Skip to main content
Deploy UserGate VE in VMware-based clouds
Last update:

Deploy UserGate VE in VMware-based clouds

You can deploy a UserGate VE virtual firewall in the public or VMware-based private cloud.

  1. Make sure to save the image received in the ticket when the order You can configure the firewall on the device from which you will be configuring it.
  2. Create a vApp and virtual machine from the image.
  3. Connect the virtual machine to a public subnet.
  4. Assign an IP address to access the firewall.
  5. Initialize the firewall.
  6. Specify DNS and NTP servers.
  7. Activate the license.

Create a vApp and virtual machine from the image

  1. From control panels open the Cloud Director panel: VMware-based cloudCloud Director.
  2. Open the page of the virtual data center where you want to deploy the firewall.
  3. Go to the section ComputevApps.
  4. Click NEWAdd vApp From OVF.
  5. Download all the image files you received in the ticket when ordering the firewall.
  6. In the section Review Details check the details of the image.
  7. Optional: under Select vApp Name in the fields Name и Description Change the name and description of the vApp to be created.
  8. Optional: under Configure Resources in the field Computer Name change the name of the virtual machine.
  9. Optional: under Configure Resources in the field Storage Policy change the network disk type.
  10. In the section Customize Hardware set the virtual machine configuration parameters, taking into account configuration requirements.
  11. Check the data and press Finish.
  12. At the bottom of the page in the block Tasks the process of creating a virtual machine from the image will start. Wait until the process completes — the virtual machine is created and ready to run.

Connect a virtual machine to a public subnet

  1. Optional: if you do not have a Direct Connected subnet or want to use a new one, create a Direct Connected subnet.
  2. From control panels open the Cloud Director panel: VMware-based cloudCloud Director.
  3. Open the data center page → section Virtual Machines.
  4. Open the virtual machine page → section HardwareNICs.
  5. Click Edit.
  6. Click ADD NETWORK TO VAPP.
  7. Specify Type — Direct.
  8. In the table, select Direct Connected subnet.
  9. Click Add.
  10. Make sure that in the line NIC 0 checkboxes Primary NIC и Connected.
  11. On the line NIC 0 in the column Network select the same Direct Connected subnet.
  12. On the line NIC 0 in the column IP Specify an IP address from the Direct Connected subnet that is different from its gateway address.
  13. Click Save.

Assign an IP address to access the firewall

  1. From control panels open the Cloud Director panel: VMware-based cloudCloud Director.

  2. Open the virtual data center page → section Virtual Machines.

  3. Open the virtual machine page.

  4. Click POWER ON.

  5. Click LAUNCH WEB CONSOLE.

  6. Connect to the firewall:

    • login — Admin;
    • the password is. utm.
  7. Switch the Internet port to the static:

    iface config -name port0 -mode static
  8. Assign an IP address to the port:

    iface config -name port0 -ipv4 <ip/mask>

    Specify <ip/mask> - The address from the Direct Connected subnet that you specified for the virtual machine at connecting to a public subnet.

  9. Create a default route to the Internet:

    gateway add -ipv4 <ip_address> -weight 1 -enabled true -default true

    Specify <ip_address> — gateway of the Direct Connected subnet. You can view the gateway address in control panels under VMware-based cloud → data center page → tab Direct Connected subnets → field Gateway.

Initialize the firewall

  1. Open the page in your browser:

    https://<ip_address>:8001

    Specify <ip_address> — The IP address that assigned to access the firewall.

  2. Go to the section Settings.

  3. Select the language of the system.

  4. Select the time zone.

  5. Accept the license agreement.

  6. Change the administrator password.

  7. Wait for the installation procedure to complete.

Specify DNS and NTP servers

  1. Open the page in your browser:

    https://<ip_address>:8001

    Specify <ip_address>  — The IP address that assigned to access the firewall.

  2. Go to the section SettingsNetworkDNS.

  3. Click Add.

  4. Specify the IP addresses of the DNS servers. We recommend using Selectel recursive DNS serversBut you can specify any available DNS servers.

  5. Click Save.

  6. Go to the section SettingsNetworkNTP.

  7. Click Add.

  8. Specify the IP addresses of the NTP servers. We recommend using Selectel NTP serversBut you can specify any available NTP servers.

  9. Click Save.

Activate license

  1. Open the page in your browser:

    https://<ip_address>:8001

    Specify <ip_address>  — The IP address that assigned to access the firewall.

  2. Go to the section License informationRegistered version.

  3. Enter the pin code received at ticket when ordering a firewall.

  4. Click Further.

  5. Fill out the registration form. We recommend that you provide the same information as in your Selectel account.

  6. Click Further.

  7. Wait until the device is registered. Information about the license composition and expiration dates of the components will be displayed in the section License information.