Ravello service provides some basic firewall capabilities. For example, by default each environment running on Ravello has access to the internet, but no access is available from the outside in. You can modify these settings and allow specific ports on selected VMs that would then be accessible from the outside.
In addition, you can upload your own firewall (for example, Check Point, Fortinet, or Palo Alto Networks) and place it within a Ravello application. It can serve as the entry point to the application (i.e., all incoming traffic to the application goes through this firewall) and control the rules and traffic to the rest of the components using the standard configuration of the firewall.