KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I have set up an Amazon Virtual Private Cloud (VPC). Inside the VPC I have 2 networks in which I create instances. For security reasons I want to put some network access control lists (Network ACL) on those networks, besides the machines firewall. Following the Amazon example I have a public network (exposed to internet access) 10.0.0.0/24 and 3 private network 10.0.1.0/24, 10.0.2.0/24, 10.0.3.0/24. The traffic between them is routed. So for the network 10.0.1.0/24 as ACL's I put this: Inbound: 10.0.0.0/24 port 80 (HTTP) 10.0.0.0/24 port 22 (SSH) 10.0.2.0/24 port 3306 (MySql) 10.0.3.0/24 port 3306 (MySql) Outbound ALL ALL For the networks 10.0.2.0/24 and 10.0.3.0/24: Inbound 10.0.1.0/24 port 3306 (MySql) Outbound ALL ALL For the public network 10.0.0.0/24 in here I have an exposed load balancer, which is redirecting traffic to the private network 10.0.1.0/24, where an app is responding over HTTP: Inbound 0.0.0.0/0 port 80 (HTTP) 0.0.0.0/0 port 443 (HTTPS) 0.0.0.0/0 port 22 (SSH) Outbound ALL ALL The problem is, when I put those rules in action, all traffic freezes and the app is not available. What's happening? Am I doing something wrong?
Tags (comma-separated)
Save Edits
Cancel