Network Access Control for application instances
Network access control is a security feature that restricts network access to services running inside application instances. By allowing access only through specified ports and an allowable IP/CIDR list, network access control minimizes attack exposure and ensures that only trusted sources can communicate with NetBackup instances. The network access control settings apply at the instance level and are enforced through firewall rules. The updated network access control details are saved in a dedicated network access control settings file for each instance. This ensures centralized management of network access control settings for each instance and controlled administration using role-based permissions.
Prerequisites:
Appropriate role permissions for managing network access control settings.
You can assign network access control-related permissions when creating custom roles.
To create custom role with network access control-related permissions
- Click the Access management icon in the left-side navigation bar to open theAccess management page.
- Go to the Roles page and click Create role.
- In the Create custom role window:
Enter the role name and description.
Under Applications, select Network access control.
Select the required permissions.
- Click Review.
- In the Permissions for the role popup, review the permissions and click Create.
Use the following procedure to configure network access control for a service.
To configure network access control for services
- From the System topology page of the Flex Appliance console, go to Application instances.
- Select the instance to open the detail page. Select the Network access control tab.
- Click Add service.
- In the Add service window, enter the required details:
Service name: Enter the name of the service.
Ports and protocols: Enter ports or ports and protocols in a comma-separated list.
Use
port/protocolformat (for example: 443/tcp).Supported protocols: tcp (default) and udp.
Click Add.
Note:
Ports and protocols cannot be updated after the service is added.
Allowed list: Enter IP addresses or subnets in a comma-separated list.
Click Add.
Description: (Optional) Provide a brief description.
- Click Add.
The instance details page will list the newly added service.
You can edit or delete the service by selecting the service and navigating to or .
If network access control settings fail during instance startup, an SMTP/SNMP alert is generated to notify administrators.
The network access control rules apply only to inward network traffic to application instances.
Select if you want to apply the firewall settings to the instance. Unselect this option when you want to clear the firewall settings.
If you configure network access control on an application in which IRE is also configured, a combination of firewall rules from both the settings will be applied.
The Instance details page displays the firewall table rules currently applied to the instance.
Click next to to review the configuration and identify the network access control settings file.
You can find the logs at
/var/log/application/instance-nac-<instance-id>.logif the connection is rejected by network access control.If the WORM instance version is 21.1.0.2 and later and if the primary and media server version are 11.1.0.2 and later, the default services to which you can add network access control are listed in the tab