The ANS distributed firewall supports three types of policies to control the ingress and egress traffic of virtual machines: global security policy, custom security policy, and VM quarantine. The custom security policy can also control the ingress and egress traffic of IP addresses and Pods. For the global security policy, each custom security policy, and quarantined virtual machines, you can also choose whether to enable security policy logging individually. With these capabilities, the ANS distributed firewall provides workloads with more flexible and fine-grained network security protection.