Access control policy examples

Updated at:

Examples of access control policies for the internet firewall, VPC firewall, and internal firewall.

Internet firewall policy examples

Cloud Firewall controls internet-facing (north-south) inbound and outbound traffic. Configure access control policies for an internet firewall covers all policy parameters.

Allow inbound public traffic to a specific port

Example: An ECS instance has private IP 10.1.XX.XX and EIP 200.2.XX.XX/32. The following policy allows all inbound internet traffic (0.0.0.0/0) to TCP port 80 only.

  1. Log on to the Cloud Firewall console.

  2. In the left-side navigation pane, select Prevention Configuration > Access Control > Policy Configuration > Internet Border.

  3. On the Inbound tab, click Create Policy. In the Create Inbound Policy panel, on the Create Policy tab, configure the following policies.

    1. Configure a policy to allow public traffic to TCP port 80 of the instance, and then click OK.

      Key parameters:

      Parameter

      Description

      Example value

      Source Type

      Traffic source. Select a source type and enter the source address.

      IP

      Source

      0.0.0.0/0

      Note

      0.0.0.0/0 represents all public IP addresses.

      Destination Type

      Traffic destination. Select a destination type and enter the destination address.

      IP

      Destination

      200.2.XX.XX/32

      Protocol Type

      Transport layer protocol: TCP, UDP, ICMP, or ANY. Select ANY if unsure.

      TCP

      Port Type

      Destination port type and port number.

      Port

      Port

      80/80

      Application

      Application type of the traffic.

      ANY

      Action

      Action on matched traffic.

      Allow

      Priority

      Policy priority. Default: Lowest.

      Highest

      Status

      Specify whether to enable the policy. Only enabled policies take effect.

      Enabled

    2. Configure a policy to deny all public traffic to all instances, and then click OK.

      Create the Deny policy with the following parameters:

      • Destination: 0.0.0.0/0

        Note

        0.0.0.0/0 represents the IP addresses of all instances.

      • Protocol Type: ANY

      • Port: 0/0

        Note

        0/0 represents all ports of the instance.

      • Application: ANY

      • Action: Drop

      • Priority: Lowest

    Confirm that the policy to Allow inbound traffic to TCP port 80 of the host has a higher priority than the policy to Deny all inbound traffic to the host.

VPC firewall policy examples

A VPC firewall controls traffic between VPCs (east-west traffic). Configure access control policies for a VPC firewall covers all policy parameters.

Deny traffic between ECS instances in different VPCs

Note

By default, ECS instances in VPCs connected by CEN or Express Connect can communicate.

Example: VPC1 and VPC2 are connected by CEN. ECS1 (10.33.XX.XX/32) is in VPC1 and ECS2 (10.66.XX.XX/32) is in VPC2. The following policy denies access from ECS1 to ECS2.

  1. Log on to the Cloud Firewall console

  2. In the left-side navigation pane, choose Prevention Configuration > Access Control > Policy Configuration > VPC Border.

  3. On the VPC Border page, click Create Policy.

  4. In the Create Policy - VPC Border panel, configure the policy as described in the following table, and then click Confirm.

    Key parameters:

    Parameter

    Description

    Example value

    Source Type

    Traffic source type.

    IP

    Source

    Traffic source address.

    10.33.XX.XX/32

    Destination Type

    Traffic destination type.

    IP

    Destination

    Traffic destination address.

    10.66.XX.XX/32

    Protocol Type

    Traffic protocol.

    TCP

    Port Type

    Port type.

    Port

    Port

    Enter a port based on the Port Type setting, or click Select to select a Port Address Book.

    0/0

    Application

    Application type.

    ANY

    Action

    Allow or deny matched traffic.

    Drop

Internal firewall policy examples

The internal firewall controls traffic between ECS instances. Policies sync to ECS security groups and take effect after publishing. Security group configuration covers all policy parameters.

Enable ECS communication within a policy group

Note

Unlike ECS security groups, which allow intra-group communication by default, the Cloud Firewall internal firewall requires an explicit Allow policy.

Example: ECS1 (10.33.XX.XX) and ECS2 (10.66.XX.XX) are in policy group sg-test. The following policies enable communication between them.

  1. Log on to the Cloud Firewall console.

  2. In the left-side navigation pane, choose Prevention Configuration > Security Group Control > Security Group Configuration.

  3. On the Security Group Configuration page, find the target policy group and click Configure Policy in the Actions column.

  4. On the Inbound tab, click Create Policy.

    Configure an inbound Allow policy with the following parameters:

    Parameter

    Description

    Example value

    Policy Type:

    Policy type.

    Allow

    Protocol Type

    Protocol type.

    TCP

    Port Range

    Port range.

    0/0

    Source Type, Source

    Traffic source. Required when the policy direction is Inbound.

    • Source Type: Policy Group

    • Source Object: sg-test

    Destination

    Traffic destination. Required for inbound policies.

    Address Segment Access (CIDR block: 10.66.XX.XX)

    Note
    • To enable communication among all ECS instances in the policy group, set Destination to All ECS Instances.

    • To enable communication among specific ECS instances in the policy group, set Destination to CIDR Block and enter the CIDR block of the peer ECS instance.

  5. If you use an advanced security group, you also need to configure an outbound Allow policy.

    A basic security group allows all outbound traffic by default.

    Configure the outbound policy with the following parameters:

    • Source Type: IP

    • Source: 10.66.XX.XX

    • CIDR Block: 10.33.XX.XX

Enable ECS communication between policy groups

Example: ECS1 (10.33.XX.XX) and ECS2 (10.66.XX.XX) are in different policy groups. The following policies enable communication between them.

  1. Log on to the Cloud Firewall console.

  2. In the left-side navigation pane, choose Prevention Configuration > Security Group Control > Security Group Configuration.

  3. On the Security Group Configuration page, find the policy group that contains ECS1 and click Configure Policy in the Actions column.

  4. On the Inbound tab, click Create Policy.

    Configure an inbound Allow policy with the following parameters:

    Parameter

    Description

    Example value

    Policy Type

    Policy type.

    Allow

    Protocol Type

    Protocol type.

    TCP

    Port Range

    Port range.

    0/0

    Source Type, Source

    Traffic source. Required for inbound policies.

    • Source Type: IP

    • Source Object: 10.66.XX.XX

    Destination

    Traffic destination. Required for inbound policies.

    Address Segment Access (CIDR block: 10.33.XX.XX)

    Note
    • If you want ECS instances in the sg-test2 policy group to access all ECS instances in the sg-test1 policy group, set Destination to All ECS Instances.

    • If you want ECS instances in the sg-test2 policy group to access specific ECS instances in the sg-test1 policy group, set Destination to CIDR Block and enter the CIDR blocks of the ECS instances in the sg-test1 policy group.

  5. If you use an advanced security group, you also need to configure an outbound Allow policy.

    A basic security group allows all outbound traffic by default.

    Configure the outbound policy with the following parameters:

    • Source Type: IP

    • Source: 10.33.XX.XX

    • CIDR Block: 10.66.XX.XX

  6. Similarly, configure the corresponding inbound and outbound Allow policies for ECS2.