Legal Disclaimer: The resource assets in this website may include abbreviated and/or legacy terminology for HPE Aruba Networking products. See www.arubanetworks.com for current and complete HPE Aruba Networking product lines and names.
Creating a Firewall Policy for Network Services
To create a firewall Firewall is a network security system used for preventing unauthorized access to or from a private network. policy, complete the following procedure:
- To configure a Branch Gateway group or a Branch Gateway, complete either one of these steps:
-
To select a gateway group:
-
In the Classic Central app, set the filter to a group that contains at least one Branch Gateway.
The dashboard context for a group is displayed.
-
Under , click > .
A list of gateways is displayed in the List view.
-
Click .
The configuration page is displayed for the selected group.
-
-
To select a gateway:
-
In the Classic Central app, set the filter to Global or a group that contains at least one Branch Gateway.
-
Under , click > .
A list of gateways is displayed in the List view.
-
Click a gateway under .
The dashboard context for the gateway is displayed.
-
Under , click .
The gateway device configuration page is displayed.
-
- If you are in the Basic Mode, click Advanced Mode to access the advanced configuration.
- Click > .
- Click the
icon in the Policies table to create a new policy. - Select a policy type from the drop-down list. You can select ,, ,,, or .
- Enter the policy name in the field.
- Click .
The Add policy pop-up window is displayed
The following animation shows you how to create a firewall policy.
Configuring Access Rules
To configure access rule, complete the following procedure:
- From the list of policies, select the policy that you created and click the
icon in the table. - To add a rule to restrict packet flow or permit access to network or services, configure the following parameters:
|
Parameter |
Description |
|
|
Specifies the IP version that the policy applies to. Select IPv4. |
|
|
|
|
|
Destination of the traffic. |
|
|
Type of traffic, which can be one of the following:
|
|
|
The action that Branch Gateway should take on a packet that matches the specified criteria.
To set the Action type as Remark-only, you must enter a value for the DSCP Differentiated Services Code Point. DSCP is a 6-bit packet header value used for traffic classification and priority assignment. parameter or select a value from the drop-down list for 802.p priority or Queue parameters.
|
|
|
Option to re-tag the traffic with the specified DSCP tag in the IP header of the packet that matches this rule when it leaves the Branch Gateway. |
|
|
You can allow or deny access during specific time range. You can either create an time range with a single fixed start and end date and time; or a (recurring) time range that starts and ends at a specified time on a weekday, weekend, or selected day. |
|
When this parameter is enabled, the value of 802.1p priority bits are marked in the frame of a packet matching this rule when it leaves the Branch Gateway. 0 represents the lowest priority (background traffic) and 7 represents the highest priority (network control). |
|
|
|
Select the required options:
|
|
|
The queue in which a packet matching this rule should be placed. |
|
Position |
The position of the rule in the table, where 1 is first and default is last. |
The following animation shows you how to add a rule to restrict packet flow or permit access to network or services.
