Manage Firewalls and Load Balancers
Manage firewall policies and load balancer policies for virtual datacenters, create firewall rules, and attach firewall policies to VMs, and attach load balancers to VMs on the multicloud platform.
Manage firewalls
Introduction to Firewalls
The platform provides a unified interface to firewalls in varied cloud environments.
This section describes firewall policies, which are similar to security groups. The platform supports firewall policies in private cloud with network managers (NSX, NSX-T) and in public cloud.
Abiquo firewall policies represent.
- AWS security groups
- Azure firewall policies
- GCP firewall rules
- OCI network security groups
For more details, please see the public cloud features table for each provider.
In vCloud Director, the platform also supports classic firewalls, which are Edge firewalls at level of the public cloud region (orgVDC). See Manage classic firewalls.
Synchronize firewall policies with the cloud provider
The synchronization process will onboard firewalls and it will update the platform's information about firewalls that already exist in the cloud provider. The platform synchronizes automatically when you onboard virtual resources from public cloud. Depending on the provider, the platform may support synchronization at the level of the location (public cloud region) or virtual datacenter.
To synchronize firewalls do these steps:
- In the myCloud view go to Virtual datacenters, or Locations, or for Google Cloud Platform select the Global view
- Go to Network → Firewalls
- Click the double-arrow synchronize button
To synchronize a firewall in AWS before you add new firewall rules:
- Select the firewall and click the double-arrow synchronize button
Create a firewall policy
The platform can create firewall policies in virtual datacenters in the provider, or in the platform only, for later use in providers, depending on provider support.
Privilege: Manage firewall
To create a new firewall, do these steps:
- Go to Virtual datacenters → Network → Firewalls
- Click the Add button
- Enter the firewall details
For more details see GUI Create firewall policy - Click Save to create the firewall
- Add Firewall rules as described below
If you entered a virtual datacenter, the platform created your firewall in the provider. The platform will display a Provider-ID and a Virtual datacenter ID for the firewall.
If you selected No virtual datacenter, the firewall will be created in the platform in the public cloud region for your enterprise. The synchronize process will not update this firewall. The platform will not create it in the provider until you select a virtual datacenter.
Edit firewall rules
You can define firewall rules for inbound and outbound traffic in your firewall policy.
To add a new firewall rule:
- Select the virtual datacenter or location
- Select the firewall
- On the Firewall rules panel, click the pencil Edit button
- Select the Inbound or Outbound tab for the traffic direction you wish to control
- Enter the details of a rule
- Protocol
- Select from Common protocols, OR
- Select and enter a Custom protocol
- Port range with the Start port and End port that this rule will apply to. To enter one port, enter the same value twice, or optionally apply the rule to a number of ports at the same time
- Sources or Targets as a network address and netmask
- Click Add. The firewall rule will be added to the Firewall rules list
- Enter more rules as required, then click Save
Before you edit firewall rules in AWS, synchronize the firewall to update the rules because AWS will not allow you to create a rule that already exists in the security group. Remember that it may take some time for firewall rules to propagate throughout AWS. Until the rules have propagated, the platform will not be able to detect them. See http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/query-api-troubleshooting.html#eventual-consistency
Create a firewall policy in GCP
In GCP, the platform can create firewall policies in virtual datacenters or in global networks, to later attach to VMs.
Privilege: Manage firewall, Manage global networks
To create a new firewall, do these steps:
- Go to Virtual datacenters → Network → Firewalls
or go to myCloud → Global → select the GCP provider → Network → Firewalls - Click the Add button
- Enter the firewall details and select the direction
For more details see GUI Create firewall policy GCP General information - Go to Inbound or Outbound and add firewall rules
For more details see GUI Create firewall policy GCP rules inbound outbound - After you finish adding rules, click Save
The platform will create your firewall in the provider.
Set a firewall policy as the default for a virtual datacenter
You can set a default firewall policy for each virtual datacenter.
Privilege: Manage default firewall
To set or unset a default firewall for a virtual datacenter:
- Select the firewall
- Click the star default firewall button
When the user creates a VM, the platform will assign the default firewall. The firewall rules apply to VMs, not individual NICs on the VMs. Changes to the firewall ruleset will apply to every VM in the virtual datacenter with the default firewall. If you do not set a default firewall but the provider requires one, for example, AWS, the platform will set the provider's default firewall. In AWS the default firewall is not marked.
Edit a firewall policy
If your provider allows it, you may edit a firewall policy in the platform.
To edit a firewall policy:
- Go to Virtual datacenters → select virtual datacenter or select a region → Network → Firewalls
- Select the firewall policy and click the pencil edit button.
- Make your changes and click Save
For more details see GUI Edit firewall policy
To add a tag, enter the Key and Value, then click Add.
For providers that support tags:
- If you have invalid tags, optionally select the checkbox to Create local tags if tags are invalid in the provider
To onboard or update tags with changes from the provider, click the round arrow Synchronize button.
To delete a tag, select the tag, then click the Delete button.
To save your changes, click Save.
Add tags to a firewall policy
When you edit a firewall, you can add tags to group resources and manage them in Control view
To manage tags for a firewall, edit the firewall and add tags as described here.
To add a tag, enter the Key and Value, then click Add.
For providers that support tags:
- If you have invalid tags, optionally select the checkbox to Create local tags if tags are invalid in the provider
To onboard or update tags with changes from the provider, click the round arrow Synchronize button.
To delete a tag, select the tag, then click the Delete button.
To save your changes, click Save.
Move a firewall policy to another virtual datacenter
Before you begin:
- Check if your provider allows you to move firewalls. For example, Azure ARM allows you to move firewalls to other VDCs in the same resource group
To move a firewall to another virtual datacenter
- Go to Virtual datacenters → Locations or Global
- Select the public cloud region, or Azure provider and resource group
- Edit the firewall policy and select the new Virtual datacenter
Display firewall policies
You can display and manage firewalls in the platforms at the level of the virtual datacenter or the location (public cloud region or datacenter).
To display firewalls in a virtual datacenter in a provider:
- Go to Virtual datacenters → select a virtual datacenter → Network → Firewalls
To display all firewalls in Google Cloud Platform
- Go to myCloud → Global view → select the GCP provider → Networks → Firewalls
To display all firewalls in a location (public cloud region or datacenter):
- Go to Cloud virtual datacenters view → Locations
- Select a location
- Go to Network → Firewalls
Firewalls that do not exist in the provider are grayed out, and you should delete these firewalls.
To filter firewalls, enter text in the Search box to search by the Name, Description, and Provider ID in the Firewalls list.
To display firewalls in an Azure Resource Group:
- Go to Cloud virtual datacenters view
- Go to Global → Azure → Resource Groups → select a resource group
- To display the details of the firewall, edit the firewall
Assign a firewall policy to a VM
See Assign a firewall policy to a VM
Delete firewall policy rules
To delete firewall rules, do these steps.
- Go to Virtual datacenters → select a virtual datacenter or select All → Network → Firewalls
- Edit the firewall
- Select the Inbound or Outbound tab
- On the left-hand side of each rule you wish to delete, click the trash bin Delete button
- Click Save
Delete a firewall policy
To delete a firewall policy:
- Edit each VM that is using the firewall policy to remove the firewall policy
- Select the firewall policy
- Click the Delete button
Manage firewalls with the API
API Documentation
For the Abiquo API documentation of this feature, see Abiquo API Resources and the page for this resource FirewallPoliciesResource.
Manage load balancers
Introduction to load balancers
The load balancer feature aims to simplify the creation of load balancers across all providers in the multi-cloud platform, providing a unified interface.
In AWS, Abiquo supports Application load balancers (see Manage Application Load Balancers) and Classic load balancers (described on this page).
Please refer to cloud provider documentation as the definitive guide to the load balancing features. And remember to check your cloud provider's pricing before you begin.
In vCloud Director, load balancers belong to a public cloud region, not a virtual datacenter. This means that in vCloud Director, you can attach VMs from more than one virtual datacenter to the same load balancer, and these load balancers do not work with private networks, which belong to only one virtual datacenter.
Display load balancers
You can display and manage load balancers in the platform at the level of the virtual datacenter or the location (public cloud region or datacenter).
To display load balancers in virtual datacenters:
- Go to Cloud virtual datacenters view
Select a virtual datacenter
Go to Network → Load balancers.
To display load balancers in a region, including those that do not exist in the provider.
- Go to Cloud virtual datacenters view
- Click the Locations button and select a location
- Go to Network → Load balancers
Load balancers that do not exist in the provider are displayed in light gray text and you should delete these load balancers.
To display load balancers in an Azure Resource Group:
- Go to Cloud virtual datacenters view
- Go to Global → Azure → Resource Groups → select a resource group
- To display the details of the load balancer, edit the load balancer
Create a load balancer
Before you begin:
- Synchronize your virtual datacenters (including VMs, networks, firewalls, firewall rules, and load balancers)
- If required by your provider, create firewalls for your VMs to allow your load balancers to access the VMs
- In Azure make sure that your VMs belong to availability sets
Privilege: Manage load balancers, Assign load balancers
To create a load balancer:
- Go to Virtual datacenters → select a virtual datacenter → Network → Load balancers
- For vCloud, select All virtual datacenters → Network → Load balancers → Region
Click the + add button and complete the following dialogs according to your cloud provider's documentation
Load balancer general information
The following screenshots are from AWS or Azure
For more details see GUI Create load balancer General info
Load balancer routing rules
For more details see GUI Create load balancer Routing rules
Load balancer SSL certificate
For more details see GUI Add a new certificate
Load balancer health check
For more details see GUI Create load balancer Health check
Load balancer firewalls
For more details see GUI Create load balancer Firewalls
Assign load balancer nodes
For more details see GUI Create load balancer Nodes
Manage load balancers with the API
API Documentation
For the Abiquo API documentation of this feature, see Abiquo API Resources and the page for this resource LoadBalancersResource.
Edit load balancers
The cloud provider determines which elements of a load balancer that you can modify. Due to different provider support for load balancer features, it may be possible to make modifications in the platform that will later be rejected by the cloud provider, triggering an error. Check your cloud provider documentation for supported modifications.
Add tags to a load balancer
To manage tags for a load balancer, edit the load balancer and add tags as described here.
To add a tag, enter the Key and Value, then click Add.
For providers that support tags:
- If you have invalid tags, optionally select the checkbox to Create local tags if tags are invalid in the provider
To onboard or update tags with changes from the provider, click the round arrow Synchronize button.
To delete a tag, select the tag, then click the Delete button.
To save your changes, click Save.
Edit VMs to assign or unassign to load balancers
Privilege: Assign load balancers
To assign a virtual machine to a load balancer, select the load balancer from the list.
Onboard and synchronize load balancers from public cloud
When you onboard a VDC from a public cloud provider, the load balancers associated with the VDC and its VMs will be onboarded into the platform.
To access vCloud load balancers, and provider-only load balancers
- Go to Virtual datacenters → All virtual datacenters
- Go to Network → Load balancers → select region
To synchronize all load balancers in a VDC or region:
- Go to Virtual datacenters
- Select the VDC or region
- Click the arrow synchronize button.
Load balancers that have been deleted directly in the provider are displayed in light gray text. You can edit these load balancers to recreate them in the provider, or delete them.
Delete or release load balancers
To delete a load balancer:
- Select the load balancer
- Click the delete button.
If your enterprise does not have credentials in the provider, then the load balancer will be released (it will be deleted in the platform but it will remain in cloud provider).
Pages related to load balancers
Copyright Ā© 2006-2022, Abiquo Holdings SL. All rights reserved