5.5

Table Of Contents
6 Select the default firewall action.
Option Description
Deny
Blocks all traffic except when overridden by a firewall rule.
Allow
Allows all traffic except when overridden by a firewall rule.
7 (Optional) Select the Log check box to log events related to the default firewall action.
8 Click OK.
9 Click Apply.
Add a Firewall Rule to a vApp Network
You can add firewall rules to a vApp network that supports a firewall. You can create rules to allow or deny
traffic that matches the rules to pass through the firewall.
For a firewall rule to be enforced, you must enable the firewall for the vApp network. See “Configure the
Firewall for a vApp Network,” on page 74.
When you add a new firewall rule to a vApp network, it appears at the end of the firewall rule list. For
information about setting the order in which firewall rules are enforced, see “Reorder Firewall Rules for a
vApp Network,” on page 76.
If a system administrator specified syslog server settings and those settings were applied to the vApp
network, then you can log firewall rule events. For information about applying syslog server settings, see
“Apply Syslog Server Settings to a vApp Network,” on page 82. To view the current syslog server settings,
see “View Syslog Server Settings for a vApp Network,” on page 82.
Prerequisites
A routed vApp network.
Procedure
1 Click the My Cloud tab and click vApps in the left pane.
2 Right-click a vApp and select Open.
3 On the Networking tab, select Show networking details.
4 Right-click the vApp network and select Configure Services.
5 Click the Firewall tab and click Add.
6 Type a name for the rule.
7 (Optional) Select Match rule on translated IP to have the rule check against translated IP addresses
rather than original IP addresses and choose a traffic direction to apply this rule on.
8 Type the traffic Source.
Option Description
IP address
Type a source IP address to apply this rule on.
Range of IP addresses
Type a range of source IP addresses to apply this rule on.
CIDR
Type the CIDR notation of traffic to apply this rule on.
internal
Apply this rule to all internal traffic.
external
Apply this rule to all external traffic.
any
Apply this rule to traffic from any source.
9 Select a Source port to apply this rule on from the drop-down menu.
Chapter 7 Working with vApps
VMware, Inc. 75