Example scenarios

The following table lists examples based on different parameters.

Protocol

Version

Outer IP rule

Inner IP rule

L7 rule needed

Result

VXLAN (not supported by LINA)

7.6.2

Yes

No

No

Traffic allowed if outer header matches

VXLAN (not supported by LINA)

7.6.4

No

Yes

No

Traffic allowed if inner header matches

GRE (supported by LINA)

7.6.2 and 7.6.4

No

Yes

No

Traffic allowed if inner header matches

VXLAN + L7 feature

7.6.2 and 7.6.4

No

Yes

Yes

Inner header rule required

Note

An outer IP rule matches traffic based on the tunnel endpoints. It evaluates:

  • Source IP address of the encapsulating device

  • Destination IP address of the encapsulating device

An inner IP rule matches traffic based on the original IP packet inside the tunnel. It evaluates:

  • The real client IP address

  • The real destination server IP address