Description
A NAS instance with network_id set to net-COMMON_PRIVATE connects to the shared private network. A dedicated Private LAN for its clients can narrow the network access boundary.
Potential impact
Loose NAS access controls may expose a path to files from systems that do not need access.
Remediation
Assign an appropriate nifcloud_private_lan and permit only required clients through NAS security groups and file-share permissions. Check existing mounts after the change.
Examples
These excerpts change the NAS network and omit LAN and client-access settings. Apply file permissions together with network isolation.
Before
hcl
resource "nifcloud_nas_instance" "example" {
identifier = "nas001"
allocated_storage = 100
protocol = "nfs"
type = 0
network_id = "net-COMMON_PRIVATE"
}
After
hcl
resource "nifcloud_nas_instance" "example" {
identifier = "nas001"
allocated_storage = 100
protocol = "nfs"
type = 0
network_id = nifcloud_private_lan.main.id
}