Migration Rules
Users can retrieve rules created in the V1 environment of the Samsung Cloud Platform Console and apply them to the V2 service.
Get firewall rules
You can import rules created in the V1 environment of the Samsung Cloud Platform Console and migrate them to the V2 service for use.
- When a firewall rule is transferred with the Migration feature, the Migration label is displayed before its name.
- If the firewall rule description exceeds 100 characters, part of the description will be omitted and appended.
- Rules that exceed the maximum quantity are not registered due to rule quantity limits based on the firewall size.
To retrieve the Firewall rules of V1, follow these steps.
Click the All Services > Networking > Firewall menu. 1. Navigate to the Firewall’s Service Home page.
On the Service Home page, click the Migration Rules menu. 2. Go to the Migration Rules page.
Select the rule information to retrieve from the Migration Rules page and click Done.
Category Required status Detailed description Original rule environment Required SCP v1 (Vmware) Auto-select Applicable target required Select the Firewall list within the account to apply the transferred rule Get rules Required Click the File Attachment button to upload the decrypted Firewall rule file - After decrypting and saving the rule file extracted from the original environment, upload it
List of Rules - View uploaded Firewall rule file details - Move up: Move the selected rule up in the list
- Move down: Move the selected rule down in the list
- Delete: Delete the selected rule
- Edit: Edit the selected rule information; see 이관할 Firewall 규칙 수정하기 for details
Rule location Required Set the position of the selected firewall rule - After the last rule: Move the selected rule after the last rule
- Set before the specified rule / Set after the specified rule: Enter the rule ID to move the selected rule before/after the specified rule
Table. Migration Rules detailed itemsAfter the firewall rule transfer request is completed, verify that the transfer item has been added to the firewall list.
Modify the Firewall rule to be transferred
You can edit each item when retrieving rules created in the V1 environment of the Samsung Cloud Platform Console.
To modify the Firewall rules to be imported from V1, follow these steps.
All Services > Networking > Firewall menu, click it. 1. Go to the Service Home page of the Firewall.
On the Service Home page, click the Migration Rules menu. 2. Go to the Migration Rules page.
Click Attach File in the Import Rules section to upload the firewall rule file.
Click Edit on the rule item you want to modify in the rule list.
Category Required status Detailed description Origin address Required Source addresses to add to the rule - CIDR (IP/Subnet Mask) format, using commas (,), ranges (-) to input multiple addresses, up to a maximum of 128 at once
Destination address Required Select the type of destination address to add to the rule - IP: In CIDR(IP/Subnet Mask) format, you can enter multiple addresses at once using commas(,) and range(-), up to a maximum of 128
- Domain: In FQDN format, you can enter up to 128 full domain names at once using commas(,)
- The type items vary depending on the selected destination address format
type Required Select protocol type to apply the rule - Destination Port/Type Selection: Select protocol type
- Internet Protocol: Enter protocol number, up to 128 entries allowed
- All: Destination port/Type, protocol selected for the entire range, meaning all ports for all protocols
Type > Protocol Essential Select detailed protocol for the type - Choose the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol.
- When ICMP is selected in the protocol, ICMP Type can be set.
- Select a commonly used Type, such as Echo, from the values defined for ICMP Type.
- Click the Add button to add the input value.
- When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, TELNET.
- When entering manually, you can input values from 1 to 65535, and you can enter up to 128 entries at once using commas (,) or ranges (-).
- Click the Add button to add the input value.
- If Internet Protocol is selected in the type
Enter a protocol number within 1 to 254.
Operation Required Traffic allow/deny classification based on rules - Allow: Allow traffic when it matches the rule
- Deny: Block traffic when it matches the rule
Direction Required Firewall standard traffic direction - Inbound: external → internal
- Outbound: internal → external
Activation status Required Set whether the rule is enabled - If disabled is selected, the rule does not operate
Explanation Selection Additional description written by the user Table. Detailed items of the Firewall rule edit windowWhen the rule information edit is complete, click Confirm in the edit window.
Check the modified rule information and click Done.