5.1

Table Of Contents
Table 6-3. SourceIp and DestinationIp Values
Value Result
Any Matches any IP address
Internal Matches any IP address originating on an
organization vDC network connected to
this EdgeGateway. When used in a vApp
network, matches any IP address assigned
to a virtual machine in the vApp.
External Matches any IP address originating on an
external network connected to this
EdgeGateway. When used in a vApp
network, matches any IP address except
those assigned to a virtual machine in the
vApp.
DestinationIp
Specify a source IP address, or use one of the strings shown in Table 6-3.
EnableLogging
Set to true to log all packets that trigger this rule. See “Firewall Rule
Logging,” on page 158.
Rules are applied to packets in the order in which the FirewallRule elements appear in the FirewallService
definition.
NOTE The system assigns an Id value to each rule you create and uses these values when logging rule actions.
<FirewallService>
<IsEnabled>true</IsEnabled>
<DefaultAction>allow</DefaultAction>
<LogDefaultAction>false</LogDefaultAction>
<FirewallRule>
<IsEnabled>true</IsEnabled>
<Description>allow incoming ssh</Description>
<Policy>allow</Policy>
<Protocols>
<Tcp>true</Tcp>
</Protocols>
<DestinationPortRange>22</DestinationPortRange>
<DestinationIp>Internal</DestinationIp>
<SourcePortRange>Any</SourcePortRange>
<SourceIp>External</SourceIp>
<EnableLogging>false</EnableLogging>
</FirewallRule>
<FirewallRule>
<IsEnabled>true</IsEnabled>
<Description>deny incoming telnet</Description>
<Policy>drop</Policy>
<Protocols>
<Tcp>true</Tcp>
</Protocols>
<DestinationPortRange>23</DestinationPortRange>
<DestinationIp>Internal</DestinationIp>
<SourcePortRange>Any</SourcePortRange>
Chapter 6 Creating and Managing Organizations
VMware, Inc. 159