such a JSON file, use the vFirewall export function.

  1. Enter a name and a description for the vFirewall.

  1. Select a firewall type.

  1. Click Add Rule.

  1. To add a rule and return to the Import Virtual Firewall dialog box, configure the rule, and then click OK. To add rules in bulk, configure each rule, click Append, and then click OK after you add all desired rules.

  1. Click OK.

Edit a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Edit in the Actions columns for a vFirewall.

  1. Enter a description for the vFirewall.

  1. Manage the rules of the firewall:

  1. Click OK.

Delete a vFirewall

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Delete in the Actions columns for a vFirewall.

  1. In the dialog box that opens, click OK.

Export a vFirewall to a JSON file

You can export a vFirewall to a JSON file for backup or to synchronize the vFirewall to another cloud management platform. You can import the JSON file to the cloud management platform that exports it or another cloud management platform.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Export in the Actions columns for a vFirewall.

  1. Click OK to confirm the export operation.

  1. Select a storage path for the JSON file, and then click Save.

Attach a vFirewall to VMs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Attach VMs in the Actions columns for a vFirewall.

  1. Select VMs, and then click OK.

Detach a vFirewall from VMs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Detach VMs in the Actions columns for a vFirewall.

  1. Select VMs, and then click OK.

Copy a vFirewall

Perform this task to create a vFirewall based on an existing one. The new vFirewall must use a unique name on the management platform. You can edit or delete rules for the new vFirewall, but you cannot edit the firewall type for the new firewall.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > vFirewalls.

  1. Click Copy in the Actions columns for a vFirewall.

  1. Enter a name and a description for the vFirewall.

  1. Click Add Rule.

  1. To add a rule and return to the Copy Virtual Firewall dialog box, configure the rule, and then click OK. To add rules in bulk, configure each rule, click Append, and then click OK after you add all desired rules.

  1. Click OK.

Parameters

vFirewall list

Rules

Rule parameters