When you deploy the VM-Series firewall from the Google Marketplace, you need
an SSH key pair to authenticate with the VM-Series firewall.
Create the key pair according to your key generator documentation. Don't
edit the public key file. Editing risks introducing illegal
characters.
The VM-Series firewall manages authentication differently than
GCE instances. After deployment, you first login with the
admin user. The VM-Series firewall
default username is accepted only once. After a successful login, you set an
administrator username and password for the VM-Series web
interface (see
Deploy the VM-Series Firewall from Google Cloud Platform Marketplace).
The Google Marketplace deployment interface SSH key
field displays the following placeholder:
admin:ssh-rsa your-SSH-key
You can't login to the VM-Series firewall if you don't supply
the entire public key, or your key has illegal characters when you paste the
key into the Marketplace SSH key field. When you SSH
in to the VM-Series firewall for the first time, the public
key is transferred to the firewall.
If the public key is corrupted, you must delete the deployment and start
over. Any networks and subnetworks remain, but the firewall rules must be
recreated.