Users can create the service by entering the required information for the Firewall service and selecting detailed options through the Samsung Cloud Platform Console.
Create Firewall
You can create and use the Firewall service from the Samsung Cloud Platform Console.
The Firewall service is created only after it is enabled in the prerequisite Networking service. The enabled Firewall can be viewed in the Firewall list.
- A firewall cannot be created independently, unlike other services in the Samsung Cloud Platform Console.
To configure the firewall, follow the steps below.
All Services > Networking > Firewall click the menu. 1. Navigate to the Service Home page of the Firewall.
On the Service Home page, click the prerequisite service to create. 2. Navigate to the service creation page.
- VPC Creation: Enable the Internet Gateway and the Transit Gateway Firewall of the VPC service.
- When creating a VPC Internet Gateway service, set the Firewall Use item to Use. * For detailed information, please refer to Internet Gateway 생성하기.
- Create the Transit Gateway service for the VPC and request the Uplink Firewall integration service. * For detailed instructions, please refer to Transit Gateway 생성하기.
- Direct Connet creation: When creating a Direct Connet service, set the Firewall usage item to Enable. * For detailed instructions, please refer to Direct Connect 생성하기.
- Load Balancer creation: When creating a Load Balancer service, set the Firewall usage option to Enabled. * For detailed instructions, see Load Balancer 생성하기.
- VPC Creation: Enable the Internet Gateway and the Transit Gateway Firewall of the VPC service.
After the prerequisite service creation is complete, verify that the corresponding Firewall resource appears in the Firewall list.
Check firewall detailed information
The Firewall service can view and edit the full resource list and detailed information in the resource management menu.
To view detailed information about the firewall, follow these steps.
- All Services > Networking > Firewall Click the menu. 1. Go to the Service Home page of the Firewall.
- On the Service Home page, click Firewall List. 2. Navigate to the Firewall list page.
- On the Firewall List page, you can view the information below.
Category Detailed description Firewall name Firewall pre-service type_Firewall automatically generated in the format Firewall classification Firewall pre-service type (Internet Gateway, Direct Connect, Load Balancer) Size User-selected Firewall size VPC name VPC name connected to the firewall Connection name Automatically generate in the format preceding service name_Firewall using Firewall Number of rules Number of rules used on this firewall Usage Whether the Firewall is used (enabled), not used (disabled) - If not used, the Any Allow rule is applied and no charges are incurred for the Firewall
Status Firewall status display - click the More button to set Enabled/Disabled
Table. Firewall resource list items
- On the Firewall List page, you can view the information below.
- On the Firewall List page, click the resource to view detailed information. 3. Go to the Firewall Details page.
- Firewall Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Action History tabs.
Category Detailed description Service status Firewall 상태 표시 - Creating: Creating
- Active: Running/All firewalls operating normally
- Editing: Editing
- Deploying: Deployment completed
- Deleting: Deleting
- Error: Error occurred/Errors occurred on one or more firewalls
Table. Firewall status information
- Firewall Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Action History tabs.
Detailed Information
Firewall list page lets you view detailed information of the selected resource and edit the information if needed.
| Category | Detailed description |
|---|---|
| Service | Service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Service’s unique resource ID |
| Constructor | User who created the service |
| Creation date and time | Service creation date and time |
| Modifier | User who edited the service information |
| Modification date and time | Date and time the service information was modified |
| Firewall name | Automatically generated using the resource name_Firewall_connection name |
| Firewall ID | Service’s unique resource ID |
| Firewall classification | Firewall pre-service type (Internet Gateway, Direct Connect, Load Balancer) |
| Size | The Firewall size selected by the user
|
| Firewall rule count/quota | The rule quota and the number of rules currently in use for the firewall |
| VPC name | VPC name connected to the firewall
|
| VPC ID | VPC ID connected to the Firewall |
| Connection name | Automatically generated as {Firewall 선행 서비스명_Firewall}
|
| Log saving status | Firewall log storage option
|
Rule
Firewall List page lets you view the rule list of the selected resource and add, modify, or delete rules.
| Category | Detailed description |
|---|---|
| Rule synchronization status | Availability Zone Firewall rule synchronization status
|
| Excel download | Download the currently entered rule list as an Excel (*.xlsx) file |
| Detailed Search | Search for rules that match user-defined conditions
|
| Rule modification | Edit and delete rules displayed in the rule list
|
| Add rule | Add new Firewall rule possible
|
| order | Display rule order, and apply top-down according to the rule order. |
| Rule ID | Unique ID value for the rule
|
| Origin address | The origin address added to the rule |
| Destination address | Destination address added to the rule, displayed as the IP address according to the entered rule |
| service | Protocol and destination port |
| Operation | Traffic Allow/Deny classification based on rules
|
| Direction | Firewall traffic direction criteria
|
| Activation status | Indicates whether the rule is active; if it is inactive, the rule does not operate. |
tag
On the Firewall List page, you can view the tag information of the selected resource, and you can add, modify, or delete it.
| Category | Detailed description |
|---|---|
| Tag list | Tag list
|
On the Firewall list page, you can view the operation history of the selected resource.
| Category | Detailed description |
|---|---|
| Task History List | Resource Change History
|
Firewall rule management
You can add, modify, or delete firewall rules.
- You can add or modify rules only when the firewall status is Active and the rule synchronization status is In Sync.
- If you lack permission to view the status in the preceding service, you cannot add a rule.
- The firewall periodically caches user‑registered Domain rules and stores the IP information for a set period.
- If the cached result of the registered domain rule does not match the user’s IP, communication may be restricted.
Create rule
In the Rules tab, you can directly enter and add Firewall rule information.
Follow these steps to add a firewall rule.
- Click the All Services > Networking > Firewall menu. 1. Go to the Service Home page of the Firewall.
- On the Service Home page, click Firewall List. 2. Navigate to the Firewall List page.
- On the Firewall List page, click the resource to add a rule. 3. Go to the Firewall Details page.
- On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
- Click the Add Rule button on the Rules tab. 5. Navigate to the Add Rule page.
- Enter the required information on the Direct Input tab page.
- After reviewing the added rules, click the Complete button.
| Category | Required status | Detailed description |
|---|---|---|
| Rule location | Required | Specify the location of the rule to be created |
| Rule ID to copy | Selection | Enter the Firewall rule ID to copy and click the Search button to select |
| Origin address | Required | Source addresses to add to the rule
|
| Destination address | Required | Select the type of destination address to add to the rule
|
| type | Required | Select protocol type to apply the rule
|
| type > protocol | Required | Select detailed protocol for the type
|
| Operation | Required | Traffic allow/block classification by rule
|
| Direction | Required | Firewall traffic direction criteria
|
| Explanation | Selection | Additional description written by the user |
| Added rules | - | Check list of entered rules
|
Create rules in bulk
To add multiple Firewall rules at once, follow these steps.
- All Services > Networking > Firewall Click the menu. 1. Navigate to the Firewall’s Service Home page.
- On the Service Home page, click Firewall List. 2. Go to the Firewall List page.
- On the Firewall List page, click the resource to add a rule. 3. Go to the Firewall Details page.
- On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
- Click the Rule tab’s Add Rule button. 5. Add Rule go to the page.
- On the Add Rule page, click the Bulk Rule Input tab.
- Select Rule location. 7. If no location is selected, it is added after the last rule.
- From Select File, click the Download Form button. 8. The rule batch input Excel file will be downloaded.
- Enter the rule information into the batch rule input Excel file, then save it.
- From File Selection, click Attach File to attach the Excel file you created, and click Add.
- You cannot upload the file if the attached Excel file format differs from the registration form or if the file is encrypted.
- You can upload up to 100 batch registration rules at a time. * Upload is not possible when the maximum number of registered rules is exceeded.
- If the configured maximum number of rules for the firewall size is exceeded, the file cannot be uploaded.
- Added rule Check that the rule you entered appears in the list and adjust its order.
- After reviewing the added rules, click the Complete button.
Modify rules
You can select a firewall rule to view and edit its information.
To modify firewall rules, follow the steps below.
All Services > Networking > Firewall Click the menu. 1. Go to the Service Home page of the Firewall.
On the Service Home page, click Firewall List. 2. Go to the Firewall list page.
On the Firewall List page, click the resource to edit the rule. 3. Go to the Firewall Details page.
On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
In the Rule tab, click the Edit Rule button. 5. Edit Rule Go to the page.
- On the rule edit page, you can configure the items below.
- Enable: Activates the selected rule.
- Disable: Disables the selected rule. * Disabled rules are not applied to preceding services.
- Delete: Deletes the selected rule. * When you click Delete, the changes will be shown with a Scheduled for Deletion status.
- Cancel Deletion: If the rule is in a pending deletion state, you can cancel the rule deletion.
- On the rule edit page, you can configure the items below.
Rule Edit page, click the Edit button for the item you want to modify. 6. Edit Rule The popup window opens.
Edit Rule Enter the item you want to edit in the popup window and click the Confirm button.
Category Required status Detailed description order - Order of rules - The order can be changed by clicking Move Up/Move Down in the added rules list
Rule ID - Cannot be changed to a unique ID value for the rule Origin address Required Source addresses registered in the rule - CIDR (IP/Subnet Mask) format, using commas (,) and ranges (-), can be entered up to 128 addresses at once for modification
Destination address Required Destination addresses to add to the rule - can be entered and modified at once using CIDR (IP/Subnet Mask) format, commas (,), and ranges (-) for up to 128 addresses
type Required Set the protocol type based on the selected destination address entry Operation Required Change the Allow/Deny traffic classification due to rules - Allow: Allow traffic when it matches the rule
- Deny: Block traffic when it matches the rule
Direction Required Ability to change the direction of traffic for Firewall criteria registered in the rule - Inbound: external → internal
- Outbound: internal → external
Activation status Required Whether the rule is active; if it is inactive, the rule does not function. Rule location Required Rule location setting Explanation Selection Additional description written by the user Table. Detailed items for modifying firewall rulesAfter confirming the revised rules, click the Complete button.
Delete rule
To delete a firewall rule, follow these steps.
- All Services > Networking > Firewall menu, click it. 1. Navigate to the Firewall’s Service Home page.
- On the Service Home page, click Firewall List. 2. Go to the Firewall List page.
- On the Firewall List page, click the resource to edit the rule. 3. Go to the Firewall Details page.
- On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
- On the Rule tab, click the Edit Rule button. 5. Go to the Edit Rule page.
- On the Rule Edit page, select the rule to delete and click the Delete button.
- Once the deletion request is completed, the item in the change log will be marked as Scheduled for Deletion.
- Click Cancel Deletion to cancel the rule deletion.
- On the Edit Rule page, click the Complete button.
Check rule synchronization history
In the Rules tab, you can check the synchronization status of firewall rules and view detailed information.
To view the synchronization history of firewall rules, follow these steps.
- All Services > Networking > Firewall Click the menu. 1. Navigate to the Firewall’s Service Home page.
- Click Firewall List on the Service Home page. 2. Go to the Firewall list page.
- On the Firewall List page, click the resource to add a rule. 3. Navigate to the Firewall Details page.
- On the Firewall Details page, click the Rules tab. 4. Go to the Rules tab page.
- In the Rules tab, click the Previous Sync History button. 5. Previous sync history popup window opens.
- Previous sync history In the popup, view the sync history and click the Confirm button.
- Resynchronization: If one or more rule states are Partial Fail/Pending, re-run the synchronization.
- Resynchronization cannot be performed when one or more items are in a Fail state.
- Delete Fail request: If one or more rule statuses are Fail, you can delete the corresponding entries.
- Status information: You can check the synchronization status of firewall rules.
- Success: Rule synchronization succeeded on all devices
- Partial Fail: Failed after attempting synchronization on one or more devices
- Pending: Synchronization stopped after Partial Fail for all devices
- Fail: All devices failed after attempting synchronization simultaneously
Managing Firewall Resources
You can modify the size of the firewall and change the log usage settings.
Modify firewall size
To modify the Firewall size, follow these steps.
- Click the All Services > Networking > Firewall menu. 1. Navigate to the Service Home page of the Firewall.
- On the Service Home page, click Firewall List. 2. Go to the Firewall list page.
- Firewall List page, click the resource you want to edit. 3. Go to the Firewall Details page.
- On the Firewall Details page, click the size edit icon. 4. Go to the Resize popup.
- Resize In the popup window, select the size to modify, then click the Confirm button.
The firewall size is provided as the default Extra Small (rule quota 5), and you can change the firewall size to add firewall rules for use. For more details, see Firewall 제약 사항.
- Firewall fees are charged based on the size of the Firewall service and traffic throughput.
Using Log Storage
To store firewall logs, first create a bucket in Object Storage for the logs, and then configure that bucket in the log repository of Firewall Logging. Then, when you enable log storage in the Firewall details view, the Firewall logs are saved to an Object Storage bucket.
- The log storage settings can be checked in Firewall Logging. * For detailed information, see Firewall Logging.
- If you configure a log repository, Object Storage charges for log storage will be billed.
To use Firewall log storage, follow these steps.
- All Services > Networking > Firewall menu, click it. 1. Navigate to the Service Home page.
- On the Service Home page, click the Firewall menu. 2. Go to the Firewall list page.
- On the Firewall List page, click the resource (Firewall) to enable log storage. 3. Go to the Firewall Details page.
- On the Firewall Details page, click the Edit icon for Log Save Setting. 4. Modify log save setting Navigate to the popup window.
- Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
Disable Log Saving
To set Firewall log storage to disabled, follow these steps.
- Click the All Services > Networking > Firewall menu. 1. Navigate to the Service Home page.
- On the Service Home page, click the Firewall menu. 2. Go to the Firewall List page.
- Firewall List page, click the resource (Firewall) for which you want to disable log storage. 3. Go to the Firewall Details page.
- Modify Log Save Setting Click the button. 4. Modify log save setting Navigate to the popup window.
- Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
- Notification Check the message in the popup window and click the Confirm button.
Disable firewall
The Firewall service cannot be deleted on its own. Deleting the preceding service will also delete the associated Firewall. When the preceding service is retained but the firewall is not used, you can set the firewall to an unused state on the firewall list page.
- If you change the firewall to an unused state, all previously registered rules will be deleted.
- You cannot delete the preceding service if there are associated firewall rules. * Delete the firewall rules before deleting the preceding service.
To disable the firewall, follow these steps.
- Click the All Services > Networking > Firewall menu. 1. Go to the Service Home page.
- On the Service Home page, click the Firewall menu. 2. Go to the Firewall list page.
- On the Firewall list page, click More > Unused for the resource you want to set as unused.
- After the usage status change is completed, check on the Firewall List page whether the resource’s usage status has been changed to unused.