4 ms·
There is no Security Group for NLB, how is that reasoned?
by stelund 9y ago
There is no Security Group for NLB, how is that reasoned?
- jdc0589 9y agothat threw me for a bit of a loop as well. This means that responsibility for doing ACL whitelisting at the edge is now moved from the actual edge, to the security groups on the actual servers responding to request, right? That's do-able and all, but I kind of didn't hate the old paradigm of having an extra layer there.
- colmmacc 9y agoOne way to think of NLB is that it's an Elastic IP address that happens to go to multiple instances or containers, instead of just one. Everything else stays the same.
- stelund 9y agoYeh, it's easy to use it like that for now. I hope they update it later on though. Seems like an missing feature in their otherwise nice firewall rules setup.