You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过NACL实现VPN用户访问AWS私有子网内的Jenkins前端

Absolutely feasible! You can absolutely lock down access to your Jenkins instance (and its private subnet load balancer) to only VPN users using Network Access Control Lists (NACLs). Here's a detailed, step-by-step breakdown to make this work:

Is This Approach Valid?

Yes, because NACLs act as subnet-level firewalls that control inbound and outbound traffic for all resources within a subnet. Since both your LB and Jenkins are in private subnets, you can use NACLs to explicitly allow only VPN-originated traffic to flow through the LB to Jenkins, while blocking all other unwanted access.

Step-by-Step Implementation

1. First, Get Your VPN's Source CIDR Range

You'll need the exact IP address range (CIDR block) that VPN users connect from. This could be:

  • The client CIDR block assigned to your AWS Client VPN endpoint
  • The public IP/CIDR range of your on-premises VPN gateway (if using a site-to-site VPN)
  • The static IP range allocated to remote VPN users (for third-party VPN solutions)
    Make sure you have this range handy—all your NACL rules will reference it.

2. Configure NACLs for the Load Balancer's Private Subnet

Since the LB is the entry point for user traffic, we'll start here to filter incoming requests:

Inbound Rules (Allow only VPN traffic to the LB)

  • Add a high-priority rule (e.g., rule #100) allowing traffic from your VPN CIDR to the LB's listening port(s) (typically 80 for HTTP or 443 for HTTPS). Set the protocol to TCP.
  • Optionally, add a rule for ICMP if you need to ping the LB for testing (but this isn't required for application access).
  • Leave the default "Deny All" rule (usually rule #1000) in place to block all other inbound traffic.

Outbound Rules (Allow LB to communicate with Jenkins and return traffic to VPN users)

  • Add a high-priority rule (e.g., rule #100) allowing traffic from the LB subnet to your Jenkins instance's subnet on Jenkins' service port (typically 8080, or your custom port). Protocol: TCP.
  • Add another rule (e.g., rule #110) allowing outbound traffic to the VPN CIDR on ephemeral ports (usually 1024-65535). This lets the LB send response traffic back to VPN users.
  • Again, leave the default "Deny All" rule at the bottom to block unintended outbound traffic.

3. Configure NACLs for Jenkins Instance's Private Subnet

Next, lock down the Jenkins subnet to only accept traffic from the LB:

Inbound Rules (Allow only LB traffic to Jenkins)

  • Add a high-priority rule (e.g., rule #100) allowing traffic from your LB's private subnet CIDR to Jenkins' service port (8080 or custom). Protocol: TCP.
  • Keep the default "Deny All" rule to block all other inbound traffic (e.g., direct access from non-LB sources).

Outbound Rules (Allow Jenkins to send responses back to the LB)

  • Add a rule (e.g., rule #100) allowing outbound traffic to the LB's subnet CIDR on ephemeral ports (1024-65535). This lets Jenkins send response traffic back to the LB, which then forwards it to VPN users.
  • If your Jenkins instance needs to pull dependencies (e.g., from Maven repositories, AWS services), add additional rules for those specific CIDR ranges—otherwise, rely on the default "Deny All" rule for unnecessary outbound traffic.
Critical Notes to Remember
  • NACLs are stateless: Unlike security groups, NACLs don't automatically allow return traffic. You must explicitly add outbound rules for response traffic (hence the ephemeral port rules).
  • Rule priority matters: NACLs evaluate rules in order from lowest to highest number. Make sure your allow rules have lower numbers (higher priority) than the default deny-all rule.
  • Verify VPN routing: Ensure your VPN setup has a route that directs traffic to the LB's private subnet CIDR. Without this, VPN users won't be able to reach the LB at all.
  • Test thoroughly: After configuring NACLs, test access from a VPN-connected device to confirm it works, then try accessing from a non-VPN source (e.g., a public EC2 instance in another subnet) to verify it's blocked.

内容的提问来源于stack exchange,提问作者Toye

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:35:37