| <?xml version='1.0' encoding='utf-8' ?> |
| <!DOCTYPE section PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN" "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [ |
| <!ENTITY % BOOK_ENTITIES SYSTEM "cloudstack.ent"> |
| %BOOK_ENTITIES; |
| ]> |
| |
| <!-- Licensed to the Apache Software Foundation (ASF) under one |
| or more contributor license agreements. See the NOTICE file |
| distributed with this work for additional information |
| regarding copyright ownership. The ASF licenses this file |
| to you under the Apache License, Version 2.0 (the |
| "License"); you may not use this file except in compliance |
| with the License. You may obtain a copy of the License at |
| |
| http://www.apache.org/licenses/LICENSE-2.0 |
| |
| Unless required by applicable law or agreed to in writing, |
| software distributed under the License is distributed on an |
| "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY |
| KIND, either express or implied. See the License for the |
| specific language governing permissions and limitations |
| under the License. |
| --> |
| <section id="shared-networks"> |
| <title>Shared Networks</title> |
| <para>A shared network can be accessed by virtual machines that belong to many different accounts. |
| Network Isolation on shared networks is accomplished by using techniques such as security |
| groups, which is supported only in Basic zones in &PRODUCT; 3.0.3 and later versions.</para> |
| <itemizedlist> |
| <listitem> |
| <para>Shared Networks are created by the administrator</para> |
| </listitem> |
| <listitem> |
| <para>Shared Networks can be designated to a certain domain</para> |
| </listitem> |
| <listitem> |
| <para>Shared Network resources such as VLAN and physical network that it maps to are |
| designated by the administrator</para> |
| </listitem> |
| <listitem> |
| <para>Shared Networks can be isolated by security groups</para> |
| </listitem> |
| <listitem> |
| <para>Public Network is a shared network that is not shown to the end users</para> |
| </listitem> |
| <listitem> |
| <para>Source NAT per zone is not supported when the service provider is virtual router. |
| However, Source NAT per account is supported with virtual router in a Shared Network.</para> |
| </listitem> |
| </itemizedlist> |
| <para>For information, see <xref linkend="creating-shared-network"/>.</para> |
| </section> |