[OPTIONS]
policy_out: REJECT
enable: 1
policy_in: REJECT
OUT SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
IN SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
According to this rule, ssh must only be allowed from source hypervisor to hypervisor set of IP. But it is allowing ssh even to other IP's
Until I replace the rule with the following
OUT SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
OUT SSH(REJECT) -source +hypervisor -log info # SSH
IN SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
policy_out: REJECT
enable: 1
policy_in: REJECT
OUT SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
IN SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
According to this rule, ssh must only be allowed from source hypervisor to hypervisor set of IP. But it is allowing ssh even to other IP's
Until I replace the rule with the following
OUT SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH
OUT SSH(REJECT) -source +hypervisor -log info # SSH
IN SSH(ACCEPT) -source +hypervisor -dest +hypervisor -log info # SSH