Firewall
Apply ordered L3/L4 rules at gateways.
Firewall evaluates traffic at a gateway after routing context exists. It does not grant a device a private service route.
Create a rule#
- Open Security → Firewall → Add Rule.
- Set direction, source, destination, protocol, port, and Allow, Deny, or Reject.
- Choose gateways or all gateways.
- Set logging and Enabled state.
- Place the rule in the intended priority order and save.
- Check gateway application status: Applied, pending or stale, no report, or upgrade required.
IP Lists centralize address entries; Rule Groups organize rules.
Use rule simulation carefully#
Test this rule compares sample traffic with the single rule being edited. A match reports that rule’s action; no match means evaluation would continue. It is advisory and does not evaluate the complete ordered ruleset, access policy, posture, tunnel health, or application reachability.
Use Policy simulation for identity-aware access and Audit for observed events.