Introduction

Purpose

Isolation of Guest VM traffic is achieved using Security Groups in Basic zone.  In Advanced zone, a shared network can be shared by multiple accounts/tenents, there is no way to do isolation in this network. The purpose of this document is to provide functional specification to use SG to isolate guest VM within a shared network in advanced zone. And in Advanced zone, VM can be on multiple shared networks, different NICs of a VM can have different SG sets, says SG works on NIC level in Advanced zone.

Glossary

Design

Not support

API changes

API behavior changes

UI Flow

The flows below require changes:

Add Zone

Add Cluster

Infrastructure -> PhysicalNetworks Diagram -> Modify Guest traffic type->AddNetwork

Networks tab

Deploy VM flow

Upgrade flow

Future release plans

In the future releases we are going to: