5.2.1.2. Firewall Instance Operation

The Firewall instance operation items executable on the control panel are outlined in this section. As shown below, a desired instance operation can be selected form the pull-down menu.

ファイアウォールインスタンスリスト

Edit Your Firewall

A customer can edit names and descriptions of Firewall and Firewall interface.

Editing Firewall interface

A customer can edit the connection-destination logical network and static IP address of Firewall.

Setting an allowed address pair

A customer can edit an address pair which is assigned to the interface of Firewall.

Reset the Password

A customer can reset the password of root which is used for access to Firewall.

Starting Firewall

A customer can start a Firewall instance.

Stopping Firewall

A customer can stop a Firewall instance.

Restarting Firewall

A customer can restart a Firewall instance.

Console

A customer can connect a console to Firewall.

Delete Your Firewall

A customer can delete a Firewall instance.

Note

  • The vSRX user whose password is to be reset is only root.

  • Firewall start or restart takes 20 to 30 minutes to complete. Keep the time in mind when estimating the workload.

  • Please note that billing will continue after the firewall is stopped or the logical network is disconnected. If you want to stop charging, delete the firewall.

Below are detailed instructions for editing firewalls, editing firewall interfaces, editing allowed address pairs, and consoles.

Edit Your Firewall

Open the edit screen of the firewall you want to edit, and specify the firewall name and description.

ファイアウォールメタデータ編集

Name

Specify the name of the Firewall.

Description

Specify the description of the Firewall.

Editing Firewall interface

Open the interface tab to be edited, check the checkbox for "Edit this interface", and then specify a connection-destination logical network and static IP address.

ファイアウォールインターフェイス編集(インターフェイス)

Edit this interface

Check the checkbox to edit.

Logical Network

Specify a connection-destination logical network.

Static IP address

Specify a static IP address to be assigned to the interface.

Note

  • To edit the interface, be sure to check the checkbox for "Edit this interface". If the checkbox is not checked, the changes are not reflected.

  • The customer portal / API interface 1-8 corresponds to the vSRX portal / API / CLI interface ge-0 /0/0-ge-0 /0/7..

  • Firewall interface edit takes 15 to 20 minutes to complete. Keep the time in mind when estimating the workload.

  • If it is already connected to the same logical network, or if the network address of the logical network is duplicated, an error will occur after editing.

  • When editing Firewall interface, be sure to enter a static IP address.

  • Unlike when creating a firewall (vSRX), the fixed IP address specified at the time of editing is not set to vSRX. Please execute in vSRX portal / API / CLI.

  • If the operation warning is displayed after the interface has been edited, there is a possibility that vSRX has not been started or that config changes (enabling / disabling the interface) have not been performed. There is. Excuse me, please stop / start vSRX or change config. If a warning is still displayed when you try again after a while, please contact us with your ticket.

Editing an allowed address pair

Click “Add Address Pair” on the interface tab you want to edit.

許可されたアドレスペア編集(インターフェイス)

Specify the following parameters on the screen for updating permitted address pairs, and click "Update permitted address pairs".

許可されたアドレスペア編集(インターフェイス)

IP Address

It is possible to specify the IP address of an allowed address pair to be assigned to the interface.

MAC Address

It is possible to specify the MAC address of an allowed address pair to be assigned to the interface.

If you want to register the IP address and VRID used in VRRP settings, select “VRRP” in “Type” and specify the following parameters.

許可されたアドレスペア編集(インターフェイス)

IP Address

It is possible to specify the IP address of an allowed address pair to be assigned to the interface.

Type

Specify "VRRP" as the allowed address pair type to be assigned to the interface.

VRID

You can specify the VRID to be used in VRRP settings.

Note

  • Regarding the address pair allowed, the upper limit number per interface is 1.

  • VRRP settings must be made for each Firewall (vSRX) which is a VRRP constituent.

  • To actually perform communications using VRRP, this setting must be followed by VRRP settings through vSRX portal/API/CLI.

  • vSRX needs to be restarted if having logged in vSRX and made VRRP settings before registering communication settings for VRRP from the customer portal.

  • For the vSRX settings, refer to vSRX guide .

Console

Opening the console makes the screen below appear.

コンソール

Note

  • Send Ctrl + Alt + Del at the top right of the screen does not work. When restarting, start from "Restart Firewall (vSRX)".