Hello, dear!
Have a nice day!
The following will describe the differences among application scenarios of VDC interworking, VPC interworking, and security groups.
VDC interworking
Resources (for example, cloud hosts) of different VDCs are isolated and cannot communicate with each other. When you require two cloud hosts of different VDCs in the same cloud resource pool to communicate with each other, create VDC interworking. After the creation, the cloud hosts on the routed networks of different VDCs can communicate with each other.
When you require two cloud hosts of different VDCs in the same cloud resource pool to communicate with each other, you can create VDC interworking.
Before creating the VDC interworking, you need to create an interworking network in the cloud resource pool and permit the network in the ACL of the firewall.
VPC interworking
A VPC can provide a secure, isolated network for VDCs. Resources (for example, cloud hosts) of different VPCs are isolated and cannot communicate with each other. When you require two cloud hosts of different VPCs to communicate with each other, create VPC interworking. After the creation, the cloud hosts on the routed networks of different VPCs can communicate with each other.
When resources (for example, cloud hosts) of different VPCs in the same VDC of a cloud resource pool need to communicate with each other, you can create VPC interworking.
Before creating the VPC interworking, you need to create an interworking network in the cloud resource pool and permit the network in the ACL of the firewall.
Security groups
A security group controls cloud host access, enhancing cloud host security. VDC administrators can define different access control rules for a created security group, and these rules take effect for all cloud hosts added to this security group.
1. When resources (for example, cloud hosts) of the same VPC in the same VDC of a cloud resource pool need to be isolated or communicate with each other, you can create security groups.
2. When resources (such as cloud hosts) of different VPCs in the same VDC of a cloud resource pool need to be isolated or communicate with each other, you can create security groups.
Constraints
There are the following constraints when you use VDC interworking, VPC interworking, and security groups:
1. If cloud host A and cloud host B that belong to different VDCs in the same cloud resource pool need to communicate with each other, you need to create VDC interworking, and cancel the restriction from security groups to which the cloud hosts belong.
2. If cloud host A and cloud host B that belong to different VPCs in the same VDC need to communicate with each other, you need to create VPC interworking, and cancel the restriction from security groups to which the cloud hosts belong.
3. If cloud host A and cloud host B belong to a same VPC, you can use security groups to control the access between the cloud hosts.
Any further questions, let us know!