|  | <?xml version='1.0' encoding='utf-8' ?> | 
|  | <!DOCTYPE section PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN" "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [ | 
|  | <!ENTITY % BOOK_ENTITIES SYSTEM "cloudstack.ent"> | 
|  | %BOOK_ENTITIES; | 
|  | ]> | 
|  |  | 
|  | <!-- Licensed to the Apache Software Foundation (ASF) under one | 
|  | or more contributor license agreements.  See the NOTICE file | 
|  | distributed with this work for additional information | 
|  | regarding copyright ownership.  The ASF licenses this file | 
|  | to you under the Apache License, Version 2.0 (the | 
|  | "License"); you may not use this file except in compliance | 
|  | with the License.  You may obtain a copy of the License at | 
|  |  | 
|  | http://www.apache.org/licenses/LICENSE-2.0 | 
|  |  | 
|  | Unless required by applicable law or agreed to in writing, | 
|  | software distributed under the License is distributed on an | 
|  | "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | 
|  | KIND, either express or implied.  See the License for the | 
|  | specific language governing permissions and limitations | 
|  | under the License. | 
|  | --> | 
|  |  | 
|  | <section id="initial-setup-of-external-firewalls-loadbalancer"> | 
|  | <title>Initial Setup of External Firewalls and Load Balancers</title> | 
|  | <para>When the first VM is created for a new account, &PRODUCT; programs the external firewall and load balancer to work with the VM. The following objects are created on the firewall:</para> | 
|  | <itemizedlist> | 
|  | <listitem><para>A new logical interface to connect to the account's private VLAN. The interface IP is always the first IP of the account's private subnet (e.g. 10.1.1.1). </para></listitem> | 
|  | <listitem><para>A source NAT rule that forwards all outgoing traffic from the account's private VLAN to the public Internet, using the account's public IP address as the source address</para></listitem> | 
|  | <listitem><para>A firewall filter counter that measures the number of bytes of outgoing traffic for the account</para></listitem> | 
|  | </itemizedlist> | 
|  | <para>The following objects are created on the load balancer:</para> | 
|  | <itemizedlist> | 
|  | <listitem><para>A new VLAN that matches the account's provisioned Zone VLAN</para></listitem> | 
|  | <listitem><para>A self IP for the VLAN. This is always the second IP of the account's private subnet (e.g. 10.1.1.2).</para></listitem> | 
|  | </itemizedlist> | 
|  | </section> |