The page has been translated by Gen AI.

How-to guides

Users can create the service by entering the required information for the Firewall service and selecting detailed options through the Samsung Cloud Platform Console.

Create Firewall

You can create and use the Firewall service from the Samsung Cloud Platform Console.

Information

The Firewall service is created only after it is enabled in the prerequisite Networking service. The enabled Firewall can be viewed in the Firewall list.

  • A firewall cannot be created independently, unlike other services in the Samsung Cloud Platform Console.

To configure the firewall, follow the steps below.

  1. All Services > Networking > Firewall click the menu. 1. Navigate to the Service Home page of the Firewall.

  2. On the Service Home page, click the prerequisite service to create. 2. Navigate to the service creation page.

    • VPC Creation: Enable the Internet Gateway and the Transit Gateway Firewall of the VPC service.
      • When creating a VPC Internet Gateway service, set the Firewall Use item to Use. * For detailed information, please refer to Internet Gateway 생성하기.
      • Create the Transit Gateway service for the VPC and request the Uplink Firewall integration service. * For detailed instructions, please refer to Transit Gateway 생성하기.
    • Direct Connet creation: When creating a Direct Connet service, set the Firewall usage item to Enable. * For detailed instructions, please refer to Direct Connect 생성하기.
    • Load Balancer creation: When creating a Load Balancer service, set the Firewall usage option to Enabled. * For detailed instructions, see Load Balancer 생성하기.
  3. After the prerequisite service creation is complete, verify that the corresponding Firewall resource appears in the Firewall list.

Check firewall detailed information

The Firewall service can view and edit the full resource list and detailed information in the resource management menu.

To view detailed information about the firewall, follow these steps.

  1. All Services > Networking > Firewall Click the menu. 1. Go to the Service Home page of the Firewall.
  2. On the Service Home page, click Firewall List. 2. Navigate to the Firewall list page.
    • On the Firewall List page, you can view the information below.
      CategoryDetailed description
      Firewall nameFirewall pre-service type_Firewall automatically generated in the format
      Firewall classificationFirewall pre-service type (Internet Gateway, Direct Connect, Load Balancer)
      SizeUser-selected Firewall size
      VPC nameVPC name connected to the firewall
      Connection nameAutomatically generate in the format preceding service name_Firewall using Firewall
      Number of rulesNumber of rules used on this firewall
      UsageWhether the Firewall is used (enabled), not used (disabled)
      • If not used, the Any Allow rule is applied and no charges are incurred for the Firewall
      StatusFirewall status display
      • click the More button to set Enabled/Disabled
      Table. Firewall resource list items
  3. On the Firewall List page, click the resource to view detailed information. 3. Go to the Firewall Details page.
    • Firewall Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Action History tabs.
      CategoryDetailed description
      Service statusFirewall 상태 표시
      • Creating: Creating
      • Active: Running/All firewalls operating normally
      • Editing: Editing
      • Deploying: Deployment completed
      • Deleting: Deleting
      • Error: Error occurred/Errors occurred on one or more firewalls
      Table. Firewall status information

Detailed Information

Firewall list page lets you view detailed information of the selected resource and edit the information if needed.

CategoryDetailed description
ServiceService name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource IDService’s unique resource ID
ConstructorUser who created the service
Creation date and timeService creation date and time
ModifierUser who edited the service information
Modification date and timeDate and time the service information was modified
Firewall nameAutomatically generated using the resource name_Firewall_connection name
Firewall IDService’s unique resource ID
Firewall classificationFirewall pre-service type (Internet Gateway, Direct Connect, Load Balancer)
SizeThe Firewall size selected by the user
  • Edit click the icon to change the settings
Firewall rule count/quotaThe rule quota and the number of rules currently in use for the firewall
VPC nameVPC name connected to the firewall
  • Click the VPC name to go to the detail page
VPC IDVPC ID connected to the Firewall
Connection nameAutomatically generated as {Firewall 선행 서비스명_Firewall}
  • Click the connection name to navigate to the detail page
Log saving statusFirewall log storage option
  • Enabled: Store logs
  • Disabled: Do not store logs
  • Edit icon can be clicked to change the setting
Table. Firewall detailed information

Rule

Firewall List page lets you view the rule list of the selected resource and add, modify, or delete rules.

CategoryDetailed description
Rule synchronization statusAvailability Zone Firewall rule synchronization status
  • In Sync: When the firewall rule synchronization status of all Availability Zones is normal
  • Syncing: Firewall rule synchronization in progress for the Availability Zone
  • Out of Sync: When the firewall rule synchronization of some Availability Zones fails or is inconsistent
  • Previous synchronization history: View detailed synchronization history of firewall rules
  • Excel downloadDownload the currently entered rule list as an Excel (*.xlsx) file
    Detailed SearchSearch for rules that match user-defined conditions
    • Support partial string match (LIKE) search
    Rule modificationEdit and delete rules displayed in the rule list
    • Click the button to go to the rule edit page
    Add ruleAdd new Firewall rule possible
    • Click the button to go to the rule addition page
    orderDisplay rule order, and apply top-down according to the rule order.
    Rule IDUnique ID value for the rule
    • Clicking the rule ID opens a popup with detailed rule information
    Origin addressThe origin address added to the rule
    Destination addressDestination address added to the rule, displayed as the IP address according to the entered rule
    serviceProtocol and destination port
    OperationTraffic Allow/Deny classification based on rules
    • Allow: Traffic is allowed when it matches the rule
    • Deny: Traffic is blocked when it matches the rule
    DirectionFirewall traffic direction criteria
    • Inbound: external → internal
    • Outbound: internal → external
    Activation statusIndicates whether the rule is active; if it is inactive, the rule does not operate.
    Table. Detailed information of firewall rule list

    tag

    On the Firewall List page, you can view the tag information of the selected resource, and you can add, modify, or delete it.

    CategoryDetailed description
    Tag listTag list
    • You can view the Key, Value information of the tag
    • Up to 50 tags can be added per resource
    • When entering a tag, you can search and select from the list of previously created Keys and Values
    Table. Firewall tag tab items

    On the Firewall list page, you can view the operation history of the selected resource.

    CategoryDetailed description
    Task History ListResource Change History
    • Operation date and time, resource name, operation details, operation result, operator information verification
    • Click the button to perform detailed search
    Table. Detailed information items for the Firewall operation history tab

    Firewall rule management

    You can add, modify, or delete firewall rules.

    Caution
    • You can add or modify rules only when the firewall status is Active and the rule synchronization status is In Sync.
    • If you lack permission to view the status in the preceding service, you cannot add a rule.
    참고
    • The firewall periodically caches user‑registered Domain rules and stores the IP information for a set period.
    • If the cached result of the registered domain rule does not match the user’s IP, communication may be restricted.

    Create rule

    In the Rules tab, you can directly enter and add Firewall rule information.

    Follow these steps to add a firewall rule.

    1. Click the All Services > Networking > Firewall menu. 1. Go to the Service Home page of the Firewall.
    2. On the Service Home page, click Firewall List. 2. Navigate to the Firewall List page.
    3. On the Firewall List page, click the resource to add a rule. 3. Go to the Firewall Details page.
    4. On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
    5. Click the Add Rule button on the Rules tab. 5. Navigate to the Add Rule page.
    6. Enter the required information on the Direct Input tab page.
    7. After reviewing the added rules, click the Complete button.
    Caution
    If you navigate to another page without clicking the Confirm button after entering content on the Add Rule page, the entered items will be reset, so be careful.
    CategoryRequired statusDetailed description
    Rule locationRequiredSpecify the location of the rule to be created
    Rule ID to copySelectionEnter the Firewall rule ID to copy and click the Search button to select
    Origin addressRequiredSource addresses to add to the rule
    • CIDR(IP/Subnet Mask) format, using commas (,), ranges (-) to input multiple addresses, up to a maximum of 128 at once
    Destination addressRequiredSelect the type of destination address to add to the rule
    • IP selection: You can input multiple addresses at once, up to a maximum of 128, using CIDR (IP/Subnet Mask) format with commas (,) and ranges (-)
    • Domain selection: You can input up to 128 full domain names in FQDN format at once using commas (,)
    • The type items vary depending on the selected destination address format
    typeRequiredSelect protocol type to apply the rule
    • Destination Port/Type selection: Select protocol type
    • Internet Protocol: Enter protocol number, up to 128 entries allowed
    • All: Destination port/Type and protocol are selected for the entire range, meaning all ports for all protocols
    type > protocolRequiredSelect detailed protocol for the type
    • Choose the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol
    • When ICMP is selected in the protocol, ICMP Type can be set
      • Select a commonly used Type, such as Echo, from the values defined for ICMP Type
      • Click the Add button to add an input value
    • When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, TELNET
      • When entering manually, you can input values from 1 to 65,535, and you can enter up to 128 entries at once using commas (,) or ranges (-)
      • Click the Add button to add an input value
    • If Internet Protocol is selected in the typeEnter a protocol number within 1 to 254
    OperationRequiredTraffic allow/block classification by rule
    • Allow: Allow traffic when it matches the rule
    • Deny: Block traffic when it matches the rule
    DirectionRequiredFirewall traffic direction criteria
    • Inbound: external → internal
    • Outbound: internal → external
    ExplanationSelectionAdditional description written by the user
    Added rules-Check list of entered rules
    • Move Up: Move the selected rule up
    • Move Down: Move the selected rule down
    • Delete: Delete the selected rule
    Table. Add Firewall Rule > Direct Input tab item

    Create rules in bulk

    To add multiple Firewall rules at once, follow these steps.

    1. All Services > Networking > Firewall Click the menu. 1. Navigate to the Firewall’s Service Home page.
    2. On the Service Home page, click Firewall List. 2. Go to the Firewall List page.
    3. On the Firewall List page, click the resource to add a rule. 3. Go to the Firewall Details page.
    4. On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
    5. Click the Rule tab’s Add Rule button. 5. Add Rule go to the page.
    6. On the Add Rule page, click the Bulk Rule Input tab.
    7. Select Rule location. 7. If no location is selected, it is added after the last rule.
    8. From Select File, click the Download Form button. 8. The rule batch input Excel file will be downloaded.
    9. Enter the rule information into the batch rule input Excel file, then save it.
    10. From File Selection, click Attach File to attach the Excel file you created, and click Add.
      • You cannot upload the file if the attached Excel file format differs from the registration form or if the file is encrypted.
      • You can upload up to 100 batch registration rules at a time. * Upload is not possible when the maximum number of registered rules is exceeded.
      • If the configured maximum number of rules for the firewall size is exceeded, the file cannot be uploaded.
    11. Added rule Check that the rule you entered appears in the list and adjust its order.
    12. After reviewing the added rules, click the Complete button.

    Modify rules

    You can select a firewall rule to view and edit its information.

    To modify firewall rules, follow the steps below.

    1. All Services > Networking > Firewall Click the menu. 1. Go to the Service Home page of the Firewall.

    2. On the Service Home page, click Firewall List. 2. Go to the Firewall list page.

    3. On the Firewall List page, click the resource to edit the rule. 3. Go to the Firewall Details page.

    4. On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.

    5. In the Rule tab, click the Edit Rule button. 5. Edit Rule Go to the page.

      • On the rule edit page, you can configure the items below.
        • Enable: Activates the selected rule.
        • Disable: Disables the selected rule. * Disabled rules are not applied to preceding services.
        • Delete: Deletes the selected rule. * When you click Delete, the changes will be shown with a Scheduled for Deletion status.
        • Cancel Deletion: If the rule is in a pending deletion state, you can cancel the rule deletion.
    6. Rule Edit page, click the Edit button for the item you want to modify. 6. Edit Rule The popup window opens.

    7. Edit Rule Enter the item you want to edit in the popup window and click the Confirm button.

      CategoryRequired statusDetailed description
      order-Order of rules
      • The order can be changed by clicking Move Up/Move Down in the added rules list
      Rule ID-Cannot be changed to a unique ID value for the rule
      Origin addressRequiredSource addresses registered in the rule
      • CIDR (IP/Subnet Mask) format, using commas (,) and ranges (-), can be entered up to 128 addresses at once for modification
      Destination addressRequiredDestination addresses to add to the rule
      • can be entered and modified at once using CIDR (IP/Subnet Mask) format, commas (,), and ranges (-) for up to 128 addresses
      typeRequiredSet the protocol type based on the selected destination address entry
      OperationRequiredChange the Allow/Deny traffic classification due to rules
      • Allow: Allow traffic when it matches the rule
      • Deny: Block traffic when it matches the rule
      DirectionRequiredAbility to change the direction of traffic for Firewall criteria registered in the rule
      • Inbound: external → internal
      • Outbound: internal → external
      Activation statusRequiredWhether the rule is active; if it is inactive, the rule does not function.
      Rule locationRequiredRule location setting
      ExplanationSelectionAdditional description written by the user
      Table. Detailed items for modifying firewall rules

    8. After confirming the revised rules, click the Complete button.

    Delete rule

    Caution
    The firewall can be deleted only when it is Active and the rule is in Active or Error state.

    To delete a firewall rule, follow these steps.

    1. All Services > Networking > Firewall menu, click it. 1. Navigate to the Firewall’s Service Home page.
    2. On the Service Home page, click Firewall List. 2. Go to the Firewall List page.
    3. On the Firewall List page, click the resource to edit the rule. 3. Go to the Firewall Details page.
    4. On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
    5. On the Rule tab, click the Edit Rule button. 5. Go to the Edit Rule page.
    6. On the Rule Edit page, select the rule to delete and click the Delete button.
      • Once the deletion request is completed, the item in the change log will be marked as Scheduled for Deletion.
      • Click Cancel Deletion to cancel the rule deletion.
    7. On the Edit Rule page, click the Complete button.

    Check rule synchronization history

    In the Rules tab, you can check the synchronization status of firewall rules and view detailed information.

    To view the synchronization history of firewall rules, follow these steps.

    1. All Services > Networking > Firewall Click the menu. 1. Navigate to the Firewall’s Service Home page.
    2. Click Firewall List on the Service Home page. 2. Go to the Firewall list page.
    3. On the Firewall List page, click the resource to add a rule. 3. Navigate to the Firewall Details page.
    4. On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
    5. In the Rules tab, click the Previous Sync History button. 5. Previous sync history popup window opens.
    6. Previous sync history In the popup, view the sync history and click the Confirm button.
      • Resynchronization: If one or more rule states are Partial Fail/Pending, re-run the synchronization.
      • Resynchronization cannot be performed when one or more items are in a Fail state.
      • Delete Fail request: If one or more rule statuses are Fail, you can delete the corresponding entries.
      • Status information: You can check the synchronization status of firewall rules.
        • Success: Rule synchronization succeeded on all devices
        • Partial Fail: Failed after attempting synchronization on one or more devices
        • Pending: Synchronization stopped after Partial Fail for all devices
        • Fail: All devices failed after attempting synchronization simultaneously

    Managing Firewall Resources

    You can modify the size of the firewall and change the log usage settings.

    Modify firewall size

    To modify the Firewall size, follow these steps.

    1. Click the All Services > Networking > Firewall menu. 1. Navigate to the Service Home page of the Firewall.
    2. On the Service Home page, click Firewall List. 2. Go to the Firewall list page.
    3. Firewall List page, click the resource you want to edit. 3. Go to the Firewall Details page.
    4. On the Firewall Details page, click the size edit icon. 4. Go to the Resize popup.
    5. Resize In the popup window, select the size to modify, then click the Confirm button.
    Reference

    The firewall size is provided as the default Extra Small (rule quota 5), and you can change the firewall size to add firewall rules for use. For more details, see Firewall 제약 사항.

    • Firewall fees are charged based on the size of the Firewall service and traffic throughput.

    Using Log Storage

    Reference

    To store firewall logs, first create a bucket in Object Storage for the logs, and then configure that bucket in the log repository of Firewall Logging. Then, when you enable log storage in the Firewall details view, the Firewall logs are saved to an Object Storage bucket.

    • The log storage settings can be checked in Firewall Logging. * For detailed information, see Firewall Logging.
    • If you configure a log repository, Object Storage charges for log storage will be billed.

    To use Firewall log storage, follow these steps.

    1. All Services > Networking > Firewall menu, click it. 1. Navigate to the Service Home page.
    2. On the Service Home page, click the Firewall menu. 2. Go to the Firewall list page.
    3. On the Firewall List page, click the resource (Firewall) to enable log storage. 3. Go to the Firewall Details page.
    4. On the Firewall Details page, click the Edit icon for Log Save Setting. 4. Modify log save setting Navigate to the popup window.
    5. Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
    주의
    If the log storage is not configured in Firewall Logging, you cannot set the log storage use.

    Disable Log Saving

    To set Firewall log storage to disabled, follow these steps.

    1. Click the All Services > Networking > Firewall menu. 1. Navigate to the Service Home page.
    2. On the Service Home page, click the Firewall menu. 2. Go to the Firewall List page.
    3. Firewall List page, click the resource (Firewall) for which you want to disable log storage. 3. Go to the Firewall Details page.
    4. Modify Log Save Setting Click the button. 4. Modify log save setting Navigate to the popup window.
    5. Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
    6. Notification Check the message in the popup window and click the Confirm button.
    Caution
    If log storage is disabled, the service’s log retention will be halted, and tracking through log analysis will be impossible in the event of a security incident.

    Disable firewall

    The Firewall service cannot be deleted on its own. Deleting the preceding service will also delete the associated Firewall. When the preceding service is retained but the firewall is not used, you can set the firewall to an unused state on the firewall list page.

    Caution
    • If you change the firewall to an unused state, all previously registered rules will be deleted.
    • You cannot delete the preceding service if there are associated firewall rules. * Delete the firewall rules before deleting the preceding service.

    To disable the firewall, follow these steps.

    1. Click the All Services > Networking > Firewall menu. 1. Go to the Service Home page.
    2. On the Service Home page, click the Firewall menu. 2. Go to the Firewall list page.
    3. On the Firewall list page, click More > Unused for the resource you want to set as unused.
    4. After the usage status change is completed, check on the Firewall List page whether the resource’s usage status has been changed to unused.
    Overview
    Firewall Logging