Re: source IP restriction on routes

2016-10-17 Thread Ram Ranganathan
*Sorry for the duplicate email Sebastian - the users list rejected the original mail* You would need a customized haproxy config template but you could add something like this in the 2 frontends public[_ssl] (or to specific backends if you need more granular control on a per-backend basis): acl a

Re: source IP restriction on routes

2016-10-17 Thread Frederic Giloux
Hi Sebastian Depending on the granularity you want you can deploy your routers on different nodes, group your routes according to the IPs you want to provide access from and configure IPtables accordingly. For a finer, app specific control you may want to look at network policies but they are st

source IP restriction on routes

2016-10-17 Thread Sebastian Wieseler
Hi guys, Is it possible with router (s, sharding) to restrict access on IP level? We want to expose various applications via various routers, but restrict access via source IP addresses, so that different source IP addresses can only access allowed applications. How can we do that? Thanks a lot