---
name: vmwaresolutions-vpc-vcf-firewall
title: Configuring VMware vDefend Firewall for VCF for VPC instances
description: As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
last-updated: 2025-10-24
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Configuring VMware vDefend Firewall for VCF for VPC instances
{: #vpc-vcf-firewall}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

Before you configure VMware vDefend™ Firewall (formerly VMware NSX Firewall), review the information in [VMware vDefend Firewall add-on](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vmware-add-ons&format=markdown#vmware-add-ons-nsx-firewall).

1. In the VMware Solutions console, click **Resources** > **KMIP for VMware** from the left navigation panel.
2. In the instances table, click the instance to configure the firewalls for.
3. On the **Access information** tab, under **Management domain**, use the NSX-T admin account for VMware NSX-T Data Center to log in to the VMware NSX-T console.
   * To configure VMware vDefend™ Gateway Firewall, see [Gateway Firewall](https://techdocs.broadcom.com/us/en/vmware-cis/nsx/nsxt-dc/3-2/administration-guide/security/gateway-firewall.html){: external}.
   * To configure the VMware vDefend™ Distributed Firewall, see [Distributed Firewall](https://techdocs.broadcom.com/us/en/vmware-cis/nsx/nsxt-dc/3-2/administration-guide/security/distributed-firewall.html){: external}.

The IBM Cloud&reg; security groups for VPC (Virtual Private Cloud) also provide network security and act as a virtual firewall for your Virtual Server Instances and bare metal servers in the IBM Cloud VPC environment by managing east-west and north-south network traffic.

The security groups for VPC provide a convenient way to define and apply rules that establish filtering to a target of a resource, based on protocols, ports, and IP addresses. `uplink-priv-sg` and `uplink-pub-sg` are provisioned for the Tier 0 gateway with default rules, and you can modify these rules based on your needs. For more information, see [About security groups](https://cloud.ibm.com/docs/vpc?topic=vpc-using-security-groups&format=markdown).

## Related links
{: #vpc-vcf-firewall-links}

* [VMware vDefend Firewall add-on](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-vmware-add-ons&interface=ui&format=markdown#vmware-add-ons-nsx-firewall)