API Doc
Search Docs...
⌘ K
ACOSABSAVEANSABDR

Global security policies

The global security policy can be divided into deny communication by default and the global allowlist.

Deny communication by default

The deny communication by default policy applies to virtual machines whose VM networks all belong to VDS instances associated with the ANS service, provided those virtual machines are not specified as objects of any custom security policy and are not quarantined. When not all VDS instances that a virtual machine's VM networks belong to are associated with the ANS service, the policy takes effect only on the VM networks that have been associated with that ANS service. Whether to enable this policy can be configured per ANS service.

Global allowlist

To ensure normal communication between services deployed outside the data center (such as bastion hosts) and virtual machines inside the data center, the ANS distributed firewall supports configuring a global allowlist. The global allowlist does not apply to virtual machines that have a quarantine policy in effect.

  • If a strict quarantine or forensic quarantine policy is applied to a virtual machine, the global allowlist will be inactive, and only the strict quarantine or forensic quarantine policy will apply.

  • If a virtual machine has only custom security policies applied, those policies will take effect first, followed by the global allowlist, ensuring that IP addresses on the allowlist can communicate with the virtual machine.