VMware Networking Community
vSohill
Expert
Expert
Jump to solution

Security Groups

Hi,

If i have 2 security groups SGAppParent and SGWebParent. In SGAppParent I create it security group1 SGApp1,SGApp2 ,the same under SGWebParent there are SGWeb1 SGWeb2.

SGApp1 must talk with SGWeb1 and no communication between SGApp1,SGApp2 .Same rules for the rest SGWeb2 communicate with SGApp2. No communication between the VMs in their parent group. I set the rules as follows :

Source                              Destination                                service                          action                applied to

ExternalSGWebParent      http,https      allow      SGwebParent
SGApp1SGWeb1https,https,..allowSGApp1 SGWeb1
SGApp2SGWeb2https,httpsAllow

SGApp1 SGApp2

SGAppParentanyanyblockSGAppParent
SGwebParentanyanyblockSGWebParent

Do I need to add more rules to block cummunications between Web1 and Web2 and between App1 and App2 ?

Is there a bitter way ?

thank you

Reply
0 Kudos
1 Solution

Accepted Solutions
chrisgnoon
Enthusiast
Enthusiast
Jump to solution

Ensure the default firewall rule is any/any deny.  Then all you need to do is permit the traffic you want to allow.

Therefore this is all that would be needed.

SGApp1SGWeb1https,https,..allowSGApp1 SGWeb1
SGApp2SGWeb2https,httpsallow

SGApp1 SGApp2

I assume the red highlighted should read "SGApp2 SGWeb2"

Chris Noon | CCDP | CCNP | VCDX 289
Don't forget to mark as solved if your questions are answered.

View solution in original post

Reply
0 Kudos
1 Reply
chrisgnoon
Enthusiast
Enthusiast
Jump to solution

Ensure the default firewall rule is any/any deny.  Then all you need to do is permit the traffic you want to allow.

Therefore this is all that would be needed.

SGApp1SGWeb1https,https,..allowSGApp1 SGWeb1
SGApp2SGWeb2https,httpsallow

SGApp1 SGApp2

I assume the red highlighted should read "SGApp2 SGWeb2"

Chris Noon | CCDP | CCNP | VCDX 289
Don't forget to mark as solved if your questions are answered.
Reply
0 Kudos