Description
An ELB attached to net-COMMON_PRIVATE uses the shared private network for that connection. Use a dedicated Private LAN when services require separate network boundaries.
Potential impact
Insufficient access controls may leave communication paths to unnecessary systems on the shared network.
Remediation
Attach the required nifcloud_private_lan through the ELB’s network_interface, then verify backend routes and access policies.
Examples
These excerpts change the network attachment and omit VIP and other interface settings. Assess encryption requirements separately for the illustrated HTTP traffic.
Before
hcl
resource "nifcloud_elb" "example" {
availability_zone = "east-11"
instance_port = 80
protocol = "HTTP"
lb_port = 80
network_interface {
network_id = "net-COMMON_PRIVATE"
}
}
After
hcl
resource "nifcloud_elb" "example" {
availability_zone = "east-11"
instance_port = 80
protocol = "HTTP"
lb_port = 80
network_interface {
network_id = nifcloud_private_lan.main.id
}
}