Skip to content

Support Destination CIDR #8864

Description

@btzq
ISSUE TYPE
  • Improvement Request
COMPONENT NAME
Improvement Request (UI, Functionality)
CLOUDSTACK VERSION
4.19
CONFIGURATION

N/A

OS / ENVIRONMENT

N/A

SUMMARY

Note: This ticket is broken down as requested from the origianl post, #8841

Support Destination CIDR

  • Reduces number of ACL Rules required
  • Adds more security
  • Makes ACL rule function more complete
STEPS TO REPRODUCE

N/A

N/A
EXPECTED RESULTS
To be able to manage ACL Rules more easily for large scale projects
ACTUAL RESULTS
Challenging to use ACL rules for large scale projects.

Activity

  1. DaanHoogland commented on Apr 2, 2024

    @DaanHoogland
    Contributor

    not sure if this would be UI only or even API would be enough. sounds complicated.

  2. DaanHoogland commented on Apr 11, 2024

    @DaanHoogland
    Contributor

    This is a bit complicated but a valid request.
    For this we need to add changes through the whole system: in the

    • VR scripts
    • backend command(s)
    • DB
    • virtual appliance managers
    • service
    • API
    • and finally in the UI
      It is not a very complicated addition but requires quite some knowledge af the system.

    and extra consideration is that the destination ip (as soon as the packet has entered the VR) is no longer the public ip, so destination can become a bit ambiguous. I suggest we limit this functionality to only apply to the private addresses of the VMs.

  3. btzq commented on Apr 12, 2024

    @btzq
    Author

    Yes maybe we can limit it to Private Adresses for the time being and see how it goes. This is also to limit the blast radius of bugs due to the big change.

  4. added this to the 4.20.0.0 milestone on May 31, 2024
  5. modified the milestones: 4.20.0.0, 4.21.0.0 on Sep 10, 2024
  6. 12 remaining items

  7. weizhouapache commented on Mar 11, 2026

    @weizhouapache
    Member

    @btzq
    there is a PR in progress: #12706

    Can it be used to solve your problem ?

  8. btzq commented on Mar 31, 2026

    @btzq
    Author

    Hi @weizhouapache , this should work well for us.

    For context, we use Autoscale Groups as internal load balancers, which should not be exposed to the internet. Currently, CloudStack requires a load balancer to have a Public IP.

    Adding a firewall rule in front of the Public IP to restrict access to private IP ranges is a good workaround.

    Long term, it would be better if CloudStack supports load balancers using Private IPs only. This reduces reliance on public IPs, lowers cost, and minimizes security risks from misconfiguration.ges.

    I think in the long term, CS should be enhanced to support creating Load Balancers without Public IP (using Private IP Instead). This is to reduce the cost of having to acquire many public IPs and risk security issues from misconfigurations.

  9. weizhouapache commented on Mar 31, 2026

    @weizhouapache
    Member

    @btzq

    there is a PR in progress: #12706
    will it solve your original issue (Support Destination CIDR) ?

  10. btzq commented on Mar 31, 2026

    @btzq
    Author

    Yup @weizhouapache its a workaround we can work with at the moment.

  11. modified the milestones: 4.22.1, 4.23.0 on Apr 24, 2026
  12. modified the milestones: 4.23.0, 4.24.0 on May 21, 2026
  13. github-actions commented on Sep 21, 2026

    @github-actions

    This issue is stale because it has been open for 120 days with no activity. It may be removed by administrators of this project at any time. Remove the stale label or comment to request for removal of it to prevent this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions