Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

ACL Deny Rules

Only ACL allow rules are supported as part of Network ACLs. Default is to block all incoming and all outgoing traffic between tiers and between tiers and various gateways (including Public).  ACL deny rules will be supported. New fields "number"  and "action"will be added to rules to resolve conflicting rules. After rule creation, its number can be modified. NetworkACLs will be evaluated in the order of its number . starting from lowest. Action of the matching rule is applied.  

NetworkACLContainer will be introduced to manage NetworkACLs.

NetworkACLContainer

NetworkACLContainer is a set of NetworkACLs that can be assigned to any vpc tier. Instead of adding NetworkACLs directly to the tier,   NetworkACLs will be added to the NetworkACLContainer. NetworkACLContainer can be assigned to multiple vpc tiers. Each tier can be associated with only one NetworkACLContainer. 

...

NetworkACLs can be added or removed from the container using APIs addACLtoContaineraddNetworkACLtoContainer, removeNetworkACLfromContainer 

API changes

Existing API

...

createNetworkAcl

  • New parameters**
    • action (required) - allow/deny
    • number (required) - rule number. ACL rules are ordered by this number

new API

...

replaceNetworkACL:

  • Parameters:** id (required) - Id of the network ACL 
    • trafficType (optional) - can be ingress/egress (defaulted to ingress if not specified)
    • cidrlist (optional) - List of the coma separated CIDRs for the rule. If not specified, defaulted to 0.0.0.0/0
    • startPort (optional)
    • endPort (optional)
    • protocol (optional). TCP/UDP/ICMP protocol types are supported
    • icmpType (optional) - type of the icmp message being sent
    • icmpCode (optional) - error code for this icmp message
    • action (optional) - allow/deny
    • number (optional) - rule number 

createNetworkAclContainer

Parameters:

  • name - Name of the Network Acl Container

Response:

  • name - Name of the Network Acl Container

...

  • id - Id of the Network Acl Container
    addNetworkACLtoContainerParameters:
  • acl_id - Id of the network ACL
  • container_id: Id of the network ACL container

Response

  • success - True when ACL is successfully added to container, false otherwise. 
    removeNetworkACLfromContainerParameters:
  • acl_id - Id of the network ACL
  • container_id: Id of the network ACL container

Response:

  • success - True when ACL is successfully removed from container, false otherwise

DB

New columns in firewall_rules table:

...