5.1

Table Of Contents
e To apply the rule to the translated IP address and services for a NAT rule, select Translated IP for
Match on.
f Click Enable Rule Direction and select Incoming or Outgoing. VMware does not recommend
specifying the direction for firewall rules.
g Click OK.
14 Click Publish Changes to push the new rule to the vShield Edge instance.
What to do next
n
Disable a rule by clicking
next to the rule number in the No. column.
n
Display additional columns in the rule table by clicking and selecting the appropriate columns.
Column Name Information Displayed
Rule Tag Unique system generated ID for each rule
Log Traffic for this rule is being logged or not
Stats
Clicking shows the traffic affected by this rule (number of sessions, traffic packets, and size)
Comments Comments for the rule
n
Search for rules by typing text in the Search field.
Change Default Firewall Rule
Default firewall settings apply to traffic that does not match any of the user-defined firewall rules. The default
firewall policy blocks all incoming traffic. You can change the default action and logging settings.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click the vShield Edge for which you want to change the default firewall policy.
6 Click the Firewall tab.
7 Select the Default Rule, which is the last rule in the firewall table.
8
Point to the Action cell of the new rule and click .
a Click Accept to allow traffic from or to the specified source and destination.
b Click Log to log all sessions matching this rule.
Enabling logging can affect performance.
c Type comments if required.
d Click OK.
9 Click Publish Changes.
Chapter 9 vShield Edge Management
VMware, Inc. 73