BMS Instances Should Not Be Publicly Accessible
Rule Details
|
Parameter |
Description |
|---|---|
|
Rule Name |
bms-instance-no-public-ip |
|
Identifier |
BMS Instances Should Not Be Publicly Accessible |
|
Description |
If a BMS instance has an EIP attached, this instance is non-compliant. |
|
Tag |
bms |
|
Trigger Type |
Configuration change |
|
Filter Type |
bms.servers |
|
Rule Parameters |
None |
Application Scenarios
Huawei Cloud BMSs may contain sensitive information. If your services do not need to interact with the public network, do not expose BMSs to the public network.
Solution
Check whether your BMSs require EIPs. If it is not necessary, unbind an EIP from a BMS.
If you need public network access, use alternatives such as load balancers, NAT gateways, and VPNs. They can meet your network requirements while reducing costs and risks.
Rule Logic
- If a BMS has an EIP attached, this instance is non-compliant.
- If a BMS does not have an EIP attached, this instance is compliant.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot