Only ACL allow rules are supported as part of Network ACLs. Default is to block all incoming and all outgoing traffic between tiers and between tiers and various gateways (including Public).  ACL deny rules will be supported. New field "order" will be added to rules to resolve conflicting rules. After rule creation, its order can be modified.

API:

createNetworkAcl: New parameter "order" will be added. Also have to:

https://cwiki.apache.org/confluence/display/CLOUDSTACK/Amazon+vs+CloudStack+APIs+for+VPC

TBD - add more detailes to this FS draft