Inter-VPC firewall rules provide multiple Access Control Lists (ACLs), each associated with a pair of connected Virtual Private Clouds (VPCs) and an inter-VPC firewall toggle.
This topic describes how to set up Inter-VPC firewall rules on the Converge Cloud Firewall Console.
Operation Guide
- Log in to the Converge Cloud Firewall Console.
- Select Access Control in the left navigation pane, and then select Inter-VPC Firewall Rules.
- In the upper-left corner of the Inter-VPC Firewall Rules page, you can switch between different inter-VPC ACLs from the drop-down list of Firewall Toggle Name.
Unlike Edge Firewall and NAT Firewall ACLs, Inter-VPC ACLs have no direction limitations. The local and peer VPCs are equivalent. When configuring rules, you can determine the VPC based on the CIDR block of the access source and destination to differentiate the traffic direction.
Adding Rules
- On the Inter-VPC Firewall Rules page, click Add Rule.
- On the Add Rule page, details such as local and peer VPCs and firewall toggle information are pre-filled.
- Enter the following details:
- Access Source IP
- Access Destination IP
- Destination Port
- Protocol and Policy
- Description
Field Descriptions
| Field | Description |
|---|---|
| Priority | Defines rule execution order. Rules with higher priority are processed first. Modifying or deleting priorities adjusts subsequent rules automatically. |
| Access Source | Must be an IP or subnet in the local or peer VPC’s CIDR block. Cannot overlap with the access destination’s range. Supports 0.0.0.0/0 as a wildcard. |
| Access Destination | Must be an IP or subnet in the local or peer VPC’s CIDR block. Cannot overlap with the access source’s range. Supports 0.0.0.0/0 as a wildcard. |
| Destination Port | Supports single ports (e.g., 80), ranges (e.g., 80/443), or multiple ports (e.g., 80,443,3389). |
| Protocol | Supported protocols: TCP, UDP, and ICMP. |
| Policy | Allow: Permits traffic and records hits and traffic logs. Observe: Permits traffic and records all logs. Block: Denies traffic but records access control logs. |
| Description | Rule description (up to 50 characters). Supports special markers such as #long connection#. |
Wildcard Rules
Refer to Edge Firewall Rules for more information about supported wildcard configurations for IP address ranges.
The CIDR blocks of the local and peer VPCs cannot be the same or overlap. Otherwise, the firewall cannot be enabled.
Access source and destination must belong to the CIDR blocks of the local or peer VPC. If both are set to 0.0.0.0/0, it indicates all VPC addresses.
Rules entered with IPs outside these ranges will not take effect.
Adding Rules in Bulk
Each rule uses one line. New rules are added to the end of the list by default and have the lowest priority.
Scenario 1: Adding Multiple Rules at Once
- Click Copy in the action column to duplicate an existing rule.
- A maximum of 10 rules can be added at a time.
- Complete all necessary fields.
- Verify priority order.
- Click OK to submit.
Scenario 2: Multiple Rules for the Same IP
- Edit a rule with common field values.
- Click Copy to duplicate (up to 10 rules).
- Adjust specific fields and confirm priorities.
- Click OK to submit.
After adding rules, you can view and manage them in the Rule List.
Importing, Backing Up, and Restoring Rules
- Import Rules: Click Import Rule to upload rules from a local file. You can specify an import location, download a template, or export existing rules.
- Backup Rules: Click Backup Rules (top-right) to save current Inter-VPC Firewall configurations.
- Restore Rules: Click Roll Back beside a backup file to restore previous configurations.
To create a backup:
- Go to Backup and Rollback Rules.
- Click Create Backup.
- Select Inter-VPC Firewall Rule Group, add a description, and click OK.
More Information
For additional guidance:
- Edge Firewall Rules: Managing inbound and outbound edge traffic.
- NAT Firewall Rules: Managing NAT-based traffic control.
- Special Scenarios: Handling advanced or unique network configurations.
- Inter-VPC Firewall Overview: Understanding cross-VPC access management.
Converge Cloud — Secure and Scalable Network Control for the Philippines