Learn · Lesson 3 of 7 · 6 min
Lock down access
Make access easy to understand: name the machines that need to connect, choose the service, then review the result.
Default ACL allows every node to reach every other node. Create your specific rules, then remove Default ACL to restrict access.
Tags give your rules meaning.
Create tags in Access Control → Tags, then assign them on the Nodes page.

devstagingprodGive development access to staging.
In Network Rules, create this rule. It allows HTTPS from devices tagged dev to devices tagged staging.
- Name
- dev-to-staging
- Source tags
- dev
- Destination tags
- staging
- Protocol / ports
- TCP / 443
See what you allowed.
Open Preview and review the sources, destinations and ports. Once the rules cover the access you need, delete Default ACL from Network Rules.
This rule grants no access to prod. Other allow rules still apply.
Preview shows your configuration. It does not test live traffic.
A few useful details
How rules combine. If any rule allows a packet, it passes. If none does, the node drops it. Rules have no order, priority or deny action.
Empty tags mean everyone. Leaving source or destination empty matches all nodes. Check these fields before saving.
Tags. Nodes can have several tags and match rules for any of them. Tags cannot be renamed: create a replacement, retag nodes, then delete the old tag.
Other services. For example, allow ci → registry on TCP 5000, sre → prod on TCP 22, or infra → prod on TCP 9090. Protocols include ALL, TCP, UDP and ICMP.
Changes are recorded. Rule creation, updates and deletion appear in the audit log.
Next, give automated machines the right tags when they join.