5.5

Table Of Contents
5 Select the default firewall action.
Option Description
Deny
Blocks all traffic except when overridden by a firewall rule.
Allow
Allows all traffic except when overridden by a firewall rule.
6 (Optional) Select the Log check box to log events related to the default firewall action.
7 Click OK.
Add a Firewall Rule for an Edge Gateway
You can add firewall rules to an edge gateway that supports a firewall. You can create rules to allow or deny
traffic that matches the rules to pass through the firewall.
For a firewall rule to be enforced, you must enable the firewall for the edge gateway. See “Configure the
Firewall for an Edge Gateway,” on page 70.
When you add a new firewall rule to an edge gateway, it appears at the bottom of the firewall rule list. For
information about setting the order in which firewall rules are enforced, see “Reorder Firewall Rules for an
Edge Gateway,” on page 72.
System administrators and organization administrators can add firewall rules to an edge gateway.
Procedure
1 Click the Manage & Monitor tab and click Organization VDCs in the left pane.
2 Double-click the organization virtual datacenter name to open the organization virtual datacenter.
3 Click the Edge Gateways tab, right-click the edge gateway name and select Edge Gateway Services.
4 Click the Firewall tab and click Add.
5 Type a name for the rule.
6 (Optional) Select Match rule on translated IP to have the rule check against translated IP addresses
rather than original IP addresses and choose a traffic direction to apply this rule on.
7 Type the traffic Source.
Option Description
IP address
Type a source IP address to apply this rule on.
Range of IP addresses
Type a range of source IP addresses to apply this rule on.
CIDR
Type the CIDR notation of traffic to apply this rule on.
internal
Apply this rule to all internal traffic.
external
Apply this rule to all external traffic.
any
Apply this rule to traffic from any source.
8 Select a Source port to apply this rule on from the drop-down menu.
9 Type the traffic Destination.
Option Description
IP address
Type a destination IP address to apply this rule on.
Range of IP addresses
Type a range of destination IP addresses to apply this rule on.
CIDR
Type the CIDR notation of traffic to apply this rule on.
internal
Apply this rule to all internal traffic.
Chapter 5 Managing Cloud Resources
VMware, Inc. 71