Network Security Groups
Bare minimum of IaaS deployment consists of virtual machines and virtual networks. The virtual machines might be exposed to the internet by applying a public IP to its network interface or it might be available to internal resources only. The internal resources in turn might be exposed to the internet. In any case, virtual machines should be secured such that unauthorized requests should not even reach them. Virtual machines should be secured using facilities that can filter requests at the network itself rather than them reaching virtual machine and it taking action on them. This is such as creating a ring-fence around virtual machines. This fence can allow or deny requests based on their protocol, origin IP, destination ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access