Skip to main content

Security Policy User Guide 21.5

Loopback Interfaces

(Works with Linux VENs) VENs can report loopback interfaces and enforce policy on them.

The VEN reports all interfaces, including loopback interfaces. If the VEN detects an interface that is a loopback interface, but is not in the standard defined IP block that is meant for loopback interfaces (127.0.0.0/8), the VEN reports this as a loopback interface to the PCE. If the workload is in the scope where loopback interfaces are to participate in policy enforcement, the workload distributes the IP address to peers and enforces policy on that interface.

The scope where loopback interfaces are to participate in policy enforcement is defined through the PCE web console.

  1. Log in to the web console as a Global Ruleset Provisioner or a Global Org Owner.

  2. Choose Settings > Security.

  3. Click the Loopback Interfaces tab.

  4. Choose labels to define the scope.