- 07 Nov 2022
- DarkLight
How to Add an Edge Gateway Firewall Rule
- Updated on 07 Nov 2022
- DarkLight
IMPORTANT: This article should only be followed if you are using the NSX Edge as your Edge firewall. In instances where you have an Expedient-provided firewall or your own firewall in any of Expedient’s cloud offerings, you should utilize the NSX-V Distributed Firewall by following the guide “Writing Distributed Firewall Rules” under the Networking category on the left.
You use the edge gateway Firewall screen in the EEC portal to add firewall rules for that edge gateway. You can add multiple NSX edge interfaces and multiple IP address groups as the source and destination for these firewall rules
Specifying internal for a source or a destination of a rule indicates traffic for all subnets on the port groups connected to the NSX edge gateway. If you select internal as the source, the rule is automatically updated when additional internal interfaces are configured on the NSX edge gateway.
Note:
Edge gateway firewall rules on internal interfaces do not work when the edge gateway is configured for dynamic routing.
Procedure
Click in the Destination cell and perform one of the following options:
Option | Description |
Click the IP icon | Type the destination value you want to use. Valid values are an IP address, CIDR, an IP range, or the keyword any. The edge gateway firewall supports both IPv4 and IPv6 formats. |
Click the + icon | Use the + icon to specify the source as an object other than a specific IP address:
When the toggle exclusion is selected on the source, the rule is applied to traffic coming from all sources except for the source you excluded. When the toggle exclusion is not selected, the rule applies to traffic coming from the source you specified in the Select objects window |
Click in the Service cell of the new rule and click the + icon to specify the service as a port-protocol combination:
Select the service protocol.
Type the port numbers for the source and destination ports, or specify any.
Click Keep.
In the Action cell of the new rule, configure the action for the rule.
Option | Description |
Accept | Allows traffic from or to the specified sources, destinations, and services. |
Deny | Blocks traffic from or to the specified sources, destinations, and services. |
Click Save changes.
The save operation can take a minute to complete.