Private networks and Partner POPs
Network ACLs and presets
ACL rules are ordered, versioned, and synchronized to attached POPs.
#Overview
ACL rules are ordered, versioned, and synchronized to attached POPs.
#Explicit policy per flow
ACLs identify source, destination, protocol, ports, action, order, and state. Presets create a coherent set of rules but still require review before activation.
Every change increments policy and must synchronize to affected POP profiles. A disabled rule remains visible for audit but no longer permits traffic. Put precise exceptions before broad rules.
#Change a policy
Map the minimum required flow.
Add or update the rule and its order.
Review the full result, not only the new line.
Synchronize POPs and test one allowed and one denied flow.
#Permissions by role
| Action | owner | admin | member | viewer |
|---|---|---|---|---|
| View networks, peers, ACLs, origins, and POPs | Read | Read | Read | Read |
| Create, edit, or delete a network | Allowed | Allowed | Allowed | No |
| Manage peers, enrollment keys, and ACLs | Allowed | Allowed | Allowed | No |
| Link zones, private origins, and POPs | Allowed | Allowed | Allowed | No |