cluster 集群节点安全问题 #1334
Answered
by
cloudwu
JieTrancender
asked this question in
Q&A
cluster 集群节点安全问题
#1334
-
我们集群使用cluster构建,最近发现一直有人尝试连接我们用于集群通信的端口,想通过clustername配置白名单方式限制,请问一下这样做会不会有什么问题? |
Beta Was this translation helpful? Give feedback.
Answered by
cloudwu
Jan 26, 2021
Replies: 2 comments 2 replies
-
建议使用系统的防火墙,限定白名单 ip 才能互通。 |
Beta Was this translation helpful? Give feedback.
1 reply
-
在业务层做肯定不如专门的防火墙。即使不用系统级的防火墙,你也可以在 cluster 外套一个你自己的防火墙网关,转发到本地 cluster 端口。我觉得防火墙业务不应该加到 cluster 服务中。 |
Beta Was this translation helpful? Give feedback.
1 reply
Answer selected by
JieTrancender
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
在业务层做肯定不如专门的防火墙。即使不用系统级的防火墙,你也可以在 cluster 外套一个你自己的防火墙网关,转发到本地 cluster 端口。我觉得防火墙业务不应该加到 cluster 服务中。