The page has been translated by Gen AI.

How-to guides

Users can create the Firewall service by entering the required information and selecting detailed options through the Samsung Cloud Platform Console.

Create Firewall

You can create and use a Firewall service in the Samsung Cloud Platform Console.

guide

The Firewall service must be enabled in the prerequisite service of Networking to be created. The enabled Firewall can be viewed in the Firewall list.

  • Firewalls cannot be created independently, unlike other services in the Samsung Cloud Platform Console.

To enable the firewall, follow these steps.

  1. Click the All Services > Networking > Firewall menu. Navigate to the Firewall’s Service Home page.

  2. On the Service Home page, click the service you want to create. You will be redirected to the service creation page.

    • VPC Creation: Configure the VPC service’s Internet Gateway and Transit Gateway firewall.
      • When creating a VPC’s Internet Gateway service, set the Use Firewall option to Enabled. For detailed instructions, refer to Create Internet Gateway.
      • Create a Transit Gateway service for the VPC and apply for the associated service of the Uplink Firewall. For detailed instructions, refer to Create Transit Gateway.
    • Direct Connet Creation: When creating a Direct Connect service, set the Firewall Use option to Enabled. For detailed instructions, refer to Direct Connect 생성하기.
    • Load Balancer Creation: When creating a Load Balancer service, set the Firewall Use option to Enabled. For detailed instructions, see Load Balancer Creation.
  3. After the prerequisite service creation is complete, verify that the corresponding Firewall resource appears in the Firewall list.

Check firewall detailed information

The Firewall service can view and edit the full resource list and detailed information in the resource management menu.

To view detailed information about the firewall, follow these steps.

  1. Click the All Services > Networking > Firewall menu. Go to the Firewall’s Service Home page.
  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.
    • The Firewall List page shows the information below.
      CategoryDetailed description
      Firewall nameAutomatically generated in the Firewall pre-service type_Firewall format
      Firewall classificationFirewall pre-service type (Internet Gateway, Direct Connect, Load Balancer)
      SizeUser-selected Firewall size
      VPC nameVPC name connected to the firewall
      Connection nameAutomatically generate in the format preceding service name_Firewall for services using Firewall.
      Number of rulesNumber of rules used on this firewall
      Whether to useWhether the firewall is used (enabled) or not used (disabled)
      • If not used, the Any Allow rule is applied and no charges are incurred for the firewall
      statusFirewall status display
      • More button can be clicked to set On/Off
      Table. Firewall resource list items
  3. On the Firewall List page, click the resource to view detailed information. It navigates to the Firewall Details page.
    • Firewall Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Activity Log tabs.
      CategoryDetailed description
      Service statusFirewall status display
      • Creating: In progress
      • Active: Operational
      • Editing: In progress
      • Deploying: Completed
      • Deleting: In progress
      • Error: Occurred
      Table. Firewall status information

Detailed Information

On the Firewall List page, you can view detailed information of the selected resource and, if necessary, edit the information.

CategoryDetailed description
ServiceService name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource IDService’s unique resource ID
constructorUser who created the service
Creation date and timeService creation timestamp
EditorUser who edited the service information
Modification date and timeDate and time the service information was modified
Firewall nameAutomatically generated as the connection name for the resource name_Firewall
Firewall IDService’s unique resource ID
Firewall classificationFirewall prerequisite service types (Internet Gateway, Direct Connect, Load Balancer)
SizeThe Firewall size selected by the user
  • Edit icon can be clicked to change the settings
Firewall rule count/quotaThe firewall’s rule quota and the number of rules currently in use
VPC nameVPC name connected to the Firewall
  • Click the VPC name to go to the detail page
VPC IDVPC ID connected to the firewall
Connection name{Firewall Prerequisite Service Name_Firewall} automatically generated
  • Click the connection name to go to the detail page
Log saving optionFirewall log storage option
  • Enabled: Store logs
  • Disabled: Do not store logs
  • Edit icon can be clicked to change settings
Table. Firewall detailed information

Rule

On the Firewall List page, you can view the rule list of the selected resource and add, modify, or delete rules.

CategoryDetailed description
Excel downloadDownload the currently entered rule list as an Excel (*.xlsx) file
Advanced SearchSearch for rules that match the conditions set by the user
  • Support partial string (LIKE) matching search
Rule modificationRules displayed in the rule list can be edited and deleted
  • Click the button to go to the rule edit page
Add ruleAdd new Firewall rule
  • Click the button to navigate to the rule addition page
OrderDisplay rule order, apply top-down according to the rule order
Rule IDUnique ID value for the rule
  • Clicking the rule ID allows you to view detailed rule information in a popup window
Rule IndexUnique index value for the rule, used in log analysis
Source addressOrigin address added to the rule
Destination addressDestination address added to the rule, displayed as the IP address according to the entered rule.
ServiceProtocol and Destination Port
OperationTraffic Allow/Deny distinction due to rules
  • Allow: Allow traffic when it matches the rule
  • Deny: Block traffic when it matches the rule
directionFirewall traffic direction criteria
  • Inbound: External → Internal
  • Outbound: Internal → External
Active statusIndicates whether the rule is active; if it is inactive, the rule does not operate.
statusRule status display
Table. Firewall rule list detailed information

tag

Firewall List page lets you view the tag information of the selected resource, and add, modify, or delete it.

CategoryDetailed description
Tag listTag list
  • You can view the Key, Value information of the tag
  • Up to 50 tags can be added per resource
  • When entering a tag, you can search and select from the list of previously created Keys and Values
Table. Firewall Tag Tab Items

Job History

On the Firewall List page, you can view the operation history of the selected resource.

CategoryDetailed description
Task History ListResource Change History
  • Check operation date/time, resource name, operation details, operation result, and operator information
  • Click the button to perform detailed search
Table. Firewall operation history tab detailed information items

Firewall Rule Management

You can add, modify, or delete firewall rules.

Caution
  • You can add or modify rules only when the firewall status is Active.
  • If you do not have permission to view the status in the preceding service, you cannot add a rule.
Reference
  • The firewall periodically caches the domain rules registered by the user and retains the IP information for a certain period.
  • If the cached result of the registered domain rule does not match the user’s IP, communication may be restricted.

Create Rule

In the Rules tab, you can directly input firewall rule information to add it.

To add a firewall rule, follow the steps below.

  1. Click the All Services > Networking > Firewall menu. Navigate to the Firewall’s Service Home page.
  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.
  3. On the Firewall List page, click the resource to which you want to add a rule. You will be taken to the Firewall Details page.
  4. On the Firewall Details page, click the Rules tab. You will be taken to the Rules tab page.
  5. Click the Add Rule button on the Rules tab. You will be taken to the Add Rule page.
  6. Enter the required information on the Manual Input tab page.
  7. After checking the added rules, click the Complete button.
Caution
On the rule addition page, if you navigate to another page without clicking the Confirm button after entering content, all entered items will be reset, so please be careful.
CategoryRequired?Detailed description
Rule locationRequiredSpecify the location of the rule to create
Rule ID to copySelectionEnter the Firewall rule ID to copy and click the Search button to select.
Source addressRequiredSource addresses to add to the rule
  • in CIDR (IP/Subnet Mask) format, using commas (,), and ranges (-), can be entered up to 128 at once
Destination addressRequiredSelect the type of destination address to add to the rule
  • IP selection: You can enter multiple addresses at once, up to a maximum of 128, using CIDR (IP/Subnet Mask) format with commas (,), and ranges (-)
  • Domain selection: You can enter full domain names in FQDN format, using commas (,), up to a maximum of 128 at once
  • The type items vary depending on the selected destination address format
typeRequiredSelect protocol type to apply the rule
  • Select destination port/Type: Select protocol type
  • Internet Protocol: Enter protocol numbers, up to 128 can be entered
  • All: Select destination port/Type and protocol for the entire range, meaning all ports for all protocols
Type > ProtocolRequiredSelect detailed protocol for the type
  • Select the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol
  • When ICMP is selected in the protocol, you can set the ICMP Type
    • Select a commonly used Type such as Echo from the values defined for ICMP Type
    • Click the Add button to add an input value
  • When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, TELENT
    • When entering manually, you can input values from 1 to 65,535, and you can enter up to 128 entries at once using commas (,), or ranges (-)
    • Click the Add button to add an input value
  • When Internet Protocol is selected in the type 1 ~ 254Enter the protocol number within
OperationRequiredTraffic allow/deny classification based on rules
  • Allow: Allow traffic when it matches the rule
  • Deny: Block traffic when it matches the rule
DirectionRequiredFirewall-based traffic direction
  • Inbound: External → Internal
  • Outbound: Internal → External
ExplanationSelectionAdditional description provided by the user
Added rule-Entered rules verification list
  • Move up: Move the selected rule up
  • Move down: Move the selected rule down
  • Delete: Delete the selected rule
Table. Add firewall rule > Direct input tab item

| Destination | Required | Destination address type to add to the rule

  • Select IP or FQDN
| | Destination IP | Required | When the destination address type is set to IP, enter the destination IP address to add to the rule
  • You can input multiple addresses at once, up to a maximum of 128, using CIDR (IP/Subnet Mask) format with commas (,) and ranges (-)
| | FQDN | Required | If you select the destination address type as FQDN, enter the domain address to add to the rule
  • Domain names can be entered in bulk using Comma(,) for up to 128 addresses at once
| –>

Batch create rules

To add multiple Firewall rules at once, follow these steps.

  1. Click the All Services > Networking > Firewall menu. Navigate to the Firewall’s Service Home page.
  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.
  3. On the Firewall List page, click the resource to which you want to add a rule. You will be taken to the Firewall Details page.
  4. On the Firewall Details page, click the Rules tab. You will be taken to the Rules tab page.
  5. Click the Add Rule button on the Rule tab. You will be taken to the Add Rule page.
  6. Add Rule on the Batch Rule Input tab, click it.
  7. Please select the rule location. If you do not select a location, it will be added at the very last order of the rule.
  8. From File Selection, click the Download Form button. The bulk rule entry Excel file will be downloaded.
  9. Enter the rule information into the batch rule input Excel file, then save it.
  10. From File Selection, click Attach File to attach the Excel file you created, and click Add.
    • You cannot upload if the attached Excel file format differs from the registration form or if the file is encrypted.
    • You can upload up to 100 batch registration rules at a time. Uploads are not allowed if you exceed the maximum number of registration rules.
    • If the number of rules set for the firewall size is exceeded, you cannot upload the file.
  11. Added rule Check that the rule you entered appears in the list and adjust its order.
  12. After checking the added rules, click the Complete button.

Modify Rules

You can select a firewall rule to view and edit its information.

To modify firewall rules, follow the steps below.

  1. Click the All Services > Networking > Firewall menu. Go to the Service Home page of Firewall.

  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.

  3. Firewall List page, click the resource to edit the rule. You will be taken to the Firewall Details page.

  4. On the Firewall Details page, click the Rules tab. You will be taken to the Rules tab page.

  5. Click the Edit Rule button on the Rules tab. You will be taken to the Edit Rule page.

    • On the rule edit page, you can configure the items below.
      • Enable: Enables the selected rule.
      • Disabled: Disables the selected rule. Disabled rules are not applied to preceding services.
      • Delete: Delete the selected rule. Clicking Delete will mark the change as Pending Deletion.
      • Cancel Deletion: If it is in a pending deletion state, you can cancel the rule deletion.
  6. On the Edit Rule page, click the Edit button for the item you want to modify. The Edit Rule popup will open.

  7. Rule Edit Enter the item you want to modify in the popup window and click the Confirm button.

    CategoryRequired?Detailed description
    Order-The order of rules can be changed by clicking Move Up/Move Down in the added rule list.
    Rule ID-Cannot be changed to a unique ID value for the rule
    Rule Index-Unique index value for the rule, usable in log analysis
    Source addressRequiredSource addresses registered in the rule
    • in CIDR (IP/Subnet Mask) format, using commas (,) and ranges (-), can be entered and modified up to a maximum of 128 at once
    Destination addressRequiredDestination address to add to the rule
    • in CIDR (IP/Subnet Mask) format, using commas (,) and ranges (-) to input multiple addresses at once, up to a maximum of 128, for modification
    typeRequiredSet the protocol type according to the selected destination address entry
    OperationRequiredTraffic Allow/Deny classification can be changed by rules
    • Allow: Allow traffic when it matches the rule
    • Deny: Block traffic when it matches the rule
    directionRequiredThe access direction of traffic defined by the firewall rule can be changed
    • Inbound: external → internal
    • Outbound: internal → external
    Rule locationRequiredRule position can be changed
    Active statusRequiredWhether the rule is active; if it is disabled, the rule does not operate.
    status-State value for the rule
    descriptionSelectUser-provided additional description
    Table. Detailed items for firewall rule modification

  8. After reviewing the updated rules, click the Complete button.

Delete rule

Caution
You can delete only when the firewall is in Active state and the rule is in Active or Error state.

To delete a firewall rule, follow the steps below.

  1. Click the All Services > Networking > Firewall menu. Go to the Firewall’s Service Home page.
  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.
  3. Click the resource to edit the rule on the Firewall List page. Navigate to the Firewall Details page.
  4. On the Firewall Details page, click the Rules tab. You will be taken to the Rules tab page.
  5. In the Rule tab, click the Edit Rule button. You will be taken to the Edit Rule page.
  6. On the Edit Rule page, select the rule to delete and click the Delete button.
    • When the deletion request is completed, the change item will be marked as Scheduled for deletion.
    • Click Cancel Deletion to cancel the rule deletion.
  7. On the Edit Rule page, click the Complete button.

Managing Firewall Resources

You can modify the firewall size and change the log usage settings.

Modify Firewall Size

To modify the size of the firewall, follow these steps.

  1. Click the All Services > Networking > Firewall menu. Go to the Firewall’s Service Home page.
  2. On the Service Home page, click Firewall List. You will be taken to the Firewall List page.
  3. Click the resource to edit on the Firewall List page. Navigate to the Firewall Details page.
  4. On the Firewall Details page, click the Size Edit icon. You will be taken to the Size Edit popup.
  5. Resize In the popup window, select the size to adjust, and click the Confirm button.
Reference

The firewall size is provided as the default Extra Small (rule quota 5), and you can change the firewall size to add firewall rules for use. For more details, refer to Firewall Constraints.

  • Firewall fees are charged based on the size of the Firewall service and traffic throughput.

Using Log Storage

Reference

To store firewall logs, first create a bucket in Object Storage for the logs and configure that bucket in the log repository of Firewall Logging. Then, by setting log storage in the firewall detail view, firewall logs will be saved to the Object Storage bucket.

  • The log storage settings can be checked in Firewall Logging. For more information, see Firewall Logging.
  • If you configure a log repository, Object Storage charges for log storage will be applied.

To use firewall log storage, follow these steps.

  1. Click the All Services > Networking > Firewall menu. Go to the Service Home page.
  2. On the Service Home page, click the Firewall menu. You will be taken to the Firewall List page.
  3. Firewall List page, click the resource (Firewall) for which you want to enable log storage. You will be taken to the Firewall Details page.
  4. On the Firewall Details page, click the Edit icon of Log Save Setting. You will be taken to the Edit Log Save Setting popup.
  5. Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
Caution
If the log storage is not configured in Firewall Logging, you cannot configure the log storage use setting.

Disable log storage

To set firewall log storage to disabled, follow these steps.

  1. Click the All Services > Networking > Firewall menu. You will be taken to the Service Home page.
  2. On the Service Home page, click the Firewall menu. You will be taken to the Firewall List page.
  3. Firewall List page, click the resource (Firewall) that does not use log storage. You will be taken to the Firewall Details page.
  4. Click the Modify Log Save Setting button. You will be taken to the Modify Log Save Setting popup.
  5. Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
  6. Notification Check the message in the popup window and click the Confirm button.
Caution
If log storage is disabled, the service’s log storage will be halted, and tracking through log analysis will be impossible in the event of a security incident.

Disable Firewall

The Firewall service cannot be deleted on its own. Deleting the preceding service will also delete the associated Firewall. When you choose not to use the firewall while retaining the preceding service, you can set the firewall to an unused state on the firewall list page.

Caution
  • If you change the firewall to an unused state, all previously registered rules will be deleted.
  • You cannot delete a preceding service if there are firewall rules associated with it. Delete the firewall rules before deleting the preceding service.

To disable the firewall, follow these steps.

  1. Click the All Services > Networking > Firewall menu. You will be taken to the Service Home page.
  2. On the Service Home page, click the Firewall menu. You will be taken to the Firewall List page.
  3. On the Firewall List page, click More > Unused for the resources you want to mark as unused.
  4. After the usage change is completed, verify on the Firewall List page that the resource’s usage status has been changed to unused.
Overview
Firewall Logging