AWS Kubernetes (EKS) SDN connector using access key

AWS SDN connectors support dynamic address groups based on AWS Kubernetes (EKS) filters.

To enable an AWS SDN connector to fetch IP addresses from AWS Kubernetes:
  1. Go to Security Fabric > External Connectors. Click Create New, then select Amazon Web Services (AWS). Configure the SDN connector as desired. See AWS SDN connector using certificates

    Screenshot of SDN connector configuration for Amazon EKS

  2. Go to Policies & Objects > Addresses. Click Create New > Address to create a dynamic firewall address for the configured SDN connector using the supported Kubernetes filter.
  3. From the Type dropdown list, select Dynamic.
  4. From the Sub Type dropdown list, select Fabric Connector Address.
  5. From the SDN Connector dropdown list, select the desired SDN connector.
  6. In the Filter field, add the desired filters. The following filters are supported:




    Name of Kubernetes cluster.


    Namespace of a Kubernetes service or pod.


    Name of a Kubernetes service.


    Name of a Kubernetes node.


    Zone of a Kubernetes node.


    Region of a Kubernetes node.


    Name of a Kubernetes pod.

    Name of label of a Kubernetes resource (cluster/service/node/pod).

    Screenshot of AWS Kubernetes setup displaying the creation of dynamic firewall address

  7. Configure the rest of the settings, then click OK.
  8. Ensure that the SDN connector resolves the dynamic firewall address IP addresses by going to Policy & Objects > Addresses and hovering over the newly created address.