VM-Series
Deployment
Guide
59
Set Up a VM-Series NSX Edition Firewall
Register the VM-Series Firewall as a Service on the NSX Manager
Register the VM-Series Firewall as a Service on the NSX
Manager
To automate the provisioning of the VM-Series NSX edition firewall, enable communication between the NSX
Manager and Panorama. This is a one-time setup, and only needs to be modified if the IP address of the NSX
Manager changes or if the capacity license for deploying the VM-Series firewall is exceeded.
Use Panorama to Register the VM-Series Firewall as a Service
Step 1
Log in to the Panorama web interface. Using a secure connection (https) from a web browser, log in
using the IP address and password you assigned during initial
configuration (https://<
IP address
>).
Step 2
Set up access to the NSX Manager.
1.
Select
Panorama > VMware Service Manager
.
2.
Enter the
Service Manager Name
.
On the NSX Manager, this name displays in the Service
Manager column on
Networking & Security > Service
Definitions.
See the screenshot in
Step 9
.
3.
(Optional) Add a
Description
that identifies the VM-Series
firewall as a service.
4.
Enter the
NSX Manager URL
—IP address or FQDN—at
which to access the NSX Manager.
5.
Enter the
NSX Manager Login
credentials—username and
password, so that Panorama can authenticate to the NSX
Manager.
Step 3
Specify the location of the web server
that hosts the OVF file.
Extract and save both the .ovf
and .vmdk files to the same
directory. Both the files are
required to deploy each
instance of the firewall.
If needed modify the security
settings on the server so that
you can download the file
types. For example, on the IIS
server modify the Mime Types
configuration; on an Apache
server edit the .htaccess file.
In
VM-Series OVF URL
, add the location of the web server that
hosts the ovf file. Both http and https are supported protocols.
For example, enter
https://acme.com/software/PA-VM-NSX.ovf
Using an ovf file with a generic name gives you the
flexibility to overwrite the image, without causing the
NSX Manager to go out of sync with Panorama. With a
non-generic name when you modify the
VM-Series OVF
URL
, the service definition on the NSX Manager goes
out of sync with Panorama. And the only way to resolve
the conflict is to redeploy the VM-Series firewall, on
each host in the cluster, using the image specified in the
URL.