Manage port policies

A port policy allows you to control access by only opening specific ports on a host. The system provides the following default port policies, which cannot be edited or deleted.

Restrictions and guidelines

Add a port policy

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click Add.

  1. Configure the parameters as described in "Parameters."

  1. Click OK.

Edit a port policy

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click Edit in the Actions column for a port policy.

  1. Edit the parameters as needed.

  1. Click OK.

Delete a port policy

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click Delete in the Actions column for a port policy.

  1. In the dialog box that opens, click OK.

Delete port policies in bulk

You cannot delete the default service node policy or management node policy.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select the target port policies, and then click Delete on top of the port policy list.

  1. In the dialog box that opens, click OK.

Enable port hardening

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click the toggle button next to Port Hardening.

  1. In the dialog box that opens, click OK.

Disable port hardening

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click the toggle button next to Port Hardening.

  1. In the dialog box that opens, click OK.

Associate a port policy with a host

Perform this task to deploy a port policy to a host and enable the specified ports on that host.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Click Associate Host in the Actions column for a port policy.

  1. Select a host, and then click OK.

Add a host to a port policy

After you add a host to a port policy, the port policy will be applied to that host and the specified ports will be open. You can associate a port policy with all hosts, all management nodes, all service nodes, or the selected hosts.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select a port policy, and then click Add next to the Associated Hosts field.

  1. Select a host, and then click OK.

Remove the association between a host and a port policy

You cannot remove the association between the hosts and their associated default service node policy or management node policy.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select a port policy and then click Remove next to the Associated Hosts field, and then click Remove in the Actions column for a host in the associated host list.

  1. In the dialog box that opens, click OK.

Bulk remove the association between hosts and a port policy

If a port policy is associated with multiple hosts, you can perform this task to bulk remove the association between that port policy and the target hosts. You cannot remove the association between the hosts and their associated default service node policy or management node policy.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select the target port policy, select the target hosts in the associated host list, and then click Remove next to the Associated Hosts field.

  1. In the dialog box that opens, click OK.

Synchronize a port policy to associated hosts

If a port policy changes, you can perform this task to synchronize that policy to the target associated hosts.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select a port policy, select the target hosts in the associated host list, and then click Sync next to the Associated Hosts field.

Repair a host associated with a port policy

Perform this task for the system to re-deploy a port policy to a host if the system fails to deploy the port policy to that host.

  1. On the top navigation bar, click Services.

  1. From the left navigation pane, select Security > Port Policies.

  1. Select a port policy in the port policy list, select a host in the associated host list, and then click Repair next to the Associated Hosts field.

  1. Wait for the system to complete repairing the host. The system will display a message that the target host has been repaired successfully.

Parameters