Firewalls

Deploy firewall instances and manage their rules, NAT, routing, DHCP, and logs.

Back to documentation

Firewalls

Purpose

  • Deploy firewall instances with one or more network interfaces.
  • Control traffic with ranked allow, deny, and reject rules.
  • Configure source NAT (SNAT) and destination NAT (DNAT).
  • Manage static routes and OSPF dynamic routing.
  • Configure DHCP servers and relay per interface.
  • Review event logs scoped to a single firewall.

Prerequisites

  • Minimum permission to view: networking.firewalls.read.
  • Permission to create firewalls, rules, NAT, routes, OSPF, and DHCP: networking.firewalls.create.
  • Permission to edit rules and NAT: networking.firewalls.update.
  • Permission to delete rules, NAT, and routes: networking.firewalls.delete.
  • Permission to view the Logs tab: networking.firewalls.read.
  • Firewall interfaces must exist before configuring DHCP or NAT.

View firewalls

Firewalls live in the Networking section.

  1. Open Networking → Firewalls.
  2. Review the list of firewalls visible to the active account.
  3. Select a firewall to open its detail tabs: Details, Rules, SNAT, DNAT, Static Routes, DHCP, and Logs.
  4. Expected result: the selected firewall opens on its Details tab.

Create a firewall

  1. Open Networking → Firewalls.
  2. Select Create Firewall.
  3. Enter a firewall name and an optional description.
  4. Choose a size: Small, Medium, or Large.
  5. Optionally enable Default Deny Rules to auto-create default deny rules for each interface.
  6. Under Network Configuration, add the firewall interfaces.
  7. Optionally assign tags or a resource group.
  8. Select Create Firewall.
  9. Expected result: the firewall is queued for creation and appears in the list once provisioned.

Add or edit firewall rules

  1. Open Networking → Firewalls, open a firewall, then open the Rules tab.
  2. Select Create to add rules, or select a rule and choose Edit.
  3. Enter a rule name, set the rank (1-9998; lower rank = higher priority), and toggle Enabled.
  4. Choose the firewall interface, action (Allow, Deny, or Reject), and protocol (TCP, UDP, ICMP, or Any).
  5. Enter source and destination IP or CIDR; for TCP or UDP, add source and destination ports.
  6. On the create form, use Add Rule to configure additional rules in one submission.
  7. Save.
  8. Expected result: the rule set is queued and applied in rank order.

Configure SNAT

  1. Open the SNAT tab on a firewall.
  2. Select Create SNAT Rule, or select a rule and choose Edit.
  3. Set the rank and the outbound interface.
  4. Enter the original source subnet in CIDR notation.
  5. Enable Masquerade, or leave it off and enter a translated source IP.
  6. Save.

Configure DNAT

  1. Open the DNAT tab on a firewall.
  2. Select Create DNAT Rule, or select a rule and choose Edit.
  3. Set the rank, the inbound interface, and the protocol (TCP, UDP, TCP/UDP, ICMP, or Any).
  4. Enter the original and translated destination IP or CIDR.
  5. For TCP or UDP protocols, enter the original and translated ports.
  6. Save.

Manage static routes and OSPF

  1. Open the Static Routes tab on a firewall.
  2. Select Create Static Route, then set the route name, destination prefix (CIDR), and next hop address; add more rows as needed.
  3. Use Refresh to pull the live routing table from the firewall.
  4. Select Manage OSPF to open the OSPF page.
  5. Enable OSPF, set the router IP, and add interface groups.
  6. Save.
  7. Expected result: routes and OSPF settings are queued and reflected in the routing table.

Configure DHCP

  1. Open the DHCP tab on a firewall.
  2. Review each interface card, which shows its current DHCP type: none, server, or relay.
  3. Edit an interface to configure a DHCP server (subnet, address range, lease time, DNS servers, static mappings) or a relay.
  4. Save.
  5. Expected result: the DHCP configuration is queued for the selected interface.

View firewall logs

  1. Open the Logs tab on a firewall.
  2. Review the event log entries filtered to that firewall.
  3. Expected result: log entries for the firewall are listed (requires networking.firewalls.read).

Best Practices

  • Enable Default Deny Rules at creation to start from a closed security posture.
  • Order rules by rank; lower rank takes higher priority and equal ranks shift down.
  • Scope rules to specific source and destination CIDRs rather than Any.
  • Create firewall interfaces before configuring DHCP or NAT.
  • Use the Static Routes Refresh action to confirm the firewall's live routing table.

Ready to rethink private cloud?

Lower costs. Simplify operations. Deliver more.