You can configure certain vApp networks to provide firewall services. Enable the firewall on a vApp network to enforce firewall rules on the incoming traffic, outgoing traffic, or both.
When you enable the firewall, you can specify a default firewall action to deny all incoming and outgoing traffic or to allow all incoming and outgoing traffic. You can also add specific firewall rules to allow or deny traffic that matches the rules to pass through the firewall. These rules take precedence over the default firewall action. See Add a Firewall Rule to a vApp Network.
If a system administrator specified syslog server settings and those settings have been applied to the vApp network, then you can log events related to the default firewall action. For information about applying syslog server settings, see Apply Syslog Server Settings to a vApp Network. To view the current syslog server settings, see View Syslog Server Settings for a vApp Network.
A routed vApp network.
- Click the My Cloud tab and click vApps in the left pane.
- Right-click the vApp in the right pane and click Open.
- Click the Networking tab.
- Right-click the vApp network and select Configure Services.
- To enable firewall services, click the Firewall tab and select Enable firewall. To disable firewall services, deselect Enable firewall.
- Select the default firewall action.
Option Description Deny Blocks all traffic except when overridden by a firewall rule. Allow Allows all traffic except when overridden by a firewall rule.
- (Optional) Select the Log check box to log events related to the default firewall action.
- Click OK.
- Click Apply.