Repository navigation
Support Destination CIDR #8864
Description
Activity
not sure if this would be UI only or even API would be enough. sounds complicated.
This is a bit complicated but a valid request.
For this we need to add changes through the whole system: in the- VR scripts
- backend command(s)
- DB
- virtual appliance managers
- service
- API
- and finally in the UI
It is not a very complicated addition but requires quite some knowledge af the system.
and extra consideration is that the destination ip (as soon as the packet has entered the VR) is no longer the public ip, so destination can become a bit ambiguous. I suggest we limit this functionality to only apply to the private addresses of the VMs.
Yes maybe we can limit it to Private Adresses for the time being and see how it goes. This is also to limit the blast radius of bugs due to the big change.
Reacted by dahn12 remaining items
Hi @weizhouapache , this should work well for us.
For context, we use Autoscale Groups as internal load balancers, which should not be exposed to the internet. Currently, CloudStack requires a load balancer to have a Public IP.
Adding a firewall rule in front of the Public IP to restrict access to private IP ranges is a good workaround.
Long term, it would be better if CloudStack supports load balancers using Private IPs only. This reduces reliance on public IPs, lowers cost, and minimizes security risks from misconfiguration.ges.
I think in the long term, CS should be enhanced to support creating Load Balancers without Public IP (using Private IP Instead). This is to reduce the cost of having to acquire many public IPs and risk security issues from misconfigurations.
Yup @weizhouapache its a workaround we can work with at the moment.
This issue is stale because it has been open for 120 days with no activity. It may be removed by administrators of this project at any time. Remove the stale label or comment to request for removal of it to prevent this.
ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATION
N/A
OS / ENVIRONMENT
N/A
SUMMARY
Note: This ticket is broken down as requested from the origianl post, #8841
Support Destination CIDR
STEPS TO REPRODUCE
N/A
EXPECTED RESULTS
ACTUAL RESULTS