Use the VM-Series Firewall CLI to Swap the Management Interface
This task is only required if your architecture
places the VM-Series firewall behind the Google Cloud Platform internal
load balancer.
If you did not specify metadata to swap
the management interface (MGT) with the dataplane interface when
you deployed the firewall, you can use the CLI to enable the firewall
to receive dataplane traffic on the primary interface.
Before you proceed, verify that
the firewall has a minimum of two network interfaces (eth0 and eth1).
If you launch the firewall with only one interface, the interface
swap command causes the firewall to boot into maintenance mode.
On the Google Cloud Console, view the VM instance details
to verify the network interface IP addresses of the eth1 interface
and verify that any security rules allow connections (HTTPS and
SSH) to the new management interface (eth1).
Log in to the VM-Series firewall CLI and enter the following command:
set system setting mgmt-interface-swap enable yes
You
can view the default mapping from the command line interface. The output
is similar to this: