Details
-
Improvement
-
Status: Closed
-
Minor
-
Resolution: Implemented
-
qpid-java-broker-8.0.6
-
None
Description
When configuring an ACL rule with the firewall predicate, e.g.
ACL ALLOW-LOG admin ALL ALL from_hostname="192.169.1.1,192.169.1.2"
or
ACL ALLOW-LOG admin ALL ALL from_network="192.169.1.*"
they are currently intended to use along with the ACCESS VIRTUALHOST rule to apply firewall restrictions for the messaging client.
Firewall predicates should be applied to HTTP(S) connections as well, restricting access from undesirable hosts or networks.