{"id":37988,"date":"2025-08-04T16:10:22","date_gmt":"2025-08-04T19:10:22","guid":{"rendered":"https:\/\/www.locaweb.com.br\/ajuda\/?post_type=ht_kb&#038;p=37988"},"modified":"2025-08-05T15:59:10","modified_gmt":"2025-08-05T18:59:10","slug":"o-que-sao-as-acls-de-rede-e-como-configura-las","status":"publish","type":"ht_kb","link":"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/o-que-sao-as-acls-de-rede-e-como-configura-las\/","title":{"rendered":"O que s\u00e3o as ACLs de rede e como configur\u00e1-las?"},"content":{"rendered":"    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Informa\u00e7\u00e3o!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Uma <\/span><b>lista de controle de acesso \u00e0 rede (network ACL)<\/b><span style=\"font-weight: 400;\"> \u00e9 uma camada de seguran\u00e7a opcional que atua como um <\/span><b>firewall para toda uma sub-rede inteira (<\/b><b><i>tier<\/i><\/b><b>)<\/b><span style=\"font-weight: 400;\"> dentro da sua VPC.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Para tra\u00e7ar um paralelo pr\u00e1tico, imagine a portaria de um condom\u00ednio, onde \u00e9 poss\u00edvel visualizar quem circula pelas proximidades, permitindo ou n\u00e3o o acesso \u00e0s casas. No mesmo sentido, as <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/como-configurar-regras-de-firewall\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">regras de sa\u00edda<\/span><\/a><span style=\"font-weight: 400;\"> das ACLs seriam as portas das casas, abertas opcionalmente por cada morador.<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">As principais caracter\u00edsticas de uma Network ACL s\u00e3o:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Atua no n\u00edvel da sub-rede (tier):<\/b><span style=\"font-weight: 400;\"> isso significa que as regras se aplicam a todas as VMs que fazem parte daquela camada, mesmo que as m\u00e1quinas virtuais tenham grupos de seguran\u00e7a e firewall pr\u00f3prios.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>\u00c9 <\/b><b><i>stateless<\/i><\/b><b> (sem estado):<\/b><span style=\"font-weight: 400;\"> n\u00e3o arquivar o estado das conex\u00f5es \u00e9 o atributo mais importante das redes ACL. A seguran\u00e7a e o controle sobre o tr\u00e1fego de informa\u00e7\u00f5es s\u00e3o maiores, pois, mesmo que o usu\u00e1rio tenha permitido tr\u00e1fego de entrada, tamb\u00e9m precisar\u00e1 criar uma <\/span><b>regra expl\u00edcita de sa\u00edda<\/b><span style=\"font-weight: 400;\">, consentindo o tr\u00e1fego de resposta, e vice-versa.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Utiliza regras numeradas:<\/b><span style=\"font-weight: 400;\"> as regras estabelecidas pelos usu\u00e1rios s\u00e3o numeradas e processadas em ordem, do menor para o maior n\u00famero. O sistema aplica automaticamente a primeira regra que corresponde ao tr\u00e1fego, ignorando as demais.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Funciona na l\u00f3gica de permitir ou negar:<\/b><span style=\"font-weight: 400;\"> o usu\u00e1rio estabelece regras tanto para permitir quanto para negar explicitamente o tr\u00e1fego.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Opera por nega\u00e7\u00e3o impl\u00edcita:<\/b><span style=\"font-weight: 400;\"> toda a ACL possui um regra padr\u00e3o, que n\u00e3o pode ser modificada, de negar todo o tr\u00e1fego que n\u00e3o atenda a nenhum dos quesitos anteriores.\u00a0<\/span><\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/p>\n<p><span style=\"font-weight: 400;\">Entenda e domine as diferen\u00e7as entre ACL e regras de sa\u00edda. Esta \u00e9 uma compreens\u00e3o fundamental.<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Caracter\u00edstica \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 ACL de redes\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 Regras de sa\u00edda<\/b><b><\/b><\/p>\n<p>&nbsp;<\/p>\n<p><b>N\u00edvel de atua\u00e7\u00e3o\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/b><span style=\"font-weight: 400;\">sub-rede \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 inst\u00e2ncia <\/span><b><br \/>\n<\/b><b> \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/b><i><span style=\"font-weight: 400;\">(tier)\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 (VM)<\/span><\/i><i><\/i><\/p>\n<p>&nbsp;<\/p>\n<p><b>Estado\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/b><i><span style=\"font-weight: 400;\">stateless \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 statefull<\/span><\/i><i><span style=\"font-weight: 400;\"><br \/>\n<\/span><\/i><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 (resposta precisa ser permitida) \u00a0 \u00a0 \u00a0 (resposta permitida\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0automaticamente)<\/span><\/p>\n<p>&nbsp;<\/p>\n<p><b>Aplica\u00e7\u00e3o \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 <\/b><span style=\"font-weight: 400;\">aplica-se a todas as VMs \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 associado a VMs <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 na sub-rede\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 espec\u00edficas<\/span><\/p>\n<p>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2><b>Quando usar uma Network ACL?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Utilizada em conjunto com as regras de sa\u00edda, a lista de controle de acesso \u00e0 rede funciona como uma <\/span><b>camada de defesa adicional<\/b><span style=\"font-weight: 400;\">. Sua utiliza\u00e7\u00e3o \u00e9 indicada para:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Bloquear tr\u00e1fego em larga escala:<\/b><span style=\"font-weight: 400;\"> quando o usu\u00e1rio precisa impedir o acesso de um endere\u00e7o ou de uma faixa de IPs maliciosos a uma sub-rede inteira.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Refor\u00e7ar a segmenta\u00e7\u00e3o de rede:<\/b><span style=\"font-weight: 400;\"> \u00e9 poss\u00edvel, por exemplo, garantir que uma tier de banco de dados n\u00e3o estabele\u00e7a conex\u00e3o com a internet. Para isso, basta criar uma regra de sa\u00edda na ACL que negue todo o tr\u00e1fego de sa\u00edda para <\/span><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><span style=\"font-weight: 400;\">.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Exercer controle expl\u00edcito sobre o tr\u00e1fego de entrada e sa\u00edda<\/b><span style=\"font-weight: 400;\">: um quesito extremamente importante em ambientes de alta seguran\u00e7a.<\/span><\/li>\n<\/ul>\n<h2><b>Configurando a sua network ACL\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Como voc\u00ea ver\u00e1 no passo a passo a passo a seguir, trata-se de um processo com tr\u00eas momentos: a cria\u00e7\u00e3o da lista de ACL, a defini\u00e7\u00e3o das regras e a associa\u00e7\u00e3o entre a lista e uma ou mais sub-redes da VPC.<\/span><\/p>\n<h3><b>Etapa 1: Cria\u00e7\u00e3o da lista de ACL<\/b><b><\/b><\/h3>\n<p>&nbsp;<\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No painel do Locaweb Cloud, selecione a aba <\/span><b>rede e, em seguida, clique em<\/b> <b>VPC.<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37996\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL.png\" alt=\"\" width=\"512\" height=\"265\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL.png 512w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL-300x155.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL-50x26.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL-60x31.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/1.-Nova-lista-ACL-100x52.png 100w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ent\u00e3o, clique no link com o nome da VPC \u00e0 qual sua lista ser\u00e1 associada.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Localize e selecione a aba <\/span><b>listas de redes ACL<\/b><span style=\"font-weight: 400;\">.<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37997\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede.png\" alt=\"\" width=\"512\" height=\"265\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede.png 512w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede-300x155.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede-50x26.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede-60x31.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/2.-Lista-de-ACLs-de-rede-100x52.png 100w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clique no bot\u00e3o <\/span><b>adicionar lista de ACL de rede<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">O pr\u00f3ximo passo \u00e9 preencher o <\/span><b>modal com informa\u00e7\u00f5es sobre a lista<\/b><span style=\"font-weight: 400;\"> a ser criada, conforme orientamos a seguir:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37998\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL.png\" alt=\"\" width=\"512\" height=\"291\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL.png 512w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL-300x171.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL-50x28.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL-60x34.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/3.-Adicionar-lista-ACL-100x57.png 100w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/span><b><br \/>\n<\/b><b>Nome:<\/b><span style=\"font-weight: 400;\"> procure definir um nome descritivo para sua lista. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Exemplo: ACL-Tier-Web, ACL-Restrita-DB).<\/span><span style=\"font-weight: 400;\"><br \/>\n<b><\/b><\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\"><b>\u00a0 \u00a0 \u00a0 \u00a0 Descri\u00e7\u00e3o:<\/b>\u00a0 indicando o prop\u00f3sito da lista.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a06. Clique em <\/span><b>OK<\/b><span style=\"font-weight: 400;\"> ou <\/span><b>criar<\/b><span style=\"font-weight: 400;\">, para concluir o processo.<\/span><\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Ponto de aten\u00e7\u00e3o importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/p>\n<p><span style=\"font-weight: 400;\">Quando o usu\u00e1rio do Locaweb Cloud cria uma nova Virtual Private Cloud \u2014 VPC, ocorre a gera\u00e7\u00e3o autom\u00e1tica de duas listas de controle de acesso pr\u00e9-configuradas, a partir dos seguintes fundamentos de seguran\u00e7a:<\/span><\/p>\n<p><b>Permitir tudo:<\/b><span style=\"font-weight: 400;\"> a lista baseia-se na regra que deixa todo o tr\u00e1fego de rede (entrada e sa\u00edda) passar livremente. A seguran\u00e7a depender\u00e1 totalmente do firewall de cada VM (o security group).<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>Negar tudo:<\/b><span style=\"font-weight: 400;\"> nesse caso, a base \u00e9 uma regra que bloqueia todo o tr\u00e1fego de rede (entrada e sa\u00edda). A rede fica completamente isolada at\u00e9 que voc\u00ea crie e aplique uma nova lista de regras, permitindo a\u00e7\u00f5es espec\u00edficas.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Aqui entra em cena o segundo est\u00e1gio deste tutorial.<\/span><\/p>\n<p>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h3><b>Etapa 2: adi\u00e7\u00e3o de regras \u00e0 sua lista de ACL<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Na rela\u00e7\u00e3o de ACLs exibida no painel Locaweb Cloud, clique na lista que voc\u00ea acabou de criar.<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-37999\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada.png\" alt=\"\" width=\"512\" height=\"237\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada.png 512w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada-300x139.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada-50x23.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada-60x28.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/4.-Lista-ACL-recem-criada-100x46.png 100w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Na \u00e1rea superior direita da tela, selecione a aba <b>adicionar ACL<\/b>.<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">Em seguida, <b>preencha o modal<\/b> no qual s\u00e3o indicados os detalhes da regra, conforme as orienta\u00e7\u00f5es a seguir:<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38000\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra.png\" alt=\"\" width=\"512\" height=\"470\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra.png 512w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra-300x275.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra-50x46.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra-60x55.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/5.-Adicionar-regra-100x92.png 100w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/li>\n<\/ol>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>#Regra: <\/b><span style=\"font-weight: 400;\">aqui deve ser indicado o n\u00famero da regra, que tamb\u00e9m determinar\u00e1 sua ordem de prioridade. Considere sempre que regras com n\u00fameros menores s\u00e3o processadas primeiro.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Lista CIDR:<\/b><span style=\"font-weight: 400;\"> neste campo, deve ser digitada a faixa de IPs na qual a regra ser\u00e1 aplicada. Se o \u201ctipo de tr\u00e1fego&#8221; for <\/span><span style=\"font-weight: 400;\">entrada<\/span><span style=\"font-weight: 400;\">, indique o <\/span><b>IP de origem<\/b><span style=\"font-weight: 400;\">; se for <\/span><span style=\"font-weight: 400;\">sa\u00edda<\/span><span style=\"font-weight: 400;\">, o <\/span><b>IP de destino<\/b><span style=\"font-weight: 400;\">. Use <\/span><span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><span style=\"font-weight: 400;\"> para &#8220;qualquer IP&#8221;.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>A\u00e7\u00e3o:<\/b><span style=\"font-weight: 400;\"> o objetivo deste campo \u00e9 o usu\u00e1rio definir se o tr\u00e1fego correspondente \u00e0 regra ser\u00e1 permitido ou negado.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Protocolo:<\/b><span style=\"font-weight: 400;\"> deve ser apontado o protocolo de rede ao qual a regra se aplica, se <\/span><span style=\"font-weight: 400;\">TCP<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">UDP<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">ICMP<\/span><span style=\"font-weight: 400;\">. A op\u00e7\u00e3o <\/span><span style=\"font-weight: 400;\">ALL <\/span><span style=\"font-weight: 400;\">aplicar\u00e1 a regra a todos os protocolos.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Porta inicial:<\/b><span style=\"font-weight: 400;\"> indique a porta inicial do intervalo que voc\u00ea deseja filtrar (ex.: <\/span><span style=\"font-weight: 400;\">80<\/span><span style=\"font-weight: 400;\">). Para uma \u00fanica porta, esse valor ser\u00e1 igual ao da &#8220;porta final&#8221;.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Porta final:<\/b><span style=\"font-weight: 400;\"> a porta final do intervalo que voc\u00ea deseja filtrar (ex: <\/span><span style=\"font-weight: 400;\">80<\/span><span style=\"font-weight: 400;\">). Para uma \u00fanica porta, esse valor ser\u00e1 igual ao da &#8220;porta inicial&#8221;.<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Tipo de tr\u00e1fego:<\/b><span style=\"font-weight: 400;\"> aqui voc\u00ea indica se a regra ir\u00e1 filtrar o tr\u00e1fego recebido (entrada), ou originado pela sua rede (sa\u00edda).<\/span>&nbsp;<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Descri\u00e7\u00e3o (opcional):<\/b><span style=\"font-weight: 400;\"> aqui, voc\u00ea pode ou n\u00e3o escrever uma breve explica\u00e7\u00e3o sobre o motivo ou a fun\u00e7\u00e3o desta regra, facilitando o gerenciamento futuro.<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><span style=\"font-weight: 400;\">Exemplo: <\/span><span style=\"font-weight: 400;\">permite acesso SSH da rede interna.<\/span><\/li>\n<\/ul>\n    \t\t<div class=\"hts-messages hts-messages--info   hts-messages--withicon \"   >\r\n    \t\t\t    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/p>\n<p><b>Exemplo pr\u00e1tico: <\/b><b><br \/>\n<\/b><b>Permitindo tr\u00e1fego web (HTTP)<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Para permitir que a internet acesse um servidor web na sua tier:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>1. Crie uma regra de entrada:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>N\u00famero da regra:<\/b> <span style=\"font-weight: 400;\">100<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>CIDR de origem:<\/b> <span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><span style=\"font-weight: 400;\"> (qualquer lugar da internet)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Protocolo:<\/b> <span style=\"font-weight: 400;\">TCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Portas:<\/b> <span style=\"font-weight: 400;\">80<\/span><span style=\"font-weight: 400;\"> a <\/span><span style=\"font-weight: 400;\">80<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>A\u00e7\u00e3o:<\/b> <span style=\"font-weight: 400;\">permitir<\/span>&nbsp;<\/li>\n<\/ul>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>2. Crie a regra de sa\u00edda correspondente, lembrando que a ACL \u00e9 <\/b><b><i>stateless<\/i><\/b><b>:<\/b>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\">V\u00e1 para a aba <\/span><b>regras de sa\u00edda<\/b><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>N\u00famero da regra:<\/b> <span style=\"font-weight: 400;\">100<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>CIDR de destino:<\/b> <span style=\"font-weight: 400;\">0.0.0.0\/0<\/span><span style=\"font-weight: 400;\"> (qualquer lugar da internet)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Protocolo:<\/b> <span style=\"font-weight: 400;\">TCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>Portas:<\/b> <span style=\"font-weight: 400;\">1024<\/span><span style=\"font-weight: 400;\"> a <\/span><span style=\"font-weight: 400;\">65535<\/span><span style=\"font-weight: 400;\"> (este \u00e9 o intervalo de portas tempor\u00e1rias que os servidores usam para enviar as respostas).<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><b>A\u00e7\u00e3o:<\/b> <span style=\"font-weight: 400;\">permitir<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Importante!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tSem essa regra de sa\u00edda, a resposta do seu servidor web nunca chegaria ao usu\u00e1rio!    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a04. Para finalizar o processo, clique <\/span><b>OK. <\/b><span style=\"font-weight: 400;\">Sua regra estar\u00e1 salva.<\/span><\/p>\n<h3><b>Etapa 3: associa\u00e7\u00e3o entre a lista de ACL e uma sub-rede<\/b><\/h3>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No painel do Locaweb Cloud, volte para a \u00e1rea de detalhes da sua <\/span><b>VPC<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Em seguida, selecione a aba <\/span><b>redes<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle hts-messages--withicon \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Dica!<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<span style=\"font-weight: 400;\">Caso sua VPC n\u00e3o tenha sub-redes, <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/criando-as-tiers-de-rede-dentro-da-vpc-suas-sub-redes\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">voc\u00ea pode cri\u00e1-las e associ\u00e1-las \u00e0 lista ACL<\/span><\/a><span style=\"font-weight: 400;\"> de forma simples. <\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a03. Agora, localize a sub-rede (<\/span><i><span style=\"font-weight: 400;\">tier) <\/span><\/i><span style=\"font-weight: 400;\">\u00e0 qual ser\u00e3o associadas novas regras.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a04. O pr\u00f3ximo passo \u00e9 selecionar o <\/span><b>nome da sub-rede<\/b><span style=\"font-weight: 400;\"> desejada <\/span><b>ou<\/b><span style=\"font-weight: 400;\"> clicar no \u00edcone de configura\u00e7\u00e3o.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 \u00a05. Na barra de ferramentas, na \u00e1rea superior direita da tela, clique em <\/span><b>substituir lista de ACL<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38001\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL.png\" alt=\"\" width=\"1600\" height=\"829\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL.png 1600w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-300x155.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-1024x531.png 1024w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-768x398.png 768w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-50x26.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-1536x796.png 1536w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-60x31.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/6.-Substituir-lista-ACL-100x52.png 100w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 6. Agora, selecione a nova ACL que voc\u00ea criou e configurou.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-38002\" src=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista.png\" alt=\"\" width=\"576\" height=\"317\" srcset=\"https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista.png 576w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista-300x165.png 300w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista-50x28.png 50w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista-60x33.png 60w, https:\/\/www.locaweb.com.br\/ajuda\/wp-content\/uploads\/2025\/08\/7.-Confirmar-substituicao-de-lista-100x55.png 100w\" sizes=\"auto, (max-width: 576px) 100vw, 576px\" \/><\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0 \u00a0 7. No modal que ver\u00e1 na sua tela, clique em <\/span><b>OK<\/b><span style=\"font-weight: 400;\"> para concluir o processo.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A partir de agora, todo o tr\u00e1fego de entrada e sa\u00edda para essa sub-rede (<\/span><i><span style=\"font-weight: 400;\">tier<\/span><\/i><span style=\"font-weight: 400;\">) ser\u00e1 filtrado de acordo com as regras que voc\u00ea definiu para a\u00a0 nova lista de ACL.<\/span><\/p>\n<p><b>Pr\u00f3ximos passos<\/b><b><br \/>\n<\/b><b><br \/>\n<\/b><strong>Conecte na sua rede com VPN site-to-site<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Agora que sua rede est\u00e1 protegida com ACLs, voc\u00ea tamb\u00e9m pode utilizar um recurso que cria um canal de comunica\u00e7\u00e3o privado entre redes e servidores. \u00c9 a <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/criando-uma-vpn-site-to-site-locaweb-cloud\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">VPN site-to-site<\/span><\/a><span style=\"font-weight: 400;\">, que estabelece um t\u00fanel criptografado para conectar duas redes, permitindo que servidores f\u00edsicos e na nuvem se comuniquem de forma pr\u00e1tica, eficiente e segura.<\/span><\/p>\n<p><b>Conecte na sua rede com VPN de acesso remoto<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Esse \u00e9 o melhor caminho para fornecer acesso remoto, via internet, sem expor as portas de gerenciamento. A <\/span><a href=\"https:\/\/www.locaweb.com.br\/ajuda\/wiki\/como-configurar-uma-vpn-para-acesso-remoto-locaweb-cloud\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">VPN de acesso remoto<\/span><\/a><span style=\"font-weight: 400;\"> permite que as equipes acessem e gerenciem VMs de qualquer lugar, com a seguran\u00e7a garantida pelo uso de IP privados, dentro de um t\u00fanel seguro.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As principais caracter\u00edsticas de uma Network ACL s\u00e3o: Atua no n\u00edvel da sub-rede (tier): isso significa que as regras se aplicam a todas as VMs que fazem parte daquela camada, mesmo que as m\u00e1quinas virtuais tenham grupos de seguran\u00e7a e firewall pr\u00f3prios.&nbsp; \u00c9 stateless (sem estado): n\u00e3o arquivar o estado&#8230;<\/p>\n","protected":false},"author":29,"comment_status":"closed","ping_status":"closed","template":"","format":"standard","meta":{"footnotes":""},"ht-kb-category":[666,645],"ht-kb-tag":[],"class_list":["post-37988","ht_kb","type-ht_kb","status-publish","format-standard","hentry","ht_kb_category-locaweb-cloud","ht_kb_category-perguntas-frequentes"],"_links":{"self":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/37988","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb"}],"about":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/comments?post=37988"}],"version-history":[{"count":3,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/37988\/revisions"}],"predecessor-version":[{"id":38161,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb\/37988\/revisions\/38161"}],"wp:attachment":[{"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/media?parent=37988"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-category?post=37988"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.locaweb.com.br\/ajuda\/wp-json\/wp\/v2\/ht-kb-tag?post=37988"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}