Gateway Firewall (GFW) allows all traffic through a route-based IPSec VPN tunnel
search cancel

Gateway Firewall (GFW) allows all traffic through a route-based IPSec VPN tunnel

book

Article ID: 452915

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

After establishing a route-based IPSec VPN tunnel on a Tier-0 (T0) or Tier-1 (T1) gateway, all network traffic passes through the tunnel unrestricted, ignoring configured Gateway Firewall (GFW) DROP rules.

Environment

VMware vDefend Firewall

VMware NSX

Cause

By default, GFW rules applied at the T0 or T1 gateway level do not automatically apply to the Virtual Tunnel Interface (VTI). Because firewall enforcement occurs at specific interface targets, traffic traversing the VTI bypasses general gateway rules unless the VTI is explicitly selected in the rule's Applied To scope.

Resolution

To enforce firewall rules on VPN tunnel traffic, explicitly bind the GFW rules to the Virtual Tunnel Interface:

  1. Access Gateway Firewall: In VMware NSX Manager, navigate to Security > Gateway Firewall.

  2. Locate Rule: Select the target T0 or T1 gateway policy and select the desired GFW rule (or create a new rule).

  3. Edit Applied To Scope: In the rule table, locate the Applied To column and click the Pencil (Edit) icon.

  4. Select Interface: Select the specific Virtual Tunnel Interface (VTI) associated with the route-based IPSec VPN tunnel, then click Apply.

  5. Publish Changes: Click Publish to enforce the updated rule set.


Additional Information

Add a Gateway Firewall Policy and Rule

Using Route-Based IPSec VPN