Configura il NSX-v Edge Firewall (EN)

creating firewall rules

Last updated 25th November 2021

Objective

The NSX firewall service restricts or allows network traffic based on rules applied to network nodes or groups.

This guide explain how to create rules.

Requirements

Instructions

Interface access

In the vSphere interface menu, go to the Networking and Security dashboard.

Menu

On the left side, navigate to the NSX Edges section then click on the appliance you're setting up.

NSX

The Firewall tab shows the status with a simple button to stop or start the service.

Any change made will need to be published to be validated, so you will not shut down the service at the single push of a button.

Rule

Firewall Rules

The basics of a firewall rule is to manage identified service(s) from specified source(s) to specified destination(s).

Click on + Add Rule.

The new rule shows with:

  • An activation slider
  • A selection box for specific actions (order change, deletion...)
  • Name
  • ID
  • Type
  • Source
  • Destination
  • Service
  • Action
  • Log slider
  • Advanced settings

Rule

By default, rules have Any as source and destination, meaning it encompasses all traffic. To avoid security issues, it is best practices to avoid broad targets.

Name the rule by clicking the Name field. ID and Type fields are automatically populated.

Source

The source field defines the origin of the traffic.

Hover over the field and click on the pencil icon. You can add objects and/or IP addresses as needed.

If "Negate Source" is turned on, the rule is applied to all sources except for the sources selected.

Click Save when ready.

Source

Source

Destination

The destination field defines the target of the traffic.

Hover over the field and click on the pencil icon. You have the same choices for destination as you had for source.

If "Negate Source" is turned on, the rule is applied to all destinations except for the destinations selected.

Click Save when ready.

Destination

Destination

Service

The service field defines the type of traffic aimed at.

Hover over the field and click on the pencil icon. You have the choice between using existing services and groups or add raw ports/protocols.

Clicking on an existing service or group will show you a description with the ports and protocols involved.

Click Save when ready.

Service

Service

Service

Action

The action field defines how to handle the traffic.

You have three possible options to choose from:

  • Accept: The traffic will go through.
  • Deny: The traffic will be blocked with no further communication.
  • Reject: The traffic will be blocked and a "port unreachable" message will be sent to the source.

Action

Log

The log slider allows you to keep a journal of events on the rule.

Advanced Settings

Aside from a comments section and a statistics section, the advanced settings section allows you to define if the target traffic is inbound, outbound or both. In case of NAT traffic, you can choose if the rule applies to the original or translated source.

Advanced

Rules priorities

Once the rule is set up, you see it in the list. The number of the rule in the list defines its priority.

Rules are applied from top to bottom.
The first rule that matches the traffic overrides all the other rules below.
That means that in the case of conflicting rules, the rule with the highest priority (lowest number) will be applied.

You can modify the rule order by selecting a rule and using the up and down arrows.

Order

Publishing rules

No creation/modification of a rule will be registered until you click the Publish button.

Publish

Publish

Go further

Join our community of users on https://community.ovh.com/en/.


Questa documentazione ti è stata utile?

Prima di inviare la valutazione, proponici dei suggerimenti per migliorare la documentazione.

Immagini, contenuti, struttura... Spiegaci perché, così possiamo migliorarla insieme!

Le richieste di assistenza non sono gestite con questo form. Se ti serve supporto, utilizza il form "Crea un ticket" .

Grazie per averci inviato il tuo feedback.


Potrebbero interessarti anche...

OVHcloud Community

Accedi al tuo spazio nella Community Fai domande, cerca informazioni, pubblica contenuti e interagisci con gli altri membri della Community OVHcloud

Discuss with the OVHcloud community

Conformemente alla Direttiva 2006/112/CE e successive modifiche, a partire dal 01/01/2015 i prezzi IVA inclusa possono variare in base al Paese di residenza del cliente
(i prezzi IVA inclusa pubblicati includono di default l'aliquota IVA attualmente in vigore in Italia).