Creating the Network Security Group(s) - NetCloud-Virtual-Edge-Deployment-Guide-Azure/Creating-the-Network-Security-Group-s

NetCloud Virtual Edge Deployment Guide - Azure

ft:locale
en-US
ft:sourceName
Paligo_Prod
Document Type
Deployment Guide

The following protocols and ports are required for Secure Connect to function:

  • (Required) inbound to WAN – TCP ports 22 (SSH), 80 (HTTP), 443 (HTTPS)

  • (Required) outbound from WAN – Allow all

  • (Optional) inbound LAN – Limited by site resource and access policy

One network security group may be created for each interface.

Complete the following steps to create a network security group and security rule for the WAN interface:

  1. In the Azure portal, search for “network security groups” and select Network security groups from the Services list.

    Note

    Do not select Network security groups (classic).

  2. Select Create.

  3. Ensure that the subscription and region are correct.

  4. Select the Resource group.

  5. Enter a descriptive name for the network security group.

  6. Select Review + create.

    Azure Create network security resource group screen highlighting the Review + create button.
  7. Select Create to save the new network security group.

  8. Select Go to resource.

    Azure security group deployment confirmation screen highlighting the Go to resource button.
  9. Select Inbound security rules, under Settings in the left-side navigation panel, and then select Add.

    Azure Inbound security rule screen highlighting the Add button.
  10. Enter 80, 443, 53, 8443 for the Destination port ranges.

  11. Select the appropriate type of the protocol as mentioned previously.

  12. Enter a descriptive name for the rule. Ericsson Enterprise Wireless recommends naming the rule based upon its function for usability and simplicity.

  13. Select Add.

    Azure Add inbound security rule screen highlighting the Add button.

Repeat this procedure for an additional network security group or inbound or outbound security rules for the lan0 interface, if needed.