Firewalls
Deploy firewall instances and manage their rules, NAT, routing, DHCP, and logs.
Firewalls
Purpose
- Deploy firewall instances with one or more network interfaces.
- Control traffic with ranked allow, deny, and reject rules.
- Configure source NAT (SNAT) and destination NAT (DNAT).
- Manage static routes and OSPF dynamic routing.
- Configure DHCP servers and relay per interface.
- Review event logs scoped to a single firewall.
Prerequisites
- Minimum permission to view: networking.firewalls.read.
- Permission to create firewalls, rules, NAT, routes, OSPF, and DHCP: networking.firewalls.create.
- Permission to edit rules and NAT: networking.firewalls.update.
- Permission to delete rules, NAT, and routes: networking.firewalls.delete.
- Permission to view the Logs tab: networking.firewalls.read.
- Firewall interfaces must exist before configuring DHCP or NAT.
View firewalls
Firewalls live in the Networking section.
- Open Networking → Firewalls.
- Review the list of firewalls visible to the active account.
- Select a firewall to open its detail tabs: Details, Rules, SNAT, DNAT, Static Routes, DHCP, and Logs.
- Expected result: the selected firewall opens on its Details tab.
Create a firewall
- Open Networking → Firewalls.
- Select Create Firewall.
- Enter a firewall name and an optional description.
- Choose a size: Small, Medium, or Large.
- Optionally enable Default Deny Rules to auto-create default deny rules for each interface.
- Under Network Configuration, add the firewall interfaces.
- Optionally assign tags or a resource group.
- Select Create Firewall.
- Expected result: the firewall is queued for creation and appears in the list once provisioned.
Add or edit firewall rules
- Open Networking → Firewalls, open a firewall, then open the Rules tab.
- Select Create to add rules, or select a rule and choose Edit.
- Enter a rule name, set the rank (1-9998; lower rank = higher priority), and toggle Enabled.
- Choose the firewall interface, action (Allow, Deny, or Reject), and protocol (TCP, UDP, ICMP, or Any).
- Enter source and destination IP or CIDR; for TCP or UDP, add source and destination ports.
- On the create form, use Add Rule to configure additional rules in one submission.
- Save.
- Expected result: the rule set is queued and applied in rank order.
Configure SNAT
- Open the SNAT tab on a firewall.
- Select Create SNAT Rule, or select a rule and choose Edit.
- Set the rank and the outbound interface.
- Enter the original source subnet in CIDR notation.
- Enable Masquerade, or leave it off and enter a translated source IP.
- Save.
Configure DNAT
- Open the DNAT tab on a firewall.
- Select Create DNAT Rule, or select a rule and choose Edit.
- Set the rank, the inbound interface, and the protocol (TCP, UDP, TCP/UDP, ICMP, or Any).
- Enter the original and translated destination IP or CIDR.
- For TCP or UDP protocols, enter the original and translated ports.
- Save.
Manage static routes and OSPF
- Open the Static Routes tab on a firewall.
- Select Create Static Route, then set the route name, destination prefix (CIDR), and next hop address; add more rows as needed.
- Use Refresh to pull the live routing table from the firewall.
- Select Manage OSPF to open the OSPF page.
- Enable OSPF, set the router IP, and add interface groups.
- Save.
- Expected result: routes and OSPF settings are queued and reflected in the routing table.
Configure DHCP
- Open the DHCP tab on a firewall.
- Review each interface card, which shows its current DHCP type: none, server, or relay.
- Edit an interface to configure a DHCP server (subnet, address range, lease time, DNS servers, static mappings) or a relay.
- Save.
- Expected result: the DHCP configuration is queued for the selected interface.
View firewall logs
- Open the Logs tab on a firewall.
- Review the event log entries filtered to that firewall.
- Expected result: log entries for the firewall are listed (requires networking.firewalls.read).
Best Practices
- Enable Default Deny Rules at creation to start from a closed security posture.
- Order rules by rank; lower rank takes higher priority and equal ranks shift down.
- Scope rules to specific source and destination CIDRs rather than Any.
- Create firewall interfaces before configuring DHCP or NAT.
- Use the Static Routes Refresh action to confirm the firewall's live routing table.
Ready to rethink private cloud?
Lower costs. Simplify operations. Deliver more.