Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 29 Next »

To fully use this screen, you must have the following permissions assigned to your account:

  • Read Virtual Data Centers
  • Read Firewall
  • Write Firewall


In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several IP addresses or just a single IP address.

You can combine related IP addresses into a single IP Group. For example, if you want to block traffic from three separate IP address, you do not have to create three separate firewall rules. Instead, you can combine the three separate IP addresses into a single, configurable IP Group. Then, when you create a firewall rule, you can pick the newly created IP Group as your Source or Destination IP addresses.


Create an IP Group


  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click IP Groups.
  5. Click Actions, and then click New Group.
  6. In IP Group Name, enter a descriptive name.
    • Armor recommends that you add Source or Destination into the name of the IP Group to help you identify the IP Group as the Source or Destination IP group.
  7. In Add Members To Group, enter a member, and then click the plus icon.
    • You can enter:
      • A single IP address
      • A range of IP addresses
      • CIDR
    • You must add at least one member.
    • You can add multiple members to a service group.
  8. Click Apply.
    • The newly created IP group will appear at the bottom of the table.


Edit an IP Group


Error rendering macro 'excerpt-include' : No link could be created for 'ESLP:Delete or edit a rule or group (snippet)'.

  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. In the Source or Destination column, hover over the desired IP group, then click Edit IP Group. Or, click the IP Groups tab.
  5. Hover over the desired IP group, then click the vertical ellipses.
  6. Make your changes, and then click Apply to save.


Delete an IP Group


Error rendering macro 'excerpt-include' : No link could be created for 'ESLP:Delete or edit a rule or group (snippet)'.

  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click IP Groups.
  5. Locate and place your cursor over the desired IP group.
  6. Click the trash icon.
  7. Click Delete IP Group.




Was this helpful?

Topics Discussed

  • No labels