Manage ACLs

An access control list (ACL) is a set of rules for identifying traffic based on criteria such as source IP address, destination IP address, and port number. The rules are also called permit or deny statements.

You can configure ACLs to limit network access to VMs and improve security of the services running on the VMs.

Restrictions and guidelines

Only security administrators can configure this feature.

ACLs that are used by port profiles cannot be deleted.

To add a global ACL rule, leave the MAC address, MAC address mask, IPv4 address, subnet mask, IPv6 address, and network prefix empty.

Add an ACL

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Click Add.

  1. Enter a name and a description for the ACL, select the default inbound action, default outbound action, ACL type, and owner. For more information about the parameters, see "Parameters."

  1. Configure whether to configure the ACL as a time-based ACL. If yes, specify the time when the ACL takes effect.

  1. Click Add to add a rule for the ACL and configure the parameters as described in "Parameters."

  1. To change the priorities of the ACL rules, click Edit Rule Priorities, drag the rules to arrange their orders, and then click OK.

  1. Click OK.

Edit an ACL

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select the target ACL and click Edit.

  1. Configure the rules for the ACL and configure the priorities for the rules as described in "Parameters."

  1. Click OK.

Convert private ACLs to public ACLs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select the target ACLs and click Convert to Public Policy.

  1. In the dialog box that opens, click OK.

Copy ACLs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select the target ACLs and click Copy.

  1. In the dialog box that opens, configure the parameters and then click OK.

Delete ACLs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select the target ACLs and click Delete.

  1. In the dialog box that opens, click OK.

Filter ACLs

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select Private, Public, or All from the Used By field to filter ACLs by owner.

Display detailed information about an ACL

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > ACLs.

  1. Select the target ACL and click View.

Parameters

If you select IP for the ACL Type parameter, configure the following parameters:

If you select Layer 2 for the ACL Type parameter, configure the following parameters: