NIFCLOUD ELB uses the common private network

Restrict ELB internal connections to the required networks.

Description

An ELB attached to net-COMMON_PRIVATE uses the shared private network for that connection. Use a dedicated Private LAN when services require separate network boundaries.

Potential impact

Insufficient access controls may leave communication paths to unnecessary systems on the shared network.

Remediation

Attach the required nifcloud_private_lan through the ELB’s network_interface, then verify backend routes and access policies.

Examples

These excerpts change the network attachment and omit VIP and other interface settings. Assess encryption requirements separately for the illustrated HTTP traffic.

Before

hcl
resource "nifcloud_elb" "example" {
  availability_zone = "east-11"
  instance_port     = 80
  protocol          = "HTTP"
  lb_port           = 80

  network_interface {
    network_id = "net-COMMON_PRIVATE"
  }
}

After

hcl
resource "nifcloud_elb" "example" {
  availability_zone = "east-11"
  instance_port     = 80
  protocol          = "HTTP"
  lb_port           = 80

  network_interface {
    network_id = nifcloud_private_lan.main.id
  }
}

References