官术网_书友最值得收藏!

How it works...

We have created a very basic regular contract to provide to another tenant. There are other types of contracts we can create. Taboo contracts are used to deny and log traffic. Like conventional access control lists to deny traffic, these need to come first. An example would be where we are permitting a large number of ports and want to deny one or two particular ports; we would do this with a taboo contract to deny the traffic, created before the regular contract permitting the entire range.

In this recipe, we added a couple of labels. Labels allow us to classify what objects can talk to each other. Label matching is performed first, and if no label matches, then no other contract or filter information is processed. The label-matching attribute can be all, none, at least one, or exactly one.

While filters specify the fields to match on between layer 2 and layer 4, the subject can specify the actual direction of the traffic (unidirectional or bidirectional).

The contract we created was not that exciting but offers a building block onto which we can add more filters.

主站蜘蛛池模板: 吴旗县| 崇明县| 长泰县| 托克逊县| 额尔古纳市| 枣庄市| 肥东县| 江阴市| 峨山| 措勤县| 仁寿县| 象山县| 罗甸县| 澜沧| 武冈市| 集安市| 陆良县| 嘉祥县| 咸阳市| 连江县| 永善县| 柳林县| 习水县| 柳林县| 铜山县| 三门县| 三门峡市| 馆陶县| 彰化市| 任丘市| 岳阳县| 潜江市| 合川市| 祥云县| 海原县| 靖州| 石林| 西和县| 和静县| 哈巴河县| 固原市|