Modifying a Network ACL Rule
Scenarios
Modify an inbound or outbound network ACL rule based on your network security requirements.
Procedure
- Log in to the management console.
- Click
in the upper left corner and select the desired region and project. - On the console homepage, under Network, click Virtual Private Cloud.
- In the navigation pane on the left, choose Access Control > Network ACLs.
- Locate the target network ACL and click its name to switch to the page showing details of that particular network ACL.
- On the Inbound Rules or Outbound Rules tab, locate the row that contains the target rule and click Modify in the Operation column. In the displayed dialog box, configure parameters as prompted. Table 1 lists the parameters to be configured.
Table 1 Parameter descriptions Parameter
Description
Example Value
Type
This parameter is available only after the IPv6 function is enabled.
The network ACL type. This parameter is mandatory. You can select a value from the drop-down list. Currently, only IPv4 and IPv6 are supported.
IPv4
Action
The action in the network ACL. This parameter is mandatory. You can select a value from the drop-down list. Currently, the value can be Allow or Deny.
Allow
Protocol
The protocol supported by the network ACL. This parameter is mandatory. You can select a value from the drop-down list. The value can be TCP, UDP, All, or ICMP. If ICMP or All is selected, you do not need to specify port information.
TCP
Source
The source from which the traffic is allowed. The source can be an IP address or IP address range.
The default value is 0.0.0.0/0, which indicates that traffic from all IP addresses is allowed.
For example:
- xxx.xxx.xxx.xxx/32 (IP address)
- xxx.xxx.xxx.0/24 (IP address range)
- 0.0.0.0/0 (all IP addresses)
0.0.0.0/0
Source Port Range
The source port number or port number range. The value ranges from 1 to 65535. For a port number range, enter two port numbers connected by a hyphen (-). For example, 1-100.
You must specify this parameter if TCP or UDP is selected for Protocol.
22, or 22-30
Destination
The destination to which the traffic is allowed. The destination can be an IP address or IP address range.
The default value is 0.0.0.0/0, which indicates that traffic to all IP addresses is allowed.
For example:
- xxx.xxx.xxx.xxx/32 (IP address)
- xxx.xxx.xxx.0/24 (IP address range)
- 0.0.0.0/0 (all IP addresses)
0.0.0.0/0
Destination Port Range
The destination port number or port number range. The value ranges from 1 to 65535. For a port number range, enter two port numbers connected by a hyphen (-). For example, 1-100.
You must specify this parameter if TCP or UDP is selected for Protocol.
22, or 22-30
Description
Supplementary information about the network ACL rule. This parameter is optional.
The description can contain a maximum of 255 characters and cannot contain angle brackets (< or >).
N/A
- Click Confirm.
Last Article: Changing the Sequence of a Network ACL Rule
Next Article: Enabling or Disabling a Network ACL Rule
Did this article solve your problem?
Thank you for your score!Your feedback would help us improve the website.