API Doc
Search Docs...
⌘ K
ACOSABSAVEANSABDR
  • ANS distributed firewall technical whitepaper

Distributed firewall policies

ANS supports three types of distributed firewall policies: global security policy, custom security policy, and VM quarantine. The custom security policy includes deny policy and allow policy, while the global security policy covers global allowlist and deny communication by default. For these policies to take effect, both the cluster where the virtual machine resides and the VDS to which the VM network belongs must be associated with the ANS service. Custom security policies can be applied to Pods through Pod security groups. Pods must use the AIC, and the VDS that the node's dedicated AIC's VM network belongs to must also be associated with the ANS service.

If the ANS distributed firewall is associated with an observability service, you can check security policy effectiveness through security policy hit counts and security policy logs.

The priority in which the above policies are applied to virtual machines and Pods, from highest to lowest, is: VM quarantine policy > custom security policy (deny policy) > custom security policy (allow policy) = global allowlist > deny communication by default. The following diagram illustrates the policy priority.