Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents

ACL Deny Rules

Currently only ACL allow rules are supported as part of Network ACLs. Default is to block all incoming and all outgoing traffic between tiers and between tiers and various gateways (including Public).  ACL deny rules will be supported through this feature. New fields "number"  and "action"will be added to rules to resolve conflicting rules. After rule creation, its number can be modified. NetworkACLs will be evaluated in the order of its number starting from lowest. Action of the first matching rule is applied.  

NetworkACLContainer will be introduced to manage NetworkACLs.

NetworkACLContainer

NetworkACLContainer is a numbered list of  NetworkACLs that are evaluated in order, starting with the lowest numbered rule, to determine whether traffic is allowed in or out of any tier associated with the network ACL.

...

  • Parameters:**  id (required) - Id of the network ACL** trafficType (optional) - can be ingress/egress (defaulted to ingress if not specified)** cidrlist (optional) - List of the coma separated CIDRs for the rule. If not specified, defaulted to 0.0.0.0/0
    • startPort (optional)
    • endPort (optional)
    • protocol (optional). TCP/UDP/ICMP protocol types are supported
    • icmpType (optional) - type of the icmp message being sent
    • icmpCode (optional) - error code for this icmp message
    • action (optional) - allow/deny
    • number (optional) - rule number 

...