Files
doc-exports/docs/dcs/umn/dcs-ug-190812001.html
Chen, Junjie 3de6842994 DCS UMN 20240521 version
Reviewed-by: Mützel, Andrea <andrea.muetzel@t-systems.com>
Co-authored-by: Chen, Junjie <chenjunjie@huawei.com>
Co-committed-by: Chen, Junjie <chenjunjie@huawei.com>
2024-07-05 08:59:46 +00:00

47 lines
6.8 KiB
HTML

<a name="dcs-ug-190812001"></a><a name="dcs-ug-190812001"></a>
<h1 class="topictitle1">Managing IP Address Whitelist</h1>
<div id="body8662426"><p id="dcs-ug-190812001__en-us_topic_0185207715_p1141917481487">DCS helps you control access to your DCS instances in the following ways, depending on the deployment mode:</p>
<ul id="dcs-ug-190812001__en-us_topic_0185207715_ul659018528500"><li id="dcs-ug-190812001__en-us_topic_0185207715_li45901952195020">To control access to DCS Redis 3.0 instances, you can use security groups. Whitelists are not supported. For details about how to configure a security group, see <a href="en-us_topic_0090662012.html">Security Group Configurations</a>.</li><li id="dcs-ug-190812001__en-us_topic_0185207715_li759018524509">To control access to DCS Redis 4.0/5.0/6.0 instances, you can use whitelists. Security groups are not supported.</li></ul>
<p id="dcs-ug-190812001__en-us_topic_0185207715_p562477191713">The following describes how to manage whitelists of a Redis 4.0/5.0/6.0 instance to allow access only from whitelisted IP addresses. If no whitelists are added for the instance or the whitelist function is disabled, all IP addresses that can communicate with the VPC can access the instance.</p>
<div class="section" id="dcs-ug-190812001__en-us_topic_0185207715_section91321125523"><h4 class="sectiontitle">Creating a Whitelist Group</h4><ol id="dcs-ug-190812001__en-us_topic_0185207715_ol11505125465320"><li id="dcs-ug-190812001__en-us_topic_0185207715_li68751861819"><span>Log in to the DCS console.</span></li><li id="dcs-ug-190812001__li1012324113597"><span>Click <span><img id="dcs-ug-190812001__image198883063720" src="en-us_image_0000001681129365.png"></span> in the upper left corner and select a region and a project.</span></li><li id="dcs-ug-190812001__en-us_topic_0185207715_li9949524104617"><span>In the navigation pane, choose <strong id="dcs-ug-190812001__en-us_topic_0185207715_b2240007119922">Cache Manager</strong>.</span></li><li id="dcs-ug-190812001__en-us_topic_0185207715_li19501824184620"><span>Click the name of a DCS instance.</span></li><li id="dcs-ug-190812001__en-us_topic_0185207715_li34099825515"><span>Choose <strong id="dcs-ug-190812001__b146121952143617">Instance Configuration</strong> &gt; <strong id="dcs-ug-190812001__b361310522368">Whitelist</strong> and then click <strong id="dcs-ug-190812001__b101971040163116">Create Whitelist Group</strong>.</span></li><li id="dcs-ug-190812001__en-us_topic_0185207715_li6504736560"><span>In the <strong id="dcs-ug-190812001__en-us_topic_0185207715_b1937637357">Create Whitelist Group</strong> dialogue box, specify <strong id="dcs-ug-190812001__en-us_topic_0185207715_b166631116113518">Group Name</strong> and <strong id="dcs-ug-190812001__en-us_topic_0185207715_b14421142113516">IP Address/Range</strong>.</span><p>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="dcs-ug-190812001__en-us_topic_0185207715_table15702121165717" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Whitelist parameters</caption><thead align="left"><tr id="dcs-ug-190812001__en-us_topic_0185207715_row1670432105716"><th align="left" class="cellrowborder" valign="top" width="21.04%" id="mcps1.3.4.2.6.2.1.2.4.1.1"><p id="dcs-ug-190812001__en-us_topic_0185207715_p1970418213577">Parameter</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="28.63%" id="mcps1.3.4.2.6.2.1.2.4.1.2"><p id="dcs-ug-190812001__en-us_topic_0185207715_p197041921165718">Description</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="50.33%" id="mcps1.3.4.2.6.2.1.2.4.1.3"><p id="dcs-ug-190812001__en-us_topic_0185207715_p62470373579">Example</p>
</th>
</tr>
</thead>
<tbody><tr id="dcs-ug-190812001__en-us_topic_0185207715_row14704421125713"><td class="cellrowborder" valign="top" width="21.04%" headers="mcps1.3.4.2.6.2.1.2.4.1.1 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p4704821185715">Group Name</p>
</td>
<td class="cellrowborder" valign="top" width="28.63%" headers="mcps1.3.4.2.6.2.1.2.4.1.2 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p16704721185713">Whitelist group name of the instance.</p>
<p id="dcs-ug-190812001__en-us_topic_0185207715_p141774169153">A maximum of four whitelist groups can be created for each instance.</p>
</td>
<td class="cellrowborder" valign="top" width="50.33%" headers="mcps1.3.4.2.6.2.1.2.4.1.3 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p182471437135714">DCS-test</p>
</td>
</tr>
<tr id="dcs-ug-190812001__en-us_topic_0185207715_row19704162112571"><td class="cellrowborder" valign="top" width="21.04%" headers="mcps1.3.4.2.6.2.1.2.4.1.1 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p67041121155711">IP Address/Range</p>
</td>
<td class="cellrowborder" valign="top" width="28.63%" headers="mcps1.3.4.2.6.2.1.2.4.1.2 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p270482117577">A maximum of 20 IP addresses or IP address ranges can be added to an instance. Separate multiple IP addresses or IP address ranges with commas.</p>
<p id="dcs-ug-190812001__en-us_topic_0185207715_p5215551897">Unsupported IP address and IP address range: 0.0.0.0 and 0.0.0.0/0.</p>
</td>
<td class="cellrowborder" valign="top" width="50.33%" headers="mcps1.3.4.2.6.2.1.2.4.1.3 "><p id="dcs-ug-190812001__en-us_topic_0185207715_p142481837165716">10.10.10.1,10.10.10.10</p>
</td>
</tr>
</tbody>
</table>
</div>
</p></li><li id="dcs-ug-190812001__en-us_topic_0185207715_li1974811372039"><span>Click <strong id="dcs-ug-190812001__en-us_topic_0185207715_b106262010143813">OK</strong>.</span><p><p id="dcs-ug-190812001__en-us_topic_0185207715_p158663218168">A whitelist group is automatically enabled for the instance once created. Only whitelisted IP addresses can access the instance.</p>
<div class="note" id="dcs-ug-190812001__en-us_topic_0185207715_note19324571648"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><ul id="dcs-ug-190812001__en-us_topic_0185207715_ul1275311554218"><li id="dcs-ug-190812001__en-us_topic_0185207715_li147534555213">In the whitelist group list, click <strong id="dcs-ug-190812001__en-us_topic_0185207715_b984053712398">Modify</strong> to modify the IP addresses or IP address ranges in a group, and click <strong id="dcs-ug-190812001__en-us_topic_0185207715_b529513610404">Delete</strong> to delete a whitelist group.</li><li id="dcs-ug-190812001__en-us_topic_0185207715_li1558257523">After whitelist has been enabled, you can click <strong id="dcs-ug-190812001__en-us_topic_0185207715_b1282043913408">Disable Whitelist</strong> above the whitelist group list to allow all IP addresses connected to the VPC to access the instance.</li></ul>
</div></div>
</p></li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="dcs-ug-0312022.html">Managing DCS Instances</a></div>
</div>
</div>