Access control policy examples
Examples of access control policies for the internet firewall, VPC firewall, and internal firewall.
Internet firewall policy examples
Cloud Firewall controls internet-facing (north-south) inbound and outbound traffic. Configure access control policies for an internet firewall covers all policy parameters.
Allow inbound public traffic to a specific port
Example: An ECS instance has private IP 10.1.XX.XX and EIP 200.2.XX.XX/32. The following policy allows all inbound internet traffic (0.0.0.0/0) to TCP port 80 only.
Log on to the Cloud Firewall console.
In the left-side navigation pane, select .
On the Inbound tab, click Create Policy. In the Create Inbound Policy panel, on the Create Policy tab, configure the following policies.
Configure a policy to allow public traffic to TCP port 80 of the instance, and then click OK.
Key parameters:
Parameter
Description
Example value
Source Type
Traffic source. Select a source type and enter the source address.
IP
Source
0.0.0.0/0Note0.0.0.0/0represents all public IP addresses.Destination Type
Traffic destination. Select a destination type and enter the destination address.
IP
Destination
200.2.XX.XX/32Protocol Type
Transport layer protocol: TCP, UDP, ICMP, or ANY. Select ANY if unsure.
TCP
Port Type
Destination port type and port number.
Port
Port
80/80Application
Application type of the traffic.
ANY
Action
Action on matched traffic.
Allow
Priority
Policy priority. Default: Lowest.
Highest
Status
Specify whether to enable the policy. Only enabled policies take effect.
Enabled
Configure a policy to deny all public traffic to all instances, and then click OK.
Create the Deny policy with the following parameters:
Destination:
0.0.0.0/0Note0.0.0.0/0represents the IP addresses of all instances.Protocol Type: ANY
Port:
0/0Note0/0represents all ports of the instance.Application: ANY
Action: Drop
Priority: Lowest
Confirm that the policy to Allow inbound traffic to TCP port 80 of the host has a higher priority than the policy to Deny all inbound traffic to the host.
VPC firewall policy examples
A VPC firewall controls traffic between VPCs (east-west traffic). Configure access control policies for a VPC firewall covers all policy parameters.
Deny traffic between ECS instances in different VPCs
By default, ECS instances in VPCs connected by CEN or Express Connect can communicate.
Example: VPC1 and VPC2 are connected by CEN. ECS1 (10.33.XX.XX/32) is in VPC1 and ECS2 (10.66.XX.XX/32) is in VPC2. The following policy denies access from ECS1 to ECS2.
Log on to the Cloud Firewall console
In the left-side navigation pane, choose .
On the VPC Border page, click Create Policy.
In the Create Policy - VPC Border panel, configure the policy as described in the following table, and then click Confirm.
Key parameters:
Parameter
Description
Example value
Source Type
Traffic source type.
IP
Source
Traffic source address.
10.33.XX.XX/32Destination Type
Traffic destination type.
IP
Destination
Traffic destination address.
10.66.XX.XX/32Protocol Type
Traffic protocol.
TCP
Port Type
Port type.
Port
Port
Enter a port based on the Port Type setting, or click Select to select a Port Address Book.
0/0Application
Application type.
ANY
Action
Allow or deny matched traffic.
Drop
Internal firewall policy examples
The internal firewall controls traffic between ECS instances. Policies sync to ECS security groups and take effect after publishing. Security group configuration covers all policy parameters.
Enable ECS communication within a policy group
Unlike ECS security groups, which allow intra-group communication by default, the Cloud Firewall internal firewall requires an explicit Allow policy.
Example: ECS1 (10.33.XX.XX) and ECS2 (10.66.XX.XX) are in policy group sg-test. The following policies enable communication between them.
Log on to the Cloud Firewall console.
In the left-side navigation pane, choose .
On the Security Group Configuration page, find the target policy group and click Configure Policy in the Actions column.
On the Inbound tab, click Create Policy.
Configure an inbound Allow policy with the following parameters:
Parameter
Description
Example value
Policy Type:
Policy type.
Allow
Protocol Type
Protocol type.
TCP
Port Range
Port range.
0/0Source Type, Source
Traffic source. Required when the policy direction is Inbound.
Source Type: Policy Group
Source Object: sg-test
Destination
Traffic destination. Required for inbound policies.
Address Segment Access (CIDR block: 10.66.XX.XX)
NoteTo enable communication among all ECS instances in the policy group, set Destination to All ECS Instances.
To enable communication among specific ECS instances in the policy group, set Destination to CIDR Block and enter the CIDR block of the peer ECS instance.
If you use an advanced security group, you also need to configure an outbound Allow policy.
A basic security group allows all outbound traffic by default.
Configure the outbound policy with the following parameters:
Source Type: IP
Source:
10.66.XX.XXCIDR Block:
10.33.XX.XX
Enable ECS communication between policy groups
Example: ECS1 (10.33.XX.XX) and ECS2 (10.66.XX.XX) are in different policy groups. The following policies enable communication between them.
Log on to the Cloud Firewall console.
In the left-side navigation pane, choose .
On the Security Group Configuration page, find the policy group that contains ECS1 and click Configure Policy in the Actions column.
On the Inbound tab, click Create Policy.
Configure an inbound Allow policy with the following parameters:
Parameter
Description
Example value
Policy Type
Policy type.
Allow
Protocol Type
Protocol type.
TCP
Port Range
Port range.
0/0Source Type, Source
Traffic source. Required for inbound policies.
Source Type: IP
Source Object:
10.66.XX.XX
Destination
Traffic destination. Required for inbound policies.
Address Segment Access (CIDR block: 10.33.XX.XX)
NoteIf you want ECS instances in the sg-test2 policy group to access all ECS instances in the sg-test1 policy group, set Destination to All ECS Instances.
If you want ECS instances in the sg-test2 policy group to access specific ECS instances in the sg-test1 policy group, set Destination to CIDR Block and enter the CIDR blocks of the ECS instances in the sg-test1 policy group.
If you use an advanced security group, you also need to configure an outbound Allow policy.
A basic security group allows all outbound traffic by default.
Configure the outbound policy with the following parameters:
Source Type: IP
Source:
10.33.XX.XXCIDR Block:
10.66.XX.XX
Similarly, configure the corresponding inbound and outbound Allow policies for ECS2.