Overview
Global Accelerator 2.0 (GA2.0) allows you to set the security access policies to control public network access permissions for acceleration instances, improving the security of network access. You can restrict access to traffic based on the source IP address, protocol, and port.
GA2.0 does not control the client traffic by default. You need to enable this feature on the access control tab.
To enable the feature, you need to select the default handling policy. The feature allows or denies all traffic to a GA2.0 instance and allows you to use an access rule for further control.
Managing an Access Control Policy
Prerequisites
You have created a GA2.0 instance.
Creating an Access Control Policy
2. On the instance list page, click the target instance ID and go to the instance details page.
3. Click the Access Control tab and go to the access control configuration page.
4. Click Create Access Control Policy, select the default handling policy, and complete the creation of the access control policy.
5. Click the Status switch to enable the control policy.
Creating an Access Rule
2. On the instance list page, click the target instance ID and go to the instance details page.
3. Click the Access Control tab and go to the access control configuration page.
4. Click Add Rule and configure the access rule in the pop-up window.
Configuration Item | Description |
Source IP Address | The client traffic source IP address. It can be in one of the following formats: Single IP address: 192.168.0.1 CIDR: 192.168.1.0/24 |
Protocol | The client source protocol. It can be TCP or UDP. |
Protocol Port | The source protocol port. It can be in one of the following formats: Single port: 80 Multiple ports: 80 and 443 Consecutive ports: 3306–20000 All ports: ALL |
Policy | Allow: GA2.0 allows traffic that hits the rule. Deny: GA2.0 denies access to traffic that hits the rule. |
Remarks | The rule remarks. It is not required. |
5. Click OK to complete the rule configuration.
Editing a Rule
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click Access Control and go to the access control configuration page.
4. On the right side of an existing rule, click Edit.
5. Complete the corresponding configuration in the pop-up window and click OK to complete the editing.
Deleting a Rule
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click Access Control and go to the access control configuration page.
4. Select the rule to be deleted and click Delete.
5. In the pop-up window, click OK to complete the deletion.
Deleting an Access Control Policy
2. On the instance list page, click the target instance ID and go to the instance details page.
3. On the listener tab, click Access Control and go to the access control configuration page.
4. Click Delete on the right side of an access control policy and click OK in the pop-up window to complete the deletion.
Attention:
After the policy is deleted, all access rules are correspondingly deleted, and GA2.0 will no longer perform access control over business traffic. Fully confirm the impact before the deletion.