...
NetworkACLContainer will be introduced to manage NetworkACLs.
NetworkACLContainer
NetworkACLContainer is a numbered list of NetworkACLs that are evaluated in order, starting with the lowest numbered rule, to determine whether traffic is allowed in or out of any tier associated with the network ACL.
...
NetworkACLs can be added to or removed from the container using APIs createNetworkACL and removedNetworkACL removeNetworkACL APIs.
API changes
Existing API{*}
createNetworkAcl
- New parameters** action (required) - allow/deny** number (required) - rule number. ACL rules are ordered by this number
- container_id (optional) - id of the network ACL container
- network_id parameter is not required when container_id is specified.
...
- New parameters** container_id (optional) - id of the network ACL container. Default NetworkACLContainer will be used when not specified.
new API
updateNetworkACL
- Parameters:** id (required) - Id of the network ACL** trafficType (optional) - can be ingress/egress (defaulted to ingress if not specified)** cidrlist (optional) - List of the coma separated CIDRs for the rule. If not specified, defaulted to 0.0.0.0/0** startPort (optional)** endPort (optional)** protocol (optional). TCP/UDP/ICMP protocol types are supported
- icmpType (optional) - type of the icmp message being sent
- icmpCode (optional) - error code for this icmp message
- action (optional) - allow/deny
- number (optional) - rule number
...
- success - True when container is successfully assigned to network, false otherwise
DB
New Tables
1. network_acl_container
- New Columns
- id (long): auto-generated id
- uuid (string): auto-generated uuid
- name: name of the network acl container
- description: network acl container description
...