Configuring a Network Defense Policy (for a VPC Network)
Scenarios
If no network defense policies are configured for a pod, all traffic is allowed to enter and leave the pod by default. In this case, pods can communicate with each other and access the external network, which poses security risks.
This section describes how to configure network defense policies for clusters using the VPC network model to control the inbound and outbound traffic of nodes, thereby enhancing cluster network security.
Creating a Network Defense Policy
- Log in to the management console.
- In the upper left corner of the page, select a region, click
, and choose Security & Compliance > Host Security Service.
- In the navigation pane on the left, choose .
- (Optional) If you have enabled the enterprise project, select the enterprise project where the target server resides from the drop-down list.
- Click Synchronize above the cluster list to synchronize the policies created on clusters.
The synchronization takes about 1 to 2 minutes. Wait for a while and click
in the upper right corner of the list to refresh and view the latest data.
Figure 1 Synchronizing cluster policies
- Click Manage Policy in the Operation column of a cluster using the VPC network model.
- In the Operation column of a node, click Configure Policy.
- In the displayed dialog box, click OK to go to the cloud server console.
- Click the Security Groups tab and view security group rules.
- Click Manage Rule. The security group page is displayed.
- Configure inbound and outbound rules.
For details, see Adding a Security Group Rule.
Related Operations
Modifying or deleting a network defense policy
- (Optional) If you have enabled the enterprise project, select the enterprise project where the target server resides from the drop-down list.
- Click Manage Policy in the Operation column of a cluster using the VPC network model.
- Click Synchronize above the node list to synchronize node information.
The synchronization takes about 1 to 2 minutes. Wait for a while and click
in the upper right corner of the list to refresh and view the latest data.
- In the Operation column of a node, click Configure Policy.
- In the displayed dialog box, click OK to go to the cloud server console.
- Click the Security Groups tab and view security group rules.
- Click Manage Rule. The security group page is displayed.
- Click a rule tab and manage rules as needed.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot