Creating the SNS EVA firewall instance
The deployed instance of the SNS EVA firewall is attached to the VPC, security group for traffic with the outside, SSH key and public network created earlier.
Creating the firewall instance
In the COCKPIT 3DS OUTSCALE console, under the Compute menu:
- Select Instances.
- Click on Create, then Expert mode.
- Name the instance (e.g., Documentation-SNS-EVA) and click on Next.
- Enter SNS in the search field, then select the desired firewall model.
- Click on Next.
- Define the properties of your instance, according to the properties chosen when you acquired your EVA license from Stormshield (cf. Stormshield Network Security Elastic Virtual Appliances – EVA datasheet):
- The CPU Generation,
- The desired Performance level (3DS OUTSCALE parameter),
- The number of Cores,
- The amount of Memory (GB) allocated to the virtual machine.
- Click on Next.
- Select the VPC (Documentation-VPC in the example).
- Select the public sub-network of the VPC (Documentation-VPC-Public in the example).
- Enter the IP address to associate with the firewall's public interface.
This address (172.21.0.59 in the example) must belong to the sub-network selected in step 9. - Select the geographic area in which this sub-network is available (eu-west-2a in the example).
- Click on Next.
- Select the security group for traffic with the outside (Documentation- Security-Group in the example).
- Click on Next.
- Select the SSH key created at the start of the process (Documentation-Keypair in the example).
- Click twice on Next.
You will be shown a summary of the instance. - Confirm the creation of the instance by clicking on Create.
IMPORTANT
For optimal performance, ensure that these properties match those in your EVA license.
NOTE
The admin account password is the instance ID;
With this admin account, the user can connect:
This password must be changed for security reasons during the initial connection to the firewall.
The admin account password is the instance ID;
With this admin account, the user can connect:
- In SSH to the firewall’s public IP address using a tool such as PuTTY.
- In HTTPS to the firewall’s web administration interface (https://firewall_public_ip_address/admin).
This password must be changed for security reasons during the initial connection to the firewall.