Changed documentation to better show what can be done with firewall rules

This commit is contained in:
Brett Mack 2015-11-10 22:49:38 +00:00
parent a15c99e5bb
commit a05ff89a7d
1 changed files with 25 additions and 5 deletions

View File

@ -19,13 +19,13 @@ resource "vcd_firewall_rules" "fw" {
default_action = "drop" default_action = "drop"
rule { rule {
description = "allow-web" description = "deny-ftp-out"
policy = "allow" policy = "deny"
protocol = "tcp" protocol = "tcp"
destination_port = "80" destination_port = "21"
destination_ip = "10.10.0.5" destination_ip = "any"
source_port = "any" source_port = "any"
source_ip = "any" source_ip = "10.10.0.0/24"
} }
rule { rule {
@ -39,6 +39,26 @@ resource "vcd_firewall_rules" "fw" {
} }
} }
resource "vcd_vapp" "web" {
...
}
resource "vcd_firewall_rules" "fw-web" {
edge_gateway = "Edge Gateway Name"
default_action = "drop"
rule {
description = "allow-web"
policy = "allow"
protocol = "tcp"
destination_port = "80"
destination_ip = "${vcd_vapp.web.ip}"
source_port = "any"
source_ip = "any"
}
}
``` ```
## Argument Reference ## Argument Reference