August 2026 release is live Read More

Datacenter Gateway firewall configuration

In Datacenter Gateway firewall Configuration we are adding two rules, they are

  • Management Gateway for (appliance access to vCenter)

  • Compute Gateway for (appliance access to internet for access to Mavvrik API via internet)

Why this matters: the appliance needs two things to work: it has to reach vCenter (Management Gateway), and it has to reach Mavvrik's API over the internet (Compute Gateway). Miss either rule and the appliance either can't read your environment or can't send the data anywhere — getting both configured correctly here avoids a confusing "it's deployed but nothing's showing up" troubleshooting session later.

Before you start: you'll need admin access to your VMware Cloud console's networking and security section.

Below are the steps for configuring the gateway firewall

  1. Login to VMware on cloud console and navigate to VMware cloud Tab under the Menu section

Open the VMware Cloud console
Open the VMware Cloud console

Under Left side nav bar > inventory > View details > Networking and security

Open Networking and Security
Open Networking and Security

Management Gateway

  1. In networking and security click on Legacy View

Switch to the legacy Networking and Security view
Switch to the legacy Networking and Security view
  1. On Security > Click on Gateway firewall > Management Gateway > Enter all the required details

Open Management Gateway firewall rules
Open Management Gateway firewall rules
  1. Then Click on Add rule. Then:

  1. Enter the rule name

  2. In the Source section click on edit icon > user-defined Group > Add Group

Create a source group for the Management Gateway rule
Create a source group for the Management Gateway rule
  1. Add Group name and click on set link and enter the IP
    eg. 192.168.0.1 your network Ip and then click on apply

Add the source IP to the Management Gateway group
Add the source IP to the Management Gateway group
  1. After setting up the Ip click on Save and then Apply

Save the Management Gateway source group
Save the Management Gateway source group
  1. Then on the Destination column click on edit icon

  2. Then select vCenter from the list and click on apply

Set vCenter as the Management Gateway destination
Set vCenter as the Management Gateway destination
  1. Then on the service column click on edit icon

  2. Select “HTTPS”, “SSO”, “ICMP All” and click on Publish

Select services and publish the Management Gateway rule
Select services and publish the Management Gateway rule

For mavvrik appliances having internet access to connect to Mavvrik APIs

Compute Gateway

  1. On Security > Click on Gateway firewall > Compute Gateway > Enter all the required details

Open Compute Gateway firewall rules
Open Compute Gateway firewall rules
  1. Then click on Add rule. Then:

  1. Enter the rule name

  2. In the Source section click on edit icon > user-defined Group > Add Group

Create a source group for the Compute Gateway rule
Create a source group for the Compute Gateway rule
  1. Add Group name and click on set link and then click on ip address only and enter the IP
    eg. 192.168.0.0/24 your network Ip and then click on apply

Add the source network to the Compute Gateway group
Add the source network to the Compute Gateway group
  1. After setting up the Ip click on Save and then Apply

Save the Compute Gateway source group
Save the Compute Gateway source group
  1. Then on the Applied to column click on edit icon

  2. Select “All Uplinks”, “VPC Interface”, “Intranet Interface”, “Internet Interface“, “VPN Tunnel Interface” and click on Publish

Apply and publish the Compute Gateway rule
Apply and publish the Compute Gateway rule