Service Groups

 

To fully use this screen, you must have the following permissions assigned to your account:

  • Read Virtual Data Centers

  • Read Firewall

  • Write Firewall



In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several protocols (and ports).

You can combine related protocols (and ports) into a Service Group. For example, if you want to create a firewall rule to block three types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three types of traffic (protocols and ports) into a single, configurable Service Group. Then, when you create a firewall rule, you can pick the newly created Service Group.


Create a Service Group


In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several protocols (and ports).

You can combine related protocols (and ports)into a Service Group. For example, if you want to create a firewall rule to block three types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three types of traffic (protocols and ports) into a single, configurable Service Group. Then, when you create a firewall rule, you can pick the newly created Service Group.

  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click Service Groups.

  5. Click Actions, and then click New Group.

  6. In Service Group Name, enter a descriptive name.

  7. In Add Members To Group, enter the service or sub-protocol, and then click the plus ( + ) icon.

    • You must add at least one member.

    • You can add multiple members to a service group.



  8. Click Create Group.

    • The newly created service group will appear at the bottom of the table.

For a complete list of supported services and sub-protocol, see Review supported services and sub-protocols.


Edit a Service Group


  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click Service Groups.

  5. Locate and place your cursor over the desired service group.

  6. Click Edit Service Group.

  7. Make your changes, and then click Update Group to save.


Delete a Service Group


  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click Service Groups.

  5. Locate the desired service group and click on the vertical ellipsis.

  6. Click on Delete.



Topics Discussed