# Private networks & firewalls with `aral`

## Private networks (VPC)

    aral network create --name backend --region hel1
    aral network attach --server-id <id> <network-id>   # hot-plugs a 2nd NIC
    aral network members <network-id>
    aral network detach --server-id <id>                # detaches THE server's network
    aral network delete <network-id>

Every project also gets a default private network automatically. Attached
servers see each other on the overlay subnet (MTU 1370 — never raise it in
the guest).

## Network security rules

    aral network add-rule <network-id> --protocol tcp --port 5432 --source 10.0.0.0/8
    aral network rules <network-id>
    aral network delete-rule <network-id> <rule-id>

## Per-server firewall

    aral firewall rules <server-id>          # effective inbound rules
    aral firewall add-rule <server-id> --protocol tcp --port 8080 --source 0.0.0.0/0
    aral firewall delete-rule <server-id> <rule-id>

Chains end in DROP: anything not explicitly allowed (besides SSH and the
defaults) is refused.
