All pages
Powered by GitBook
1 of 17

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

1. Working with Network

Overview

HI GIO uses a layered networking architecture with four categories of networks to provide a highly flexible and secure network infrastructure in a multipurpose cloud environment. The categories are external networks, organization virtual data center (VDC) networks, data center group networks, and vApp networks. Most types of networks require additional infrastructure objects, such as edge gateways and network pools.

2. VPN

Please refer to the VPN usage guide in the list below.

Guideline

IPSec parameters
IPSec VPN
IPSec Remote Access VPN Clients on Windows

Monitor Traffic Analytics

Procedure

Step 1: Log in to the HI GIO PORTAL as an Organization Administrator and Navigate to

Networking > Edge Gateway > Load Balancer > Virtual Services.

Step 2: Click on the “ >>” icon beside the virtual service you want to monitor.

HI GIO LB support Statistics Chart:

  • By the time (Past 30 minutes, 6 Hours,….)

  • Application Metrics: End-to-End Timing, Throughput, Open Connection,…

  • Total time for End-to-End RTT.

Step 1: Log in to the HI GIO PORTAL as an Organization Administrator and Navigate to

Networking > Edge Gateway > Load Balancer > Pool.

Step 2: Click on “>>” icon beside Pool that you want to monitor.

HI GIO LB support Statistics Chart:

  • By the time (Past 30 minutes, 6 Hours,….)

NETWORK

Information

This short manual guide is crafted to help HI GIO users navigate our network offerings, providing you with the knowledge and tools necessary to optimize your network infrastructure. In this guide, you will find step-by-step instructions for configuring and managing your network services, best practices for maintaining optimal performance, and tips for troubleshooting common issues.

Overview

We provide HI GIO Network & Security for all enterprises’ networks that need to address their particular protection and compliance requirements by fine-grained protections at host, network, and application levels such as Distributed Firewall, Edge Firewall, Web Application Firewall (WAF), Third Party Firewall (Checkpoint, Fortigate), Zero Trust Network Access (ZTNA).

Guideline

  • 1. Working with Network

    • Working with Organization VDC Networks

    • U

Import SSL Certificate

Overview

The private key must be in PKCS8 encoded format.

You cannot import a certificate that already exists on the portal.

To renew SSL:

  • Delete the current SSL.

  • Import a new one.

Procedure

1

Step 1: Log in to the HI GIO Portal as an Organization Administrator and Navigate to

Administration > Certificate Management > Certificates Library.

2

Step 2: Press IMPORT to Import the Certificate and Private Key for application traffic encryption.

Friendly Name: type your Certificate Name (for example, IIJVN-Cert). Click NEXT

3

Step 3: Click SELECT CERTIFICATE FILE to upload your Certificate file

4

Step 4: Select your Certificate file (DER encoded or PEM format) and import it to HI GIO Portal. Click Open

5

Step 5: Review your Certificate information. Click NEXT

6

Step 6: Click SELECT PRIVATE KEY to import Private Key

7

Step 7: Select your Private Key import to HI GIO Portal. Click Open

  • Input Private Key Passphrase if your Private Key is protected by password. Click IMPORT

  • Input Private Key Passphrase if your Private Key is protected.

Open Firewall Rule To Public Service To Internet

The default Edge gateway firewall rule on Tenant is set to Deny all. We must create firewall rules for traffic to virtual services from the internet.

Step 1: Log in to the HI GIO PORTAL as an Organization Administrator and Navigate to

Step 2: Networking > Edge Gateway > Security > IP Sets.

Press NEW to define the IP Set for VIPs.

3. Load Balancer

HI GIO CLOUD supports Layer-4 and Layer-7 Load balancer.

Configure load balancing for an application in HI GIO CLOUD. The main configuration steps need to be performed as follows:

Item
Description
  • OPEN FIREWALL RULE TO PUBIC SERVICE TO INTERNET

  • MONITOR TRAFFIC ANALYTICS IN FPT HI GIO CLOUD UI

  • How to create NAT rules on Edge Gateway
    Using Edge Gateway Firewall
    sing Distributed Firewall in a Data Center Group
    2. VPN
    IPSec parameters
    IPSec VPN
    IPSec Remote Access VPN Clients on Windows
    3. Load Balancer
    IMPORT SSL CERTIFICATE
    CREATE POOLS ON LOAD BALANCING
    CREATE VIRTUAL SERVICE (VS) ON LOAD BALANCING

    Pool member VMs that are running the same application

    Monitor Profile (required)

    Define how Load balancer health check Pool member’s application status.

    HI GIO Portal has built-in support for Monitor Profile (Ping/TCP/HTTP/HTTPS,…) default that can be used.

    Persistence Profile (optional)

    How load balancer to direct all requests originating from a single client to a single backend VM

    SSL Certificate (optional)

    If you want to do SSL termination on the Load balancer, you must register an SSL certificate on Portal.

    Virtual Service (required)

    Virtual Services (VIP) is the main object of load balancing, which is a service representing the pool server backend.

    Please refer to the Load Balancer usage guide in the list below:

    1 IMPORT SSL CERTIFICATE

    2 CREATE POOLS ON LOAD BALANCER

    3 CREATE VIRTUAL SERVICE (VS) ON LOAD BALANCER

    4 OPEN FIREWALL RULE AND PUBIC SERVICE TO INTERNET

    5 MONITOR TRAFFIC ANALYTICS IN FPT HI GIO CLOUD UI

    Service Engine Group (required)

    Instance of Load balancer (Preparing by HI GIO support)

    Overview

    Server Pool (required)

    Guideline

    Application Metrics: End-to-End Timing, Throughput, Open Connection,…

  • Total time for End-to-End RTT.

  • New Certificate and Key were imported as below.

    Please arrange the maintenance time for it.
    Name:
    type IP Set name (example VIP-Web)
  • IP Address: type IP Address or IP Range (this IP for VIP that was created before).

  • Step 1: Log in to the HI GIO PORTAL as an Organization Administrator and Navigate to

    Networking > Edge Gateway > Services > Firewall.

    Step 2: Press EDIT RULES to add NEW RULE for VIPs.

    • Name: type Rule name (example Allow_VSWeb)

    • Applications: choose your application types (example: HTTP and HTTPS)

    • Source: Any (for internet users)

    • Destination: Select IP Set configured before (example VS_192.168.2.10)

    • Action: Allow

    Step 3: Click Save to complete EDIT RULES

    Overview

    Procedure

    More detail on edge way firewall.

    Working with Organization VDC Networks

    Overview

    Organization virtual data center (VDC) networks enable vApps\VMs to communicate with each other or with external networks outside the organization.

    Depending on the connection of the organization VDC network, there are several different types of organization VDC networks:

    • An isolated (internally connected) network is one that only VMs within the VDC network can connect to.

    • A routed network (externally connected) provides access to machines and networks outside the VDC via the edge gateway.

    Procedure

    1

    Step 1: Creating an Isolated VCD Network

    • In the top navigation bar, click Networking.

    • On the Networks tab, click New to Open New Organization VDC Network window.

    • On the Scope page, select Organization Virtual Data Center

    2

    Step 2: Creating a Routed VCD Network

    • In the top navigation bar, click Networking.

    • On the Networks tab, click New to Open New Organization VDC Network window.

    3

    Step 3: View the Available Organization VDC Networks

    • In the top navigation bar, click Networking.

    • In the Networks tab, you will see a list of the available networks that you can also edit, increase the scope, or delete the Organization VDC network

    Create Virtual Service (VS) on Load Balancing

    Procedure

    Log in to the HI GIO portal as an Organization Administrator and Navigate to

    Networking > Edge Gateway > Load Balancer > Virtual Services.

    Click ADD.

    1

    Step 1: Create a Layer 4 Virtual Service

    Virtual Service can be created with the required properties:

    · Name: Virtual Service name

    · Service-Engine-Group: select SEG which assign for each Tenant

    · Load Balancer Pool: select Loadbalancer Pool (example select App-587-Pool)

    · Virtual IP: Select 01 public IP for VIP

    · Service Type: L4

    · Port: application port (example 587)

    2

    Virtual Service can be created with the required properties:

    · Name: Virtual Service name

    · Service-Engine-Group: select SEG which assigns to each Tenant

    · Load Balancer Pool:

    o If Server Pool is running port 80 non-encryption (example: select IIS-Web-Pool)

    o If the Server Pool is running port 443 encryption (example select IIS-Web-443-Pool)

    In case we’re using a distributed firewall in our environment. we should create and distribute firewall rules for virtual service and pool

    or
    Data Center Group
    which to create the network, and click
    Next
    • On the Select Network Type page, select Isolated >> Next.

    • Enter a Name and description (optional) for the network.

    • To enable dual-stack networking (enable the network to have both IPv4 & IPv6 subnet), turn on the Dual-Stack Mode toggle.

    • Enter the Classless Inter-Domain Routing (CIDR) settings for the network >>Next

    Format: network_gateway_IP_address/ subnet_prefix_length like 192.168.100.254/24

    • In Static IP Pools, enter the ranges of IP addresses that you want to use, click Add >> Next

    • Configure the DNS settings (Optional).

    You can put Primary DNS\Secondary DNS\DNS suffix >> Next

    • Review your settings and click Finish.

    On the Scope page, select Organization Virtual Data Center or Data Center Group which to create the network, and click Next

    • On the Select Network Type page, select Routed >> Next.

    • Enter a Name and Description (optional) for the network.

    • To enable dual-stack networking (enable the network to have both IPv4 & IPv6 subnet), turn on the Dual-Stack Mode toggle.

    • Enter the Classless Inter-Domain Routing (CIDR) settings for the network >>Next

    Format: network_gateway_IP_address/ subnet_prefix_length like 192.168.100.254/24

    • In Static IP Pools, enter the ranges of IP addresses that you want to use, click Add >> Next

    • Configure the DNS settings (Optional).

    You can put Primary DNS\Secondary DNS\DNS suffix >> Next

    • Review your settings and click Finish.

    Edge Gateway created by the HI GIO team

    · Virtual IP: Virtual Service IP Address (VIP)

    · Service Type: HTTPS

    · Certificate: Select your Certificate

    · Port: application port (443 SSL and 80 no-SSL)

    *Note: we add port 80 no-SSL for redirect HTTP-to-HTTPS request automatically. Usually End users prefer to type domain rather than type https://domain-name.

    Press SAVE to create the Virtual Service. When this is the first Virtual Service, this might take some time because the Service Engine Virtual Machines need to be deployed. Subsequent virtual services will be faster as they just require a route addition. After a couple of minutes, you should be able to access the Virtual Service.

    In some cases, Virtual Service has DOWN status (Health). We have to check Server Pool Status to handle this situation. Example: IIS-Web-443-VS is DOWN.

    Let’s check Pool Server. We see that IIS-Web-443-VS is mapping to IIS-Web-443-Pool.

    This Pool has only 01 Server.

    Let's continue to check the server. We see Server 10.1.20.10:443 is DOWN.

    Usually, there are 2 situations:

    • The server is Off, we need Power it On;

    • Or Disable Firewall Rule Server port 443.

    After powering on the VM. The Pool Server is UP again.

    So Virtual Service IIS-Web-443-VS is UP also and working.

    Step 2: Create a Layer 7 Virtual Service

    How to create NAT rules on Edge Gateway

    Overview

    Network address translation (NAT) allows the source or destination IP address to be changed to enable traffic to transition through a gateway or router.

    HI GIO supports some NAT types:

    A SNAT rule translates the source IP address of packets sent from an organization's VDC network out to an external network or another organization's VDC network.

    A NO SNAT rule prevents the translation of the internal IP address of packets sent from an organization VDC out to an external network or another organization VDC network.

    A DNAT rule translates the IP address and, optionally, the port of packets received by an organization VDC network that are coming from an external network or another organization VDC network.

    A NO DNAT rule prevents the translation of the external IP address of packets received by an organization VDC from an external network or another organization VDC network.

    Step 1: In the top navigation bar, click Networking and Edge Gateways.

    Step 2: Select the edge gateway that you want to edit

    Step 3: Under Security, click NAT

    Step 4: Click New.

    Step 5: Configure an DNAT

    Name

    Create Pools on Load Balancing

    Procedure

    Step 1: Log in to the HI GIO PORTAL as an Organization Administrator and Navigate to

    Networking > Edge Gateway > Load Balancer > Pool.

    Step 2: Press ADD to create and configure a load balancer pool.

    General Settings Tab:

    • Name: type Pool name (example IIS-Web-Pool)

    • Default Server Port: The destination server port used by the traffic sent to the member (example 80)

    • Load Balancer Algorithm: (example Round Robin)

    NSX ALB supports various Load-balancing methods:

    Consistent Hash

    Core Affinity

    Fastest Response

    Fewest Servers

    Least Connections

    Least Load

    Round Robin

    • Persistence: The persistence profile will ensure that the same user sticks to the same server for a desired duration of time (e.g. Client IP)

    NSX ALB supports various Persistence types:

    System-Persistence-App-Cookie

    System-Persistence-Client-IP

    System-Persistence-Custom-HTTP-Header

    System-Persistence-HTTP-Cookie

    System-Persistence-TLS

    • Active Health Monitor: (example HTTP - This will send periodic HTTP HEAD requests to each server in the Pool to check the availability)

    • Add two/or more entries in the Members tab and enter the IP Addresses and Port from the Virtual Machines running the application Servers.

    • Press SAVE to create a non-encrypted pool.

    General Settings Tab:

    • Name: type Pool name (example IIS-Web-Pool)

    • Default Server Port: The destination server port used by the traffic sent to the member (example 443)

    • HTTP/HTTPS:

      • Send Interval: 10s

      • Receive Timeout: 4s

    IPSec VPN

    IPsec VPN offers site-to-site connectivity between an HI GIO and remote sites with third-party hardware routers or VPN gateways that support IPSec.

    On HI GIO, you can create VPN tunnels between:

    • Organization virtual data center networks in the same organization

    • Organization virtual data center networks in different organizations

    IPSec parameters

    Object Name
    Customer's Device
    HI GIO
    HI GIO support
    Description

    How to Use WAF on HI GIO Portal

    This document guides how to use WAF on the HI GIO Portal to protect your virtual services from attacks and proactively prevent threats.

    1. Configure Allowlist Rules for a Virtual Service

    2. Edit the WAF Signatures for a Virtual Service

    Step 1: Log in to the HI GIO portal, select Networking

    :
    [Name of rule]

    Description: [optional]

    Interface type: Select DNAT\No DNAT

    External IP: Enter the public IP address of the edge gateway

    External Port: [optional - Enter a port into which the DNAT rule is translating]

    Internal IP: Enter IP or range IP to receive traffic from the external network

    Application: [optional – select application profile with port]

    Advanced Settings: (Optional)

    - State: Enable or disable the NAT rule.

    - Logging: Toggle the Logging button to enable logging

    - Priority: A lower value means a higher priority. The default is 0. A No SNAT or No DNAT rule should have a higher priority than other rules.

    - Firewall Match: The available settings are

    • Match External Address - The firewall will be applied to external address of a NAT rule.

    For SNAT, the external address is the translated source address after NAT is done.

    For DNAT, the external address is the original destination address before NAT is done.

    • Match Internal Address - Indicates the firewall will be applied to internal address of a NAT rule.

    For SNAT, the internal address is the original source address before NAT is done.

    For DNAT, the internal address is the translated destination address after NAT is done.

    • Bypass - The packet bypasses firewall rules

    Step 6: Click Save

    Step 1: In the top navigation bar, click Networking and Edge Gateways.

    Step 2: Select the edge gateway that you want to edit

    Step 3: Under Security, click NAT

    Step 4: Click New.

    Step 5: Configure an SNAT

    Name: [Name of rule]

    Description: [optional]

    Interface type: Select SNAT\No SNAT

    External IP: Enter the public IP address of the edge gateway

    Internal IP: Enter IP or range IP to receive traffic from the external network

    Destination IP: [Optional]

    Advanced Settings: (Optional)

    - State: Enable or disable the NAT rule.

    - Logging: Toggle the Logging button to enable logging

    - Priority: A lower value means a higher priority. The default is 0. A No SNAT or No DNAT rule should have a higher priority than other rules.

    - Firewall Match: The available settings are

    • Match External Address - The firewall will be applied to external address of a NAT rule.

    For SNAT, the external address is the translated source address after NAT is done.

    For DNAT, the external address is the original destination address before NAT is done.

    • Match Internal Address - Indicates the firewall will be applied to internal address of a NAT rule.

    For SNAT, the internal address is the original source address before NAT is done.

    For DNAT, the internal address is the translated destination address after NAT is done.

    • Bypass - The packet bypasses firewall rules

    Step 6: Click Save

    Note: Please do not remove SNAT/DNAT rules name starting with HIGIO- (if any)

    Step 7: Add Edge Firewall rules for SNAT/DNAT after completing NAT rules.

    The public IP addresses must have been added to the edge gateway interface where you want to add the NAT rule.

    Firewall rule will be applied to the local IP address by default configuration. If you want to specify a firewall rule for the Public IP address, please change the "Firewall Match" configuration to "Match External Address" on the Advanced option

    Procedure

    Load Balancer Algorithm: (example Round Robin)

    NSX ALB supports various Load-balancing methods:

    Consistent Hash

    Core Affinity

    Fastest Response

    Fewest Servers

    Least Connections

    Least Load

    Round Robin

    • Persistence: The persistence profile will ensure that the same user sticks to the same server for a desired duration of time (e.g. Client IP)

    NSX ALB supports various Persistence types:

    System-Persistence-App-Cookie

    System-Persistence-Client-IP

    System-Persistence-Custom-HTTP-Header

    System-Persistence-HTTP-Cookie

    System-Persistence-TLS

    • Active Health Monitor: (example HTTPS - This will send periodic HTTPS HEAD requests to each server in the Pool to check the availability)

    • Add two/or more entries in the Members Tab and enter the IP Addresses and Port from the Virtual Machines running the application Servers.

    In the SSL Settings Tab:

    • SSL Enable: Enable

    • Hide Service Certificates: disable

    • Select one or more certificates to be used by the Load Balancer Pool: Select your Certificate

    • Press SAVE to create an encrypted pool.

    Successful Checks: 3
  • Failed Checks: 3

  • Health Monitor Port: use the Default Server Port of the pool.

  • HTTP request: HEAD / HTTP/1.0

  • Response Code: 2xx, 3xx

  • TCP:

    • Send Interval: 10s

    • Receive Timeout: 4s

    • Successful Checks: 2

    • Failed Checks: 2

    • Health Monitor Port: use the Default Server Port of the pool.

  • UDP:

    • Send Interval: 4s

    • Receive Timeout: 2s

    • Successful Checks: 2

    • Failed Checks: 2

    • Health Monitor Port: use the Default Server Port of the pool.

  • PING:

    • Send Interval: 10s

    • Receive Timeout: 4s

    • Successful Checks: 2

    • Failed Checks: 2

  • Default Active Health Monitor:

    Active Health Monitor Flow
    Between an organization's virtual data center network and an external network

    Fulfill IPSec parameters.

    Step 1: In the top navigation bar, click Networking and click the Edge Gateways tab.

    Step 2: Click the edge gateway.

    Step 3: Under Services, click IPSec VPN.

    Step 4: To configure an IPSec VPN tunnel, click New.

    Step 5: Enter a Name and a description (optional) for the IPSec VPN tunnel.

    Step 6: To enable the tunnel upon creation, toggle on the Status option.

    Step 7: Click NEXT to select Authentication mode.

    Step 8: Select a peer authentication mode and NEXT.

    HI GIO supported 02 option for Authentication Mode:

    Step 9: On Endpoint Configuration windows, we put some parameters (follow in the prepare step):

    IP address [Local Endpoint]: Enter public IP (HI GIO’s public IP).

    Networks [Local Endpoint]: Enter at least one local (HI GIO’s network) IP subnet address for the IPSec VPN tunnel.

    IP address [Remote Endpoint]: Enter public IP (remote site, ex: Office’s public IP).

    Networks [Remote Endpoint]: Enter at least one remote IP (ex: Office’s network) subnet address for the IPSec VPN tunnel.

    Step 10: Enter the remote ID (optional) for the peer site.

    The remote ID must match the SAN (Subject Alternative Name) of the remote endpoint certificate, if available. If the remote certificate does not contain a SAN, the remote ID must match the distinguished name of the certificate that is used to secure the remote endpoint, for example, C=US, ST=Massachusetts, O=VMware, OU=VCD, CN=Edge1.

    Step 11: Click Next.

    Step 12: Review your settings and click Finish.

    The newly created IPSec VPN tunnel is listed in the IPSec VPN view. The IPSec VPN tunnel is created with a default security profile.

    Step 13: To verify that the tunnel is functioning, select it and click View Statistics.

    If the tunnel is functioning, Tunnel Status and IKE Service Status both display Up.

    Once the IPSec VPN tunnel has been created. We can change the IPSec VPN configuration by security profile, it must fit with the remote site.

    Step 1: In the top navigation bar, click Networking and click the Edge Gateways tab.

    Step 2: Click the edge gateway.

    Step 3: Under Services, click IPSec VPN.

    Step 4: Select the IPSec VPN tunnel and click Security Profile Customization.

    Step 1: Preparing IP set for firewall rule (can use dynamic\static group also).

    IP set detail:

    Step 2: Create 02 the firewall rules (Edge gateway firewall) for the IPsec tunnel:

    + HI GIO to Local (remote site)

    + And Local (remote site) to HI GIO

    Overview

    Procedure

    Enabled

    Turn on / off the tunnel

    Authentication

    Pre-Shared Key, Certificate

    How to authenticate parties when raising a tunnel

    Local Endpoint IP Address

    The public IP address from HI GIO

    Local Endpoint Network

    List of the network share in the HI GIO cloud accessible through the tunnel

    Remote Endpoint IP Address

    The public IP address of the remote router from which you are connecting

    Remote Endpoint Network

    List of remote networks accessible through the tunne

    Remote ID (Optional)

    IKE Profile (Phase 1)

    Object Name
    Customer's Device
    HI GIO
    HI GIO support
    Description

    IKE Version

    IKEv1, IKEv2

    Tunnel Configuration (Phase2)

    Object Name
    Customer's Device
    HI GIO
    HI GIO support
    Description

    Enabled perfect forward secrecy (PFS)

    DPD Configuration

    Interval

    VPN Tunnel Name

    >
    Edge Gateways
    > Select Edge Gateway name from the primary left navigation panel.

    Step 2: Select Virtual Services > Click the virtual service name on the Load Balancer menu.

    Step 3: Select the WAF tab > Allowlist Rules > NEW to create a new rule.

    Step 4: Enter the rule name > To activate the rule upon creation, turn on the Active

    toggle > Select match criteria > Select an action to apply upon a match > Add.

    Match Criteria
    Description

    Client IP Address

    1. Select Is or Is Not to indicate whether to perform an action if the client IP matches or doesn't match the value that you enter.

    2. Enter an IPv4 address, or an IPv6 address, or a range, or a CIDR notation.

    3. (Optional) To add more IP addresses, click Add IP.

    HTTP Method

    1. Select Is or Is Not to indicate whether to perform an action if the HTTP method matches or doesn't match the value that you enter.

    2. From the drop-down menu, select one or more HTTP methods.

    Path

    1. Enter a path string.

    The path doesn't need to begin with a forward slash (/).

    1. (Optional) To add more paths, click Add Path.

    Actions

    Description

    Bypass

    The WAF does not execute any further rules and the request is allowed.

    Continue

    Stops the allowlist execution and proceeds with WAF signature evaluation.

    Detection Mode

    The WAF evaluates and processes the incoming request, but does not perform a blocking action. A log entry is created when the request is flagged.

    You can edit the WAF signatures for a virtual service - you can change a signature mode from Detection to Enforcement or the reverse, or, if necessary, deactivate a signature or a signature group.

    Step 1: In the WAF tab, under the General section > click EDIT to edit the WAF configuration

    Step 2: Edit WAF general settings

    Step 3: In the WAF tab, under the Signature Groups section, you can see the signature groups included in your WAF policy. You can see if they are actively in use or not. You can also see the number of active rules in each group and the number of rules that have been overridden manually.

    Step 4: Under Signature Groups, click the expand button on the left of the signature group you want to edit.

    Step 5: To edit the signatures of a group, click Edit Signatures and select an action > SAVE.

    Overview

    Procedure

    You can use the allowlist functionality to define match conditions and associated actions for the WAF to perform when processing a request.

    Using Distributed Firewall in a Data Center Group

    Overview

    HI GIO supports a distributed firewall service for data center groups. You create a single default security policy applied to the data center group.

    It can inspect every packet and frame coming to and leaving the VM regardless of the network topology. Packet inspection is done at the VM virtual NIC (vNIC) level, which enables access-control lists (ACLs) to be applied closest to the source.

    Procedure

    To create distributed firewall rules and add them to a data center group, you need to define some things:

    Name: Name for the rule.

    Source: IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)

    Destination: IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)

    Application: Select applications with port to apply rule (1.5)

    Action: Allow\Reject\Drop

    IP Protocol: IPv4/IPv6 or both

    • Add an IP Set to the Data Center Group:

    IP sets are groups of IP addresses and networks to which the distributed firewall rules apply (as Source and Destination). Combining multiple objects into IP sets helps you reduce the total number of distributed firewall rules to be created

    Step 1: In the top navigation bar, click Networking and then click the Data Center Groups tab

    Step 2: Click the data center group name

    Step 3: Under Security, click IP Sets

    Step 4: Click New.

    Step 5: Enter a meaningful Name, a Description for IP Sets

    Step 6: Enter an IPv4 address, IPv6 address, or an address range in a CIDR format, and click Add.

    Step 7: To modify an existing IP address or range, click Modify and edit the value.

    Step 8: To confirm, click Save.

    • Create a Static Security Group:

    Static security groups are data center group networks to which distributed firewall rules apply (as Source and Destination). Grouping networks helps you reduce the total number of distributed firewall rules that need to be created.

    Step 1: In the top navigation bar, click Networking and then click the Data Center Groups tab

    Step 2: Click the data center group name

    Step 3: Under Security, click Static Groups.

    Step 4: Click New.

    Step 5: Enter a Name, a Description for the static group, and click Save.

    The static security group will appear in the list.

    Step 6: Select the newly created static security group and click Manage Members.

    Step 7: Select the data center group networks that you want to add to the static security group >> Save

    • Assign Security Tags to VM:

    Security tags you create and assign to virtual machines help you define edge gateway and distributed firewall rules.

    Step 1: In the top navigation bar, click Networking.

    Step 2: Click Security Tags.

    Step 3: Click Add Tag.

    Step 4: Enter a tag name.

    Step 5: From the list of virtual machines in the organization, select the ones to assign the newly created tag.

    Step 6: Click Save.

    • Create a Dynamic Security Group:

    You can define dynamic security groups of virtual machines based on specific criteria (VM Name or Tag Name) to which to apply distributed firewall rules.

    Step 1: In the top navigation bar, click Networking and then click the Data Center Groups tab

    Step 2: Click the data center group name

    Step 3: Under Security, click Dynamic Groups.

    Step 4: Click New.

    Step 5: Enter a Name and a Description for the dynamic security group.

    Step 6: To create a Criterion for inclusion in the group, add up to four rules that apply to a VM Name or a VM security tag.

    • VM Name: a rule that applies to VM names containing or starting with a term you specify.

    • VM tag: a rule that applies to VM tags that equal, contain, start with, or end with a term you specify.

    As figured out, I created 02 rules

    • VM Name: Start With “demo”

    • VM Tag: Equals “non-prd” (That you created in 1.3)

    Step 7: Click Save.

    • Add a Custom Application Port Profile:

    You can use preconfigured and custom application port profiles to create distributed firewall rules.

    Application port profiles include a combination of a protocol and a port or a group of ports, used for firewall services.

    Step 1: In the top navigation bar, click Networking and then click the Data Center Groups tab

    Step 2: Click the data center group name

    Step 3: Under Security, click Application Port Profiles

    Step 4: In the Custom Applications pane, click New.

    Step 5: Enter a Name and, a Description for the application port profile.

    Step 6: From the Protocol drop-down menu, select the protocol: TCP, UDP, ICMPv4, ICMPv6

    Step 7: Enter a port, or a range of ports, separated by a comma, and click Save.

    We have predefined Objects in the previous. We will create the distributed firewall rules as below:

    1. In the top navigation bar, click Networking and then click the Data Center Groups tab

    2. Click the data center group name

    3. Click the Distributed Firewall tab on the left.

    Using Edge Gateway Firewall

    An edge gateway firewall monitors North-South traffic to provide perimeter security functionality, including firewall, Network Address Translation (NAT), and site-to-site IPSec and SSL VPN functionality.

    Firewall rules to apply to an edge gateway firewall to protect the virtual machines in an organization's virtual data center from outside network traffic

    To create firewall rules and add them to an edge gateway, you need to define some things:

    Name: Name for the rule.

    Source: IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)

    Encryption

    AES 128, AES 256, AES-CGM 128, AES-CGM 192, AES-CGM 256

    Digest

    SHA1, SHA 2-256, SHA 2-384, SHA 2-152

    Package Integrity Control Hash Algorithm

    Diffie-Hellman Group

    Group 2,

    Group 5,

    Group 14, Group 15, Group 16, Group 19, Group 20, Group 21

    Encryption Public Key Size

    Association Life Time (seconds)

    Encryption

    AES 128, AES 256, AES-CGM 128, AES-CGM 192, AES-CGM 256

    Digest Algorithm

    SHA1, SHA 2-256, SHA 2-384, SHA 2-152

    Package Integrity Control Hash Algorithm

    Diffie-Hellman Group

    Group 2,

    Group 5,

    Group 14, Group 15, Group 16, Group 19, Group 20, Group 21

    Association Life Time (seconds)

    Host Header

    1. Select a criterion for the host header.

    2. Enter a value for the header.

    Settings

    WAF State

    Active/Deactive

    Mode

    • Detection: In this mode, WAF policy will evaluate the incoming request. A log entry is created when this request is flagged.

    • Enforcement: In this mode, WAF policy will evaluate and block the request based on the specified rules.

    Step 5: Change the configures of the VPN tunnel as you prepared (IPSec parameters).

    If we used Distributed firewall, we also need to create firewall rules to allow VPN’s traffic (remote site to HI GIO).

    *** Please also set the firewall rules for VPN traffic on the remote routers.

    VALIDATE: Tunnel static is UP with Traffic

    Option

    Description

    Pre-Shared Key

    Choose a pre-shared key to enter. The pre-shared key must be the same on the other end of the IPSec VPN tunnel.

    Certificate

    Select site and CA certificates to be used for authentication.

    For the Security Profile – we keep it as Default and configure it later once the VPN tunnel has been created.

    In case we use a Certificate for Authentication mode

    IPSec parameters
    More detail
    IPsec-Higio
    IPsec-Local-Subnet

    Remember that the security settings must match the remote site's security settings.

    4. Click Edit Rules.

    5. To add a firewall rule, click New on Top.

    NOTE: Each traffic session is checked against the top rule in the firewall table before moving down the subsequent rules in the table. The first rule in the table that matches the traffic parameters is enforced

    6. Configure the rule

    Name: [Name of rule]

    State: [Enable or disable rule by toggle]

    Applications: Select default profiles or custom profiles that created in 1.5

    Context: (Optional) Select context profile for the rule.

    Source: Select Any or Object created in 1.1, 1.2, 1.3, 1.4

    Destination: Select Any or Object created in 1.1, 1.2, 1.3, 1.4

    Action: Allow\Reject\Drop

    IP Protocol: IPv4/IPv6 or both

    Logging: [Enable or disable by toggle] enable to have the address translation performed by this rule logged

    7. Click Save.

    Please do not remove the rules name starting with HIGIO (if any)

    Destination: IP Sets\Dynamic Groups\Static Group (1.1, 1.2, 1.3, 1.4)

    Application: Select applications with port to apply rule (1.5)

    Action: Allow\Reject\Drop

    IP Protocol: IPv4/IPv6 or both

    • Add an IP Set:

    Step 1: IP sets are groups of IP addresses and networks to which the firewall rules apply (as Source and Destination).

    Step 2: In the top navigation bar, click Networking and click Edge Gateways.

    Step 3: Select the edge gateway that you want to edit

    Step 4: Under Security, click IP Sets

    Step 5: Click New.

    Step 6: Enter a meaningful Name, and a Description for IP Sets

    Step 7: Enter an IPv4 address, IPv6 address, or an address range in a CIDR format, and click Add.

    Step 8: To modify an existing IP address or range, click Modify and edit the value.

    Step 9: To confirm, click Save.

    • Create a Static Security Group:

    Static security groups are data center group networks to which distributed firewall rules apply (as Source and Destination). Grouping networks helps you reduce the number of distributed firewall rules that need to be created.

    Step 1: In the top navigation bar, click Networking and click Edge Gateways.

    Step 2: Select the edge gateway that you want to edit

    Step 3: Under Security, click Static Groups.

    Step 4: click New.

    Step 5: Enter a Name and a Description for the static group, and click Save.

    The static security group will appear in the list.

    Step 6: Select the newly created static security group and click Manage Members.

    Step 7: Select the data center group networks that you want to add to the static security group >> Save

    • Assign Security Tags to VM:

    Security tags you create and assign to virtual machines help you define edge gateway and distributed firewall rules.

    Step 1: In the top navigation bar, click Networking.

    Step 2: Click Security Tags.

    Step 3: Click Add Tag.

    Step 4: Enter a tag name.

    Step 5: From the list of virtual machines in the organization, select the ones to assign the newly created tag.

    Step 6: Click Save.

    • Create a Dynamic Security Group:

    You can define dynamic security groups of virtual machines based on specific criteria (VM Name or Tag Name) to which firewall rules should be applied.

    Step 1: In the top navigation bar, click Networking and Edge Gateways.

    Step 2: Select the edge gateway that you want to edit

    Step 3: Under Security, click Dynamic Groups.

    Step 4: Click New.

    Step 5: Enter a Name and a Description for the dynamic security group.

    Step 6: To create a Criterion for inclusion in the group, add up to four rules that apply to a VM Name or a VM security tag.

    • VM Name: a rule that applies to VM names containing or starting with a term you specify.

    • VM tag: a rule that applies to VM tags that equal, contain, start with, or end with a term you specify.

    As figured out, I created 02 rules

    • VM Name: Start With “demo”

    • VM Tag: Equals “non-prd” (That you created in 1.3)

    Step 7: Click Save.

    Add a Custom Application Port Profile:

    You can use preconfigured and custom application port profiles to create firewall rules.

    Application port profiles include a combination of a protocol and a port or a group of ports used for firewall services.

    Step 1: In the top navigation bar, click Networking and click Edge Gateways.

    Step 2: Select the edge gateway that you want to edit

    Step 3: Under Security, click Application Port Profiles

    Step 4: In the Custom Applications pane, click New.

    Step 5: Enter a Name and a Description for the application port profile.

    Step 6: From the Protocol drop-down menu, select the protocol: TCP, UDP, ICMPv4, ICMPv6

    Step 7: Enter a port or a range of ports, separated by a comma, and click Save.

    We have predefined Objects in the previous. We will create the edge gateway firewall rule as below:

    Step 1: In the top navigation bar, click Networking and click Edge Gateways

    Step 2: Select the edge gateway.

    Step 3: Select Firewall under Services on the left.

    Step 4: Click Edit Rules.

    Step 5: To add a firewall rule, click New on Top.

    Each traffic session is checked against the top rule in the firewall table before moving down the subsequent rules in the table. The first rule in the table that matches the traffic parameters is enforced.

    Step 6: Configure the rule

    Name: [Name of rule]

    State: [Enable or disable rule by toggle]

    Applications: Select default profiles or custom profiles that created in 1.5

    Source: Select Any or Object created in 1.1, 1.2, 1.3, 1.4

    Destination: Select Any or Object created in 1.1, 1.2, 1.3, 1.4

    Action: Allow\Reject\Drop

    IP Protocol: IPv4/IPv6 or both

    Logging: [Enable or disable by toggle] enable to have the address translation performed by this rule logged

    Step 7: Click Save.

    After creating the firewall rules, they appear in the Edge Gateway Firewall Rules list. You can move up, down, edit, or delete the rules as needed.

    Overview

    Procedure

    Please do not remove IP Sets name starting with HIGIO- (if any)

    Please do not remove the rules name starting with HIGIO- (if any)

    IPSec Remote Access VPN Clients on Windows

    Overview

    This configuration guide describes configuring IPsec IKEv2 Remote Access VPN by Windows Client on Windows OS to establish VPN connections. After that, the customer can access virtual machines and applications located on the HGIO Cloud with more security and reliability.

    Procedure

    Setup IPSec IKEv2 Remote Access VPN Setup VPN Windows Client

    1

    Step 1: Configuration VPN Profile for Windows client.

    Open PowerShell with Administrator permission.

    Copy and paste the information below into PowerShell (replace red word xxxx by your domain name).

    Add-VpnConnection -Name "HI-GIO-IKEv2-VPN" -ServerAddress " remote-xxxxx.xxxx01.vpn.higio.net " -TunnelType "Ikev2"

    Set-VpnConnectionIPsecConfiguration -ConnectionName "HI-GIO-IKEv2-VPN" -AuthenticationTransformConstants GCMAES128 -CipherTransformConstants GCMAES128 -EncryptionMethod GCMAES128 -IntegrityCheckMethod SHA256 -PfsGroup "PFS2048" -DHGroup "Group14" -PassThru -Force

    2

    Step 2: Enable VPN split tunneling in the Windows client.

    Virtual private network (VPN) split tunneling lets you route some of your application or device traffic through an encrypted VPN. In contrast, other applications or devices have direct access to the internet.

    Copy and paste the information below into PowerShell.

    Set-VPNconnection -name "HI-GIO-IKEv2-VPN" -SplitTunneling $true

    3

    Step 3: Add a route to a VPN connection.

    • Add a VPN connection route for the subnet (example: 10.16.1.0/24). If we need to add an additional subnet, perform the same way and replace it with the new subnet.

    • Copy and paste the information below into PowerShell.

    Add-VpnConnectionRoute -ConnectionName "HI-GIO-IKEv2-VPN" -DestinationPrefix "10.16.1.0/24" -PassThru
    • Step Connect VPN from Windows Client.

    • Login to the account with the provided username and password, then click OK.

    • The VPN connection was established successfully.

    • Using the ping command line, confirm that you are connected to the application located on the HGIO Cloud.