Skip to Main Content
Status Delivered
Workspace * IBM Cloud Ideas
Categories Virtual Servers
Created by Guest
Created on Feb 19, 2025

PowerVS traffic deny rule (or something like that) between subnets in the same Workspace.

Good-afternoon,

Use case:

Production Workspace - WSPRD

1 IBM i LPAR - IBMiPRD

3 Cores

128 GB Memory

11TB of Storage

=============================

DR Workspace - WSDR

2 IBM i LPARs - IBMiDR and IBMiQA

SPP with 3 Cores

IBMiDR

0.25 Cores

32 GB Memory

11TB of Storage

DR Subnets i.e.:

Management 172.19.4.0/28

Front End 172.19.4.32/27

PowerHA 172.19.4.64/27

========

IBMiQA

2.75 Cores

32GB Memory

11TB of Storage

QA Subnets i.e.:

Management 172.18.4.0/28

Front End 172.18.4.32/27

PowerHA 172.18.4.64/27

=======================================

Take the scenario above...

We want to take advantage of the SPP (Service Processor Pools) for the 2 LPARs in WSDR and the advantage of doing an image capture and deploy it to a new QA LPAR every 6 months, without going to COS, which we can do in under one hour.

But we do not want that the DR subnets talk with the QA subnets.

At the moment we can not block traffic between subnets in the same Workspace, and this is a kill switch for the solution.

In the above scenario, we are unable to take advantage of these PowerVS features (SPP and image captures in the same Workspace) because of the inability to block traffic between two subnets in the same Workspace.

Please add a feature to allow blocking subnets in the same Workspace.

Thank you.

Idea priority Urgent
Needed By Yesterday (Let's go already!)