Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents

ACL Deny Rules

Currently only ACL allow rules are supported as part of Network ACLs. Default is to block all incoming and all outgoing traffic between tiers and between tiers and various gateways (including Public).  ACL deny rules will be supported through this feature. New fields "number"  and "action"will be added to rules to resolve conflicting rules. After rule creation, its number can be modified. NetworkACLs will be evaluated in the order of its number starting from lowest. Action of the first matching rule is applied.  

...

  • New parameters**  action (required) - allow/deny** number (required) - rule number. ACL rules are ordered by this number
    • container_id (optional) - id of the network ACL container

...

updateNetworkACL

  • Parameters:**  id (required) - Id of the network ACL
    • trafficType (optional) - can be ingress/egress (defaulted to ingress if not specified)
    • cidrlist (optional) - List of the coma separated CIDRs for the rule. If not specified, defaulted to 0.0.0.0/0
    • startPort (optional)
    • endPort (optional)
    • protocol (optional). TCP/UDP/ICMP protocol types are supported
    • icmpType (optional) - type of the icmp message being sent
    • icmpCode (optional) - error code for this icmp message
    • action (optional) - allow/deny
    • number (optional) - rule number 

...