Deploy UserGate VE in a VMware-based cloud
You can deploy the UserGate VE virtual firewall in a public or private VMware-based cloud.
- Save the firewall image.
- Create a vApp and virtual machine from the image.
- Connect the virtual machine to a public subnet.
- Assign an IP address to access the firewall.
- Initialize the firewall.
- Specify DNS and NTP servers.
- Activate the license.
1. Save the firewall image
- Go to the ticket that was created when ordering the firewall.
- Save the firewall image to the device from which you will perform the configuration.
2. Create a vApp and virtual machine from the image
- From the control panel, open the Cloud Director panel: in the top menu, click Products → VMware-based cloud → Cloud Director.
- Open the virtual data center page where you want to deploy the firewall.
- Go to the Compute → vApps.
- Click NEW → Add vApp From OVF.
- Upload the saved firewall image files.
- In the Review Details section, verify the image details.
- Optional: in the Select vApp Name section, in the Name and Description fields, change the vApp name and description.
- Optional: in the Configure Resources section, in the Computer Name field, change the virtual machine name.
- Optional: in the Configure Resources section, in the Storage Policy field, change the network volume type.
- In the Customize Hardware section, set the virtual machine configuration parameters, taking into account the configuration requirements.
- Check the details and click Finish.
- Wait for the virtual machine creation from the image to complete. The installation process will appear at the bottom of the page in the Tasks.
3. Connect the virtual machine to a public subnet
- Optional: if you do not have a Direct Connected subnet or you want to use a new one, create a Direct Connected subnet.
- From the control panel, open the Cloud Director panel: in the top menu, click Products → VMware-based cloud → Cloud Director.
- Open the virtual data center page → Virtual Machines.
- Open the virtual machine page → Hardware → NICs.
- Click Edit.
- Click ADD NETWORK TO VAPP.
- In the Type field, select Direct.
- In the table, select the Direct Connected subnet.
- Click Add.
- Make sure that in the NIC 0 row, the Primary NIC and Connected checkboxes are selected.
- In the NIC 0 row, in the Network column, select the same Direct Connected subnet.
- In the NIC 0 row, in the IP column, specify an IP address from the Direct Connected subnet, other than its gateway address.
- Click Save.
4. Assign an IP address to access the firewall
UGOS 6
UGOS 7
UGOS 7.1 and higher
-
From the control panel, open the Cloud Director panel: in the top menu, click Products → VMware-based cloud → Cloud Director.
-
Open the virtual data center page → Virtual Machines.
-
Open the virtual machine page.
-
Click POWER ON.
-
Click LAUNCH WEB CONSOLE.
-
- login — Admin;
- password — utm.
-
Switch the internet port to
staticmode:iface config -name port0 -mode static -
Assign an IP address to the port:
iface config -name port0 -ipv4 <ip_address>/<mask>Specify:
<ip_address>— IP address from the Direct Connected subnet that you assigned to the virtual machine when connecting to the public subnet in step 3;<mask>— subnet mask.
-
Create a default route to the internet:
gateway add -ipv4 <gateway> -weight 1 -enabled true -default trueSpecify
<gateway>— gateway of the Direct Connected subnet. You can find the gateway address in the control panel: in the top menu, click Products → VMware-based cloud → data center page → Direct Connected subnets tab → Gateway.
5. Initialize the firewall
-
Open the page in your browser:
https://<ip_address>:8001Specify
<ip_address>— IP address that you assigned to access the firewall in step 4. -
Go to the Settings section.
-
Select the system language.
-
Select the time zone.
-
Accept the license agreement.
-
Change the administrator password.
-
Wait for the installation procedure to complete.
6. Specify DNS and NTP servers
-
Open the page in your browser:
https://<ip_address>:8001Specify
<ip_address>— IP address that you assigned to access the firewall in step 4. -
Go to the Settings → Network → DNS section.
-
Click Add.
-
Specify the DNS server IP addresses. We recommend using Selectel recursive DNS servers, but you can specify any available DNS servers.
-
Click Save.
-
Go to the Settings → Network → NTP section.
-
Click Add.
-
Specify the NTP server IP addresses. We recommend using Selectel NTP servers, but you can specify any available NTP servers.
-
Click Save.
7. Activate the license
UGOS 6
UGOS 7 and higher
-
Open the page in your browser:
https://<ip_address>:8001Specify
<ip_address>— IP address that you assigned to access the firewall in step 4. -
Go to the License Information → Registered version section.
-
Enter the pin code received in the ticket when ordering the firewall.
-
Click Next.
-
Fill out the registration form. We recommend using the same data as in your Selectel account.
-
Click Next.
-
Wait for the device to register. Information about the license composition and component expiration dates will be displayed in the License Information section.