官术网_书友最值得收藏!

How it works...

We have created a very basic regular contract to provide to another tenant. There are other types of contracts we can create. Taboo contracts are used to deny and log traffic. Like conventional access control lists to deny traffic, these need to come first. An example would be where we are permitting a large number of ports and want to deny one or two particular ports; we would do this with a taboo contract to deny the traffic, created before the regular contract permitting the entire range.

In this recipe, we added a couple of labels. Labels allow us to classify what objects can talk to each other. Label matching is performed first, and if no label matches, then no other contract or filter information is processed. The label-matching attribute can be all, none, at least one, or exactly one.

While filters specify the fields to match on between layer 2 and layer 4, the subject can specify the actual direction of the traffic (unidirectional or bidirectional).

The contract we created was not that exciting but offers a building block onto which we can add more filters.

主站蜘蛛池模板: 错那县| 额尔古纳市| 德令哈市| 淳安县| 乌鲁木齐市| 和平区| 家居| 聂荣县| 宁远县| 庆云县| 白沙| 祁阳县| 吕梁市| 余庆县| 比如县| 卢龙县| 什邡市| 遵化市| 遂昌县| 巫溪县| 通辽市| 赤峰市| 阜新市| 蒙城县| 梁平县| 北海市| 扎囊县| 三台县| 汕头市| 牡丹江市| 金山区| 黄山市| 大同县| 古交市| 交口县| 彰化市| 霍城县| 峨边| 哈密市| 金昌市| 八宿县|