Deploy the VM-Series Firewall

Learn how to deploy the VM-Series firewall on VMware NSX-T.
After completing the configuration on Panorama, perform the following procedure to launch the VM-Series firewall in your NSX-T Data Center.
When deploying the VM-Series firewall on NSX-T in high availability, both firewalls are deployed to the same Device Group and Template Stack.
To complete your VM-Series on AVS deployment, there are additional steps required to establish connectivity between Panorama and managed firewalls.
  1. Log in to NSX-T Manager.
  2. (
    VM-Series firewall on Azure VMware Solution only
    ) Create a network overlay segment for the VM-Series firewall.
    If you are deploying the VM-Series firewall on Azure VMware Solution (AVS), you must create a network overlay segment to allow your deployed firewalls to connect with Panorama. This is required to manage your firewalls from Panorama and push configuration and licenses.
    1. In NSX-T Manager, select
      Networking
      Segments
      and click
      Add Segment
      .
    2. Enter a descriptive
      Name
      for your segment.
    3. Select the tier-1 router from the drop-down under
      Connected Gateway & Type
      .
    4. Create a subnet for your overlay segment.
      1. Click
        Set Subnet
        Add Subnet
        .
      2. Enter the CIDR for the subnet. The CIDR you enter must be outside the CIDR where NSX-T Manager is located.
      3. Click
        Add
        and then click
        Add
        to save and close the subnet configuration.
    5. Select the overlay from the
      Transport Zone
      drop-down.
    6. Click
      Save
      to complete the overlay configuration.
  3. Select
    System
    Service Deployments
    Deployment
    .
  4. Select your service definition from the
    Partner Service
    drop-down.
  5. Click
    Deploy Service
    .
  6. Enter a descriptive
    Service Deployment Name
    for your VM-Series firewall.
  7. Select a tier-0 or tier-1 router under
    Attachment Points
    . NSX-T Manager attaches the VM-Series firewall to the selected router and redirects traffic passing through that router to the VM-Series firewall for inspection. You must select a router with no service insertion attached.
    • (
      VM-Series firewall on NSX-T
      ) Select a tier-0 or tier-1 router. NSX-T Manager attaches the VM-Series firewall to the selected router and redirects traffic passing through that router to the VM-Series firewall for inspection. You must select a router with no service insertion attached.
    • (
      VM-Series firewall on Azure VMware Solution only
      ) Select the same tier-1 router you selected for the overlay segment.
  8. Select a
    Compute Manager
    . The compute manager is the vCenter server managing your datacenter.
  9. Select a
    Cluster
    . You can deploy the VM-Series firewall on any cluster that does not include any Edge Transport Nodes.
  10. Select a
    Datastore
    .
  11. Configure your network settings.
    1. Click
      Edit Details
      in the
      Networks
      column.
    2. Select the
      Primary Interface Network
      .
    3. Enter the
      Primary Interface IP
      .
    4. Enter the
      Primary Gateway Address
      .
    5. Enter the
      Primary Subnet Mask
      .
    6. Click
      Save
      .
      (
      VM-Series firewall on Azure VMware Solution only
      ) When deploying the VM-Series firewall on AVS, the management IP address you enter must be in the same IP range you used when configuring your overlay segment. Additionally, the gateway must be the gateway of the overlay segment you created.
  12. NSX-T Manager prepopulates the
    Deployment Specification
    and
    Deployment Template
    based on the Partner Service you selected.
  13. Set the
    Failure Policy
    to Allow or Block. The failure policy defines how NSX-T Manager handles traffic that is directed to the VM-Series firewall if the firewall becomes unavailable.
  14. Select the
    Deployment Mode
    for your VM-Series firewall—Standalone or High Availability. If you have an edge node cluster and select High Availability, NSX-T Manager will deploy an additional VM-Series firewall on the standby edge node in addition to the firewall deployed on the active edge node.
  15. Click
    Save
    to deploy the VM-Series firewall.
  16. (
    VM-Series firewall on Azure VMware Solution only
    ) Attach the deployed firewalls to the overlay segment.
    When deployed in an AVS environment, VM-Series firewalls do not have an assigned network adapter. Therefore, you must manually add an adapter (the overlay segment).
    1. Log in to your vSphere web client.
    2. Select your firewall and click the edit settings icon.
    3. On the
      Virtual Hardware
      tab, click
      Browse
      in the
      Network Adapter 1
      drop-down.
    4. Select the overlay networks segment you created and click
      OK
      .
    5. Click
      OK
      to close the Edit Settings window.

Recommended For You