Updated on 2024-04-18 GMT+08:00

Associating Subnets with a Network ACL

Scenarios

You can associate a network ACL with a subnet to protect resources in the subnet.

Notes and Constraints

  • You can associate a network ACL with multiple subnets. However, a subnet can only be associated with one network ACL at a time.
  • After a network ACL is associated with a subnet, the default network ACL rules deny all traffic to and from the subnet until you add custom rules to allow traffic. For details, see Adding a Network ACL Rule.

Procedure

  1. Log in to the management console.
  1. Click in the upper left corner and choose Network > Virtual Private Cloud.

    The Virtual Private Cloud page is displayed.

  2. Associate a subnet with a network ACL using either of the following methods:
    • Method 1
      1. In the navigation pane on the left, click Subnets.

        The Subnets page is displayed.

      2. In the subnet list, locate the row that contains the subnet and click Associate under the Network ACL column.

        The Associate Network ACL page is displayed.

      3. Select a network ACL from the drop-down list.

        If there is no network ACL, click in the drop-down list to create one.

      4. Click OK.

        The subnet list is displayed. You can view the associated network ACL of the subnet.

    • Method 2
      1. In the navigation pane on the left, choose Access Control > Network ACLs.

        The network ACL list is displayed.

      2. In the subnet list, locate the row that contains the network ACL and click Associate Subnet in the Operation column.

        The Associated Subnets tab is displayed.

      3. On the Associated Subnets tab, click Associate.

        The Associate Subnet dialog box is displayed.

      4. In the Associate Subnet dialog box, select the subnet from the subnet list and click OK.

        In the associated subnet list, you can view all subnets associated with the network ACL.

        A subnet with a network ACL associated will not be displayed in the subnet list of the Associate Subnet dialog box for you to select. If you want to associate such a subnet with another network ACL, you must first disassociate the subnet from the original network ACL.