Firewall Manager
Firewall Manager
Node: —
—
Draft: —
Deployed: —
Validate: —
Draft check: —
—
Dashboard Nodes
Reliability
High Availability Locked
Network Protection
Firewall NAT Mangle
Definitions
Sites SSH Keys Objects
Tenant Admin
Tenants Audit
Support
Tickets

Dashboard

Needs attention

Nodes that are offline, stale, erroring, or pending.
Node Status Deploy Apply Backend
No issues detected.

Integrations

System updates

Nodes with OS updates available.
Node Updates Mechanism Checked
No system updates pending.

Overview

Recent audit events

Latest portal activity.
When Action Tenant
No audit events yet.

Nodes

Tenants

SuperAdmin tenant management.
Name Tenant ID Actions

Tenant

Tenant ID
—
Nodes
—
Sites
—
Users
—
Last node seen
—
Tenant admins
—
Entitlements
Toggle entitlements for this tenant.

High Availability

VRRP-based failover (keepalived) for managed nodes.
Locked
This is a licensed module.
Plan HA groups, VIPs, and health checks in the portal, then deploy to nodes. Activate a license to unlock configuration and deployment.
Entitlement key: feature:ha
About keepalived
HA Groups
Plan VRRP instances (VIPs, priorities, peers, health checks). Apply to nodes will be added next.
Name VRID VIPs Interface Peers Preempt Advert Health Deploy Actions
No HA groups yet.
Note: First implementation will target keepalived (unicast VRRP). Firewall rules must allow VRRP (IP protocol 112) between peers.

Licensing

Tenant license status and enabled modules.

License

Modules

Module Key Status License Expires Capabilities

Firewall

Rules (node-specific)
Use New Rule to open the editor and drag objects from the right drawer into Sources, Destinations, and Services.
Sort # On Chain Match Comment Src Dst Services DPorts SPorts Proto Action Actions

            

NAT

Prerouting / Postrouting (node-specific)
Use New NAT Rule to open the editor and drag objects from the right drawer.
Sort # On Chain Match Comment Src Dst Services DPorts SPorts Proto Action Actions

            

Mangle

Prerouting / Input / Forward / Output / Postrouting
Use New Mangle Rule to open the editor and drag objects from the right drawer.
Sort # On Chain Match Comment Src Dst Services DPorts SPorts Proto Action Actions

            

Sites

Name Code Created Actions

SSH Keys

Tenant-scoped SSH public key library (used for CloudRouter bootstrap).
Name Type Fingerprint Comment Updated Used by Actions

Objects

Tenant-global objects (drag from the right drawer into rules).

Audit

Time Action Tenant Actor Target Details

Support

Tickets
ID Status Type Comments Submitted By Summary Created Updated
Ticket
Comments
0/2000
Objects
Edit Rule
Drop objects from the drawer.
Action
1:1 NAT mode
Use address
Action
Change the destination to
Or enter address:
And the service to
Or enter port(s):
Advanced
Matching condition
Traffic from
Using service
Going to
Edit
Details